<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX and VS restart in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173258#M31493</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/69604"&gt;@nooni&lt;/a&gt;&amp;nbsp;kernel parameters set via „fw ctl set ….“ are set for all VS on a host. You can‘t set these kernel parameters only for one VS.&lt;/P&gt;
&lt;P&gt;Regarding your mentioned article&amp;nbsp;&lt;A title="How to force a Security Gateway to send a TCP [RST] packet upon TCP connection expiration" href="https://support.checkpoint.com/results/sk/sk19746" target="_blank" rel="noopener"&gt;How to force a Security Gateway to send a TCP [RST] packet upon TCP connection expiration&lt;/A&gt;&amp;nbsp;you can set your needed parameter for a specific system via GUIdbedit tool. If you only need the change from sk19746 this will be a better solution then setting kernel parameters via fwkern.conf.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 19:15:37 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2023-03-01T19:15:37Z</dc:date>
    <item>
      <title>VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173125#M31460</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope someone can help me clarify how it is possible to restart an VS to make changes in fwkern.conf for that VS effective ?&lt;/P&gt;&lt;P&gt;I know it is possible to make changes on the fly, but in this SK it can only understand that it does not work when SecureXL is enabled ?&lt;/P&gt;&lt;P&gt;This is the SK where i want to enable this feature for only one VS: sk19746&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:58:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173125#M31460</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-01T08:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173127#M31462</link>
      <description>&lt;P&gt;Ask TAC - the sk19746 does not state that it is valid for VSX at all !&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 09:10:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173127#M31462</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-01T09:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173136#M31463</link>
      <description>&lt;P&gt;For such changes the machine must be rebooted (for it to be permanent).&lt;/P&gt;
&lt;P&gt;In a cluster properly sized for failover scenarios this should be manageable within a maintenance window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In other situations there is this process:&lt;/P&gt;
&lt;P&gt;sk169472: How to restart a specific VSX Virtual System in R80.30 and higher&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173136#M31463</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-01T14:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173209#M31480</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the SK. If the VS runs in a high availability setup, for example VSLS.&lt;/P&gt;&lt;P&gt;Will this cpstop/cpstart procedure change the behaviour on the current host the VS resides on ?&lt;/P&gt;&lt;P&gt;If the VS is active on host1 and you do cpstop it will be considered as down and startup at host2 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:30:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173209#M31480</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-01T14:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173212#M31483</link>
      <description>&lt;P&gt;No, you only stop one residing on the physical member you are connected to.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173212#M31483</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-01T14:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173213#M31484</link>
      <description>&lt;P&gt;I always do below option now if I have to do this, as it does NOT need cpstop;cpstart or reboot, applies right away and it actually takes care of the file on its own.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Connect to the command line on the Security Gateway / each Cluster Member.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Run this command:&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;STRONG&gt;fw ctl set -f int &amp;lt;Name_of_Kernel_Parameter&amp;gt; &amp;lt;Value_of_Kernel_Parameter&amp;gt;&lt;/STRONG&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;Notes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;This command works in Gaia Clish and Expert mode.&lt;/LI&gt;
&lt;LI&gt;This command applies immediately.&lt;/LI&gt;
&lt;LI&gt;This command changes the value of the kernel parameter on-the-fly and adds the required line in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;$FWDIR/boot/modules/fwkern.conf&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file for permanent configuration.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Reboot when possible.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk26202" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk26202&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:39:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173213#M31484</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-01T14:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173255#M31490</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks, yes i am aware of that possibility but the SK stated that when using SecureXL a change in fwkern.conf was neccesary.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 18:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173255#M31490</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2023-03-01T18:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173256#M31491</link>
      <description>&lt;P&gt;I never ever had to do that on regular fw, its possible might be different for VSX.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 18:55:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173256#M31491</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-01T18:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173258#M31493</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/69604"&gt;@nooni&lt;/a&gt;&amp;nbsp;kernel parameters set via „fw ctl set ….“ are set for all VS on a host. You can‘t set these kernel parameters only for one VS.&lt;/P&gt;
&lt;P&gt;Regarding your mentioned article&amp;nbsp;&lt;A title="How to force a Security Gateway to send a TCP [RST] packet upon TCP connection expiration" href="https://support.checkpoint.com/results/sk/sk19746" target="_blank" rel="noopener"&gt;How to force a Security Gateway to send a TCP [RST] packet upon TCP connection expiration&lt;/A&gt;&amp;nbsp;you can set your needed parameter for a specific system via GUIdbedit tool. If you only need the change from sk19746 this will be a better solution then setting kernel parameters via fwkern.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 19:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173258#M31493</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-03-01T19:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173277#M31494</link>
      <description>&lt;P&gt;nice to know that there is newer way how to modify fwkern.conf &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; I am still always updating fwkern.conf manually using vi &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; Wondering if such a action is even supported (modify the fwkern file by your own) ...&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 21:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173277#M31494</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-03-01T21:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and VS restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173278#M31495</link>
      <description>&lt;P&gt;That method works fine, never an issue, sometimes old school way is the best, haha : - )&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 22:07:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-VS-restart/m-p/173278#M31495</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-01T22:07:00Z</dc:date>
    </item>
  </channel>
</rss>

