<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MDPS Separation breaks existing management communication in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239459#M46443</link>
    <description>&lt;P&gt;What version/JHF?&lt;BR /&gt;Might need TAC to assist here.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2025 13:09:46 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-01-23T13:09:46Z</dc:date>
    <item>
      <title>MDPS Separation breaks existing management communication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239106#M46393</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have enabled MDPS separation following the sk138672 article in my LAB setup before deploying it in production.&lt;/P&gt;&lt;P&gt;Before enabling MDPS separation, I had a standard clusterXL setup with a default route pointed towards the management gateway and BGP routes towards the VLAN interfaces.&lt;/P&gt;&lt;P&gt;Below is the script I followed.&lt;/P&gt;&lt;P&gt;clish&lt;/P&gt;&lt;P&gt;set mdps interface Mgmt management on&lt;BR /&gt;set mdps interface Sync sync on&lt;BR /&gt;set mdps mgmt plane on&lt;BR /&gt;set mdps mgmt resource on&lt;BR /&gt;save config&lt;/P&gt;&lt;P&gt;set mdps environment mplane&lt;BR /&gt;set static-route default nexthop gateway address x.x.x.x on&lt;BR /&gt;save config&lt;BR /&gt;reboot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have changed the 26000 devices, and it took a very long time to come UP with the firewalls after the reboot.&lt;/P&gt;&lt;P&gt;Once firewalls appeared, I disabled the management route from the "dplane" and only left the default route via mgmt.&lt;/P&gt;&lt;P&gt;After this separation, I lost access to the firewalls via management, and BGP communication on the "dplane" went entirely down.&lt;/P&gt;&lt;P&gt;Also, there is a loss of communication between the management server and the inability to retrieve or push any firewall policy via the management server.&lt;/P&gt;&lt;P&gt;I have tried resetting the SIC, but the communication is completely broken.&lt;/P&gt;&lt;P&gt;Does anyone have the same experience and overcome the situation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;T&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 01:45:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239106#M46393</guid>
      <dc:creator>Thanux89</dc:creator>
      <dc:date>2025-01-21T01:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: MDPS Separation breaks existing management communication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239459#M46443</link>
      <description>&lt;P&gt;What version/JHF?&lt;BR /&gt;Might need TAC to assist here.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 13:09:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239459#M46443</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-23T13:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: MDPS Separation breaks existing management communication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239511#M46467</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am working on getting some assistance.&lt;/P&gt;&lt;P&gt;It's R81.20 Take 89&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;T&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 23:41:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239511#M46467</guid>
      <dc:creator>Thanux89</dc:creator>
      <dc:date>2025-01-23T23:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: MDPS Separation breaks existing management communication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239513#M46469</link>
      <description>&lt;P&gt;During my observations, I have observed that after multiple reboots, the firewalls are responding to the management via SSH, and the GUI is not responding.&lt;/P&gt;&lt;P&gt;Also, when the firewall is rebooting, SecureXL does not come UP.&lt;/P&gt;&lt;P&gt;"SecureXL disabled, cannot use affinity commands"&lt;/P&gt;&lt;P&gt;I am unsure whether I need to create the cluster in the management server as the SIC is not forming with the existing cluster object.&lt;/P&gt;&lt;P&gt;I can switch between mplane and dplane, and I was having BGP peering before the conversation, and the BGP is showing down after the MDPS&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;T&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 23:47:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239513#M46469</guid>
      <dc:creator>Thanux89</dc:creator>
      <dc:date>2025-01-23T23:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: MDPS Separation breaks existing management communication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239514#M46470</link>
      <description>&lt;P&gt;I don't think MDPS turns off SecureXL, but something is clearly amiss (thus why I'm suggesting a TAC case).&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 00:25:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDPS-Separation-breaks-existing-management-communication/m-p/239514#M46470</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-24T00:25:37Z</dc:date>
    </item>
  </channel>
</rss>

