<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uptime Restart practice in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uptime-Restart-practice/m-p/243584#M47332</link>
    <description>&lt;P&gt;We have a goal to get to "always on recommended".&amp;nbsp; Not there yet.&lt;BR /&gt;&lt;BR /&gt;Sidebar - At a former employer, we had some Sun gateways.&amp;nbsp; The hardware was "end of Ebay" (there is end of life, end of support, and end of EBay - parts can no longer be found even on Ebay).&amp;nbsp; No restart as the hard drives would probably not restart if they were rebooted.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Mar 2025 14:40:17 GMT</pubDate>
    <dc:creator>George_Ellis</dc:creator>
    <dc:date>2025-03-11T14:40:17Z</dc:date>
    <item>
      <title>Uptime Restart practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uptime-Restart-practice/m-p/243567#M47325</link>
      <description>&lt;P&gt;I do not see this metric included anywhere.&amp;nbsp; Hence, the query for the community.&lt;BR /&gt;&lt;BR /&gt;What would be a reasonable length of time before we would consider restarting a gateway?&lt;BR /&gt;&lt;BR /&gt;Days in the past (I started with R55), we generally accepted 180 days of uptime as being a candidate for restarting a gateway.&amp;nbsp; Memory leaks, heap issues, errant code, and other strange things tended to destabilize a box over time.&amp;nbsp; Issues were avoided, especially before an upgrade, by restarting a gateway before changes were made.&lt;BR /&gt;&lt;BR /&gt;What would you consider a reasonable uptime to target restarts?&amp;nbsp; Or is that considered an issue anymore (I think it still is)?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 13:18:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uptime-Restart-practice/m-p/243567#M47325</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2025-03-11T13:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Uptime Restart practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uptime-Restart-practice/m-p/243579#M47328</link>
      <description>&lt;P&gt;I've had firewalls which have run for over eight years with no reboots. That was mostly because the applications which sent traffic through them had conflicting windows for potentially-disruptive changes, and we could never get a window from all of them at the same time.&lt;/P&gt;
&lt;P&gt;Long uptime gives me hives because it means you haven't recently tested to be sure the firewall can come back up after losing power. I've had a few datacenter-wide power outages (fire in the power distribution room, state superconducting grid outages, etc.). Every time, some system which has been too critical to maintain hasn't come back up. Most of the times, they're not one of my systems, but a few have been.&lt;/P&gt;
&lt;P&gt;Today, we install a jumbo every 180 days at most, and I'm working towards every 90 days. For years, the first response on every ticket we opened was "You're on an old version. Jumbos include a lot of fixes. Try updating the jumbo and tell us if the issue is still present." Since we've gotten serious about more frequent updates, we get that a lot less, and every ticket spends a week less dealing with that kind of boilerplate. The work to let us update more frequently (e.g, &lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/Finding-differences-between-cluster-members/m-p/236908/highlight/true#M8906" target="_self"&gt;finding and eliminating differences between cluster members&lt;/A&gt;) has also led to much greater overall reliability on our firewalls.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 14:16:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uptime-Restart-practice/m-p/243579#M47328</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-03-11T14:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: Uptime Restart practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uptime-Restart-practice/m-p/243584#M47332</link>
      <description>&lt;P&gt;We have a goal to get to "always on recommended".&amp;nbsp; Not there yet.&lt;BR /&gt;&lt;BR /&gt;Sidebar - At a former employer, we had some Sun gateways.&amp;nbsp; The hardware was "end of Ebay" (there is end of life, end of support, and end of EBay - parts can no longer be found even on Ebay).&amp;nbsp; No restart as the hard drives would probably not restart if they were rebooted.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 14:40:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uptime-Restart-practice/m-p/243584#M47332</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2025-03-11T14:40:17Z</dc:date>
    </item>
  </channel>
</rss>

