<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Generic Datacenter object push interval to gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228980#M44122</link>
    <description>&lt;P&gt;How many gateways are involved in the environment with these objects in the policy?&lt;/P&gt;
&lt;P&gt;vsec.conf otherwise holds relevant parameters.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 05 Oct 2024 14:44:16 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2024-10-05T14:44:16Z</dc:date>
    <item>
      <title>Generic Datacenter object push interval to gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228952#M44109</link>
      <description>&lt;P&gt;In settings&amp;nbsp; of Generic Datacenter object you can specify the pull interval,&amp;nbsp; how often management server should update object from the source URL.&lt;/P&gt;&lt;P&gt;But what is push interval to the gateways where this object used in policy rules?&lt;/P&gt;&lt;P&gt;From my experiments on R81 Take92 management server&lt;/P&gt;&lt;P&gt;I am getting around 15 minutes(!) delay between change of the object on management server and enforcement of the change on gateway.&lt;/P&gt;&lt;P&gt;cloud_proxy.elg&amp;nbsp; shows no errors&lt;/P&gt;&lt;P&gt;Is it by design such interval or where to look for issue or how to change that interval?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 17:35:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228952#M44109</guid>
      <dc:creator>SPM</dc:creator>
      <dc:date>2024-10-04T17:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Datacenter object push interval to gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228957#M44110</link>
      <description>&lt;P&gt;I believe from memory its 300 seconds = 5 mins&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 18:09:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228957#M44110</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-04T18:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Datacenter object push interval to gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228966#M44114</link>
      <description>&lt;P&gt;It looks like it is not&amp;nbsp; 5min&amp;nbsp; but 15min&lt;/P&gt;&lt;P&gt;here is from cloud_proxy.elg&amp;nbsp; end of one request to push changes to gateway and start of the other&lt;/P&gt;&lt;P&gt;04/10/24 18:39:36,063 INFO ida.api.IDACpridRequestSenderClient [gateway-updater_CP1]: Response from gw xx.xxx.xxx.xxx is 'OK'&lt;BR /&gt;04/10/24 19:43:35,344 INFO ida.api.IDACpridRequestSenderClient [gateway-updater_CP1]: Sending update to gw xx.xxx.xxx.xxx: #!/bin/bash&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;one set of objects were changed at 04/10/24 19:29, and the other at 04/10/24 19:35&lt;/P&gt;&lt;P&gt;(there were no more changes since last push at 04/10/24 18:39)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where can I look for this push interval value?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 21:01:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228966#M44114</guid>
      <dc:creator>SPM</dc:creator>
      <dc:date>2024-10-04T21:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Datacenter object push interval to gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228976#M44118</link>
      <description>&lt;P&gt;I thought there was command to check it, but I could be wrong.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 01:13:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228976#M44118</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-05T01:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Datacenter object push interval to gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228980#M44122</link>
      <description>&lt;P&gt;How many gateways are involved in the environment with these objects in the policy?&lt;/P&gt;
&lt;P&gt;vsec.conf otherwise holds relevant parameters.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 14:44:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228980#M44122</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-10-05T14:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Datacenter object push interval to gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228981#M44123</link>
      <description>&lt;P&gt;there are only 2 gateways where these objects used in the policy rules&lt;/P&gt;&lt;P&gt;here is from vsec.conf&lt;/P&gt;&lt;P&gt;# delay time between GW update cycles&lt;BR /&gt;enforcementUpdateIntervalTime=10&lt;/P&gt;&lt;P&gt;# TTL (mins) for objects expiration on GW in case&lt;BR /&gt;# there are no updates from the Controller&lt;BR /&gt;enforcementSessionTimeoutInMinutes=10080&lt;/P&gt;&lt;P&gt;autoUpdateIntervalInSeconds=30&lt;/P&gt;&lt;P&gt;# max number of GWs to update concurrently&lt;BR /&gt;enforcementThreadPool=5&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# Generic Data Center scanner config&lt;BR /&gt;ctf.scannerInterval=60&lt;BR /&gt;ctf.deleteTemporaryFiles=true&lt;BR /&gt;ctf.ignoreInvalidContent=false&lt;BR /&gt;ctf.scanningLogsOn=false&lt;BR /&gt;ctf.scanFlatListFiles=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose this parameter ( ctf.scannerInterval=60 ) determines push interval. So it should be 1min.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is a full timeline from another test:&lt;/P&gt;&lt;P&gt;05/10/24 20:23&amp;nbsp; - Object changed,&amp;nbsp; 1 IP address (lets say it&amp;nbsp;192.0.2.2) added&amp;nbsp;&lt;/P&gt;&lt;P&gt;05/10/24 20:38&amp;nbsp; - Object changed,&amp;nbsp; IP address removed (the same as was added 15min ago, i.e. 192.0.2.2)&lt;/P&gt;&lt;P&gt;05/10/24 20:40 - Changes detected and pushed to gateways but with IP address&amp;nbsp;192.0.2.2 that was added 17min ago and removed 2 min ago&lt;/P&gt;&lt;P&gt;05/10/24 20:49 - Changes detected and pushed to the gateway with IP address&amp;nbsp; 192.0.2.2 removed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No other Generic Datacenter objects where changed during that period, so no interference from other changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 18:31:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Generic-Datacenter-object-push-interval-to-gateway/m-p/228981#M44123</guid>
      <dc:creator>SPM</dc:creator>
      <dc:date>2024-10-05T18:31:51Z</dc:date>
    </item>
  </channel>
</rss>

