<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Installing Policies on an HA cluster one member at a time in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235219#M45593</link>
    <description>&lt;P&gt;We have some soon-to-be-replaced 23000 gateways running r80.40 take 211 in a cluster. In the last few months it has become increasingly difficult to install policy updates on the firewalls with typically the active member of the cluster failing to install the policy and therefore the whole installation fails. I have tried failing over onto the standby and pushing policy and again it will still fail on the new active firewall.&lt;/P&gt;&lt;P&gt;Is a temporary tactic to uncheck the box 'For gateway clusters, if installation on a cluster member fails, do not install on that cluster' and have the install succeed on the standby member, then failover to the standby member, then push the policy again and this time it should then succeed on the new standby firewall? Thereby the new policy is installed on both firewalls.&lt;/P&gt;&lt;P&gt;We have the new firewalls in place and are being built by Checkpoint PS, but with the Christmas change freeze about to start we are not in a position to start using the new firewalls before Jan but we need to make minor changes to the policy.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2024 16:54:33 GMT</pubDate>
    <dc:creator>P_Williams</dc:creator>
    <dc:date>2024-12-10T16:54:33Z</dc:date>
    <item>
      <title>Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235219#M45593</link>
      <description>&lt;P&gt;We have some soon-to-be-replaced 23000 gateways running r80.40 take 211 in a cluster. In the last few months it has become increasingly difficult to install policy updates on the firewalls with typically the active member of the cluster failing to install the policy and therefore the whole installation fails. I have tried failing over onto the standby and pushing policy and again it will still fail on the new active firewall.&lt;/P&gt;&lt;P&gt;Is a temporary tactic to uncheck the box 'For gateway clusters, if installation on a cluster member fails, do not install on that cluster' and have the install succeed on the standby member, then failover to the standby member, then push the policy again and this time it should then succeed on the new standby firewall? Thereby the new policy is installed on both firewalls.&lt;/P&gt;&lt;P&gt;We have the new firewalls in place and are being built by Checkpoint PS, but with the Christmas change freeze about to start we are not in a position to start using the new firewalls before Jan but we need to make minor changes to the policy.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 16:54:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235219#M45593</guid>
      <dc:creator>P_Williams</dc:creator>
      <dc:date>2024-12-10T16:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235244#M45603</link>
      <description>&lt;P&gt;I believe you can do this, yes.&lt;BR /&gt;Note this is something that ElasticXL "fixes" insofar as policy installation happens to the SMO only, which is responsible for copying the policy to the other members.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 20:49:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235244#M45603</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-10T20:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235260#M45605</link>
      <description>&lt;P&gt;This is indeed a workaround for this issue&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 00:01:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235260#M45605</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-11T00:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235414#M45632</link>
      <description>&lt;P&gt;What about doing fw fetch -m individually on cluster members? If I recall correctly, it pulls the policy from the server that is defined in masters file and writes it to kernel individually. But I'm not sure about the sync between members after that point. Maybe someone can add to it.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 06:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235414#M45632</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-12-12T06:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235417#M45634</link>
      <description>&lt;P&gt;Indeed &lt;STRONG&gt;fw fetch &amp;lt;Security Management Server name&amp;gt;&lt;/STRONG&gt; will also work:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_CLI_ReferenceGuide/Content/Topics-CLIG/FWG/fw-fetch.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_CLI_ReferenceGuide/Content/Topics-CLIG/FWG/fw-fetch.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems the -c flag also allows to fetch policy from a Cluster member&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 06:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235417#M45634</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-12-12T06:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235418#M45635</link>
      <description>&lt;P&gt;Hypothetically, let's say that I did it with -m flag and forgot to do the same on the other member. Will the policies ever get synced between members, or do I need to come back and do a -c anyway?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 06:57:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235418#M45635</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-12-12T06:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235425#M45637</link>
      <description>&lt;P&gt;Not sure you even need the -m flag&lt;/P&gt;
&lt;P&gt;But yes, you can either fetch the policy (on the other cluster member) directly from the Security Management Server or from the other cluster using -c&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 08:03:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235425#M45637</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-12-12T08:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Policies on an HA cluster one member at a time</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235444#M45644</link>
      <description>&lt;P&gt;Accepting this as it was the first response. I have now tried the method and it worked. I think the two firewalls had different policies for less than 10 minutes.&lt;BR /&gt;&lt;BR /&gt;I will look into the other methods listed here as well. I think though as it is an old setup about to be pulled out I dont really want to start trying out something new, but something to look into for the new environment should there be similar issues.&lt;/P&gt;&lt;P&gt;Thank you all for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 09:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Installing-Policies-on-an-HA-cluster-one-member-at-a-time/m-p/235444#M45644</guid>
      <dc:creator>P_Williams</dc:creator>
      <dc:date>2024-12-12T09:19:45Z</dc:date>
    </item>
  </channel>
</rss>

