<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CPUSE will fail to install new Jumbo on restored gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56491#M4237</link>
    <description>&lt;P&gt;Seems like something we can improve upon.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8469"&gt;@Tsahi_Etziony&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Jun 2019 21:43:42 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-06-23T21:43:42Z</dc:date>
    <item>
      <title>CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56157#M4234</link>
      <description>&lt;P&gt;Just run into a interesting scenario with CPUSE failing to install take 203 on very last gateway (nearly 40 updated without any issues). Won't be creating TAC case out of pure laziness and too much to do as is&lt;/P&gt;
&lt;P&gt;DA agent version is 1677, so all good there and gateway had take 154 installed before attempt to upgrade to 203.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What turned out was that this particular box was recently fully re-built from factory image due to SSD failure (second SSD dying on 5900 appliances! not good trend there). So we went R77.30 &amp;gt; R80.10 &amp;gt; take 154 &amp;gt; backup restore. All went great and box was running like a charm.&lt;/P&gt;
&lt;P&gt;But now when I attempted to install take 203 it failed at very early stage with following error:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpuse error.jpg" style="width: 465px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1590i03756D2517C9205A/image-size/large?v=v2&amp;amp;px=999" role="button" title="cpuse error.jpg" alt="cpuse error.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Digging into more detailed logs I found that CPUSE was looking for an older file that was not there (&lt;STRONG&gt;/opt/CPInstLog&lt;/STRONG&gt;/install_cpfc_wrapper_HOTFIX_R80_10_JUMBO_HF.log)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="detailed error.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1589i35CB2D20B66BB13A/image-size/large?v=v2&amp;amp;px=999" role="button" title="detailed error.jpg" alt="detailed error.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So I compared the deployment agent backup directory contents on both cluster members.&amp;nbsp;&lt;STRONG&gt;/opt/CPda/backup/&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This was restored node&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpda fw1.jpg" style="width: 884px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1588iCA4B061E4F891D8D/image-size/large?v=v2&amp;amp;px=999" role="button" title="cpda fw1.jpg" alt="cpda fw1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;and this was the secondary that was in it's "original" state&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpda fw2.jpg" style="width: 880px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1587iA02E9160D3F88056/image-size/large?v=v2&amp;amp;px=999" role="button" title="cpda fw2.jpg" alt="cpda fw2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Ok - bunch of archives missing..&lt;/P&gt;
&lt;P&gt;Then it clicked - when we restored the box from backup, we did not install all jumbo HFs that were installed over time originally but went straight to the latest take 154 that was running on the node when backup was taken.&lt;/P&gt;
&lt;P&gt;So quick action was simply to copy all missing archives from "original" node&lt;STRONG&gt;&amp;nbsp;/opt/CPda/backup&lt;/STRONG&gt; to restored one and then take 203 installation succeeded.&lt;/P&gt;
&lt;P&gt;It might be a known issue, but there's a definitely room for improvement for CPUSE in case you use backup for restore instead of snapshot&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 07:53:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56157#M4234</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-06-19T07:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56367#M4235</link>
      <description>&lt;P&gt;Just discussed this during User Group meeting in Tallinn at the beginning of this week, and before that, a couple of month ago, in Zurich.&lt;/P&gt;
&lt;P&gt;CPUSE repository is in /var/log partition. This part of your filesystem is not backed up neither by snapshot nor backup tool. When restoring from one of those, it is likely you lose at least some of downloaded packages.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks to me that in your case CPUSE fails after backup restored cause some of those packages are missing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 06:45:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56367#M4235</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-06-25T06:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56369#M4236</link>
      <description>&lt;P&gt;LOL,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;,&amp;nbsp;you basically explained it yourself, I should read till the end before answering.&lt;BR /&gt;&lt;BR /&gt;Anyhow, this is not a bug, this is expected behaviour, but not many people know that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 11:48:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56369#M4236</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-06-21T11:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56491#M4237</link>
      <description>&lt;P&gt;Seems like something we can improve upon.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8469"&gt;@Tsahi_Etziony&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2019 21:43:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56491#M4237</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-23T21:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56535#M4240</link>
      <description>Valeri - backup restore succeeds but the next time we try to install JHF on such box, it will fail. You must have misunderstood the problem</description>
      <pubDate>Mon, 24 Jun 2019 11:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56535#M4240</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-06-24T11:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56536#M4241</link>
      <description>I would disagree on that - so you are saying that if you do disaster recovery using OS re-install and then backup restore, you won't be able to install new JHFs?</description>
      <pubDate>Mon, 24 Jun 2019 11:22:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56536#M4241</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-06-24T11:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56594#M4246</link>
      <description>&lt;P&gt;No, I did not, but I fixed my previous comment to be more correct. It will fail because of some missing package info. Explained why&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 06:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56594#M4246</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-06-25T06:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56599#M4247</link>
      <description>&lt;P&gt;This is the CPUSE mechanism that is depending on backups in a directory/partition that is not included in snapshots and backup. The new HF over HF method may help a lot here as uninstall is not needed anymore for higher version installs.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 07:14:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56599#M4247</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-06-25T07:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56600#M4248</link>
      <description>&lt;P&gt;You are forced to do a OS reinstall, HF / JT reinstall and restore...&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 07:15:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56600#M4248</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-06-25T07:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56601#M4249</link>
      <description>Yeah, but you don't want to re-install every single JHF that was existing on the gateway before it crashed as it can be rather many over 1-2 years. So you want to install the latest that was there when backup was taken. And then CPUSE should take care of any "missing" old JFH info that's irrelevant anyways. I understand that it can be tricky with custom HF but not generic Jumbos - they should be handled by CPUSE without jumping through loops and hoops.&lt;BR /&gt;I checked sk91400 and sk108902 but cannot find any reference that says that when you start restore from fresh OS install, you must re-install all old JHFs in exact order as they were done prior on that GW</description>
      <pubDate>Tue, 25 Jun 2019 07:29:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56601#M4249</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-06-25T07:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56632#M4250</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;I hate to say that, but I think you are wrong here.&lt;/P&gt;
&lt;P&gt;You have mentioned&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk91400" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk91400&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It says in the limitation section: "&lt;SPAN&gt;Restore is only allowed using &lt;U&gt;the same Gaia version on the source and target computers"&lt;/U&gt;&lt;/SPAN&gt;&lt;U&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;That means, before pulling backup, you need to restore the exact combination of binaries, e.i vanilla plus HFAs, before pulling backups. If you do not do that, unexpected results are bound to happen.&lt;/P&gt;
&lt;P&gt;Another case,&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902&lt;/A&gt;&amp;nbsp;describes the optimal combination of snapshots and backups, that would allow you to avoid most of the hustle when restoring GWs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 18:03:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56632#M4250</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-06-25T18:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56635#M4251</link>
      <description>I think there's a difference here between expected behavior (which you document) and optimal behavior &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Tue, 25 Jun 2019 18:52:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56635#M4251</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-25T18:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56656#M4252</link>
      <description>As said earlier, I just think there's room for improvement. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; In our case we had only local snapshots that died when SSD failed so the only option was fresh install along with JHF reinstallation and backup restore. You always want a system that's as simple as possible to restore in critical conditions. But we can park the case now.</description>
      <pubDate>Wed, 26 Jun 2019 04:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56656#M4252</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-06-26T04:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56664#M4255</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;, Agree with you, there is a room to improve built-in disaster recovery tools.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;On the other hand &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Just yesterday during CheckMates Live event in Athens, I was drilling the guys that any critical backup should be taken out, snapshots included. Specifically to cover cases when SSD/HDD fails. It is not straight forward in case of snapshots, I know.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 06:39:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56664#M4255</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-06-26T06:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: CPUSE will fail to install new Jumbo on restored gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56665#M4256</link>
      <description>&lt;P&gt;We had the same issue on MDM 80.20 restored from backup , TAC had do modify cpregistry (after a mont) to make us able to install the latest JHF , guess indeed there are room for improvement here&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 06:41:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPUSE-will-fail-to-install-new-Jumbo-on-restored-gateway/m-p/56665#M4256</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2019-06-26T06:41:55Z</dc:date>
    </item>
  </channel>
</rss>

