<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster behaviour in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182829#M33533</link>
    <description>&lt;P&gt;A gateway, whether or not it’s a cluster, will use the last successfully installed policy UNLESS you don’t have a valid license.&lt;BR /&gt;Clustering works on the same principle: it’s generally unaffected by the management not being available.&lt;BR /&gt;Two notable exceptions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Logs will be stored in the relevant gateway until the management or log server comes back online.&lt;/LI&gt;
&lt;LI&gt;If you are doing any VPNs using certificate-based authentication with the Internal CA, expect these VPNs to fail after about 24 hours as the CRL points to the management server.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 01 Jun 2023 00:31:12 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-01T00:31:12Z</dc:date>
    <item>
      <title>Cluster behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182704#M33505</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have a couple of questions that need answering:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So if the 6600 cluster firewalls aren't able to reach the management server on the other datacentre. What will happen will they still be able to route traffic and essentially just become a router without cluster configuration and Firewall policy? I pushed the policy when I was building the Firewall's for the policy that will be used, so if the management&amp;nbsp;server isn't contactable will this policy still be active and usable?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Another scenario; if we are able to get the Firewall to communicate to the management server so that it can install all the policy and form the cluster. If the server was to go down for some unknown reason what will happen to the HA cluster, will the cluster not be formed anymore? Will the Firewall's not be able to transit data? What would be the impact of that scenario? Or would live traffic not be affected?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 14:32:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182704#M33505</guid>
      <dc:creator>ZakMeadows</dc:creator>
      <dc:date>2023-05-31T14:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182829#M33533</link>
      <description>&lt;P&gt;A gateway, whether or not it’s a cluster, will use the last successfully installed policy UNLESS you don’t have a valid license.&lt;BR /&gt;Clustering works on the same principle: it’s generally unaffected by the management not being available.&lt;BR /&gt;Two notable exceptions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Logs will be stored in the relevant gateway until the management or log server comes back online.&lt;/LI&gt;
&lt;LI&gt;If you are doing any VPNs using certificate-based authentication with the Internal CA, expect these VPNs to fail after about 24 hours as the CRL points to the management server.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 01 Jun 2023 00:31:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182829#M33533</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T00:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182839#M33539</link>
      <description>&lt;P&gt;To answer your other question about Firewall HA.&lt;/P&gt;&lt;P&gt;If one of the FW is down, the other member will take over, that is the reason of HA and live traffic will be not affected unless both devices are down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 01:36:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182839#M33539</guid>
      <dc:creator>just13pro</dc:creator>
      <dc:date>2023-06-01T01:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182874#M33546</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am asking if the Management server was to goes down, will this affect anything to do with how the cluster acts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;BR /&gt;Zak&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 08:37:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182874#M33546</guid>
      <dc:creator>ZakMeadows</dc:creator>
      <dc:date>2023-06-01T08:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182875#M33547</link>
      <description>&lt;P&gt;Nope, it will not&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 08:39:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-behaviour/m-p/182875#M33547</guid>
      <dc:creator>just13pro</dc:creator>
      <dc:date>2023-06-01T08:39:33Z</dc:date>
    </item>
  </channel>
</rss>

