<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Member of ClusterXL unable to reach updates.checkpoint.com in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Member-of-ClusterXL-unable-to-reach-updates-checkpoint/m-p/188966#M34770</link>
    <description>&lt;P&gt;I was having this problem under R80.40, and upgraded to R81.10 and problem still exists.&amp;nbsp; The Active (call it B1) gateway is receiving an error Anti-Bot-Update Failed. Contract Entitlement check failed.&amp;nbsp; Could not reach 'updates.checkpoint.com'. Check DNS and Proxy Configuration on gateway.&lt;/P&gt;&lt;P&gt;The Standby (call it B2) member has no errors.&amp;nbsp; Now, if I do a force failover between the two, B1 now has no errors after about 2 minutes, it is able to check, and B2 now gets the error.&lt;/P&gt;&lt;P&gt;I have explicit rules allowing the Cluster object, and each cluster member access to the internet via the required ports on both the Security ruleset and the Application ruleset.&lt;/P&gt;&lt;P&gt;What else can I check?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 14:39:35 GMT</pubDate>
    <dc:creator>JoaT</dc:creator>
    <dc:date>2023-08-08T14:39:35Z</dc:date>
    <item>
      <title>Active Member of ClusterXL unable to reach updates.checkpoint.com</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Member-of-ClusterXL-unable-to-reach-updates-checkpoint/m-p/188966#M34770</link>
      <description>&lt;P&gt;I was having this problem under R80.40, and upgraded to R81.10 and problem still exists.&amp;nbsp; The Active (call it B1) gateway is receiving an error Anti-Bot-Update Failed. Contract Entitlement check failed.&amp;nbsp; Could not reach 'updates.checkpoint.com'. Check DNS and Proxy Configuration on gateway.&lt;/P&gt;&lt;P&gt;The Standby (call it B2) member has no errors.&amp;nbsp; Now, if I do a force failover between the two, B1 now has no errors after about 2 minutes, it is able to check, and B2 now gets the error.&lt;/P&gt;&lt;P&gt;I have explicit rules allowing the Cluster object, and each cluster member access to the internet via the required ports on both the Security ruleset and the Application ruleset.&lt;/P&gt;&lt;P&gt;What else can I check?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 14:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Member-of-ClusterXL-unable-to-reach-updates-checkpoint/m-p/188966#M34770</guid>
      <dc:creator>JoaT</dc:creator>
      <dc:date>2023-08-08T14:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Active Member of ClusterXL unable to reach updates.checkpoint.com</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Member-of-ClusterXL-unable-to-reach-updates-checkpoint/m-p/190388#M35133</link>
      <description>&lt;P&gt;Usually, it's the backup gateway that is problematic to reach the update servers, not the primary.&lt;BR /&gt;In any case, recommend a TAC case to assist: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 21:33:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Active-Member-of-ClusterXL-unable-to-reach-updates-checkpoint/m-p/190388#M35133</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-23T21:33:23Z</dc:date>
    </item>
  </channel>
</rss>

