<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint Gateway backup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248648#M48588</link>
    <description>&lt;P&gt;Appears as Val had said its just a simple no-nat rule, thats it, does not need any other network changes.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 12 May 2025 11:41:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-05-12T11:41:11Z</dc:date>
    <item>
      <title>CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248621#M48576</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Our&amp;nbsp; environment consists of 2 Checkpoint Clusters (External &amp;amp; Internal Firewall) where each cluster comprises of three nodes. Also we've got two SMS servers in Active-Standby. All Gateways as well as management Servers are on 81.20 version. My issue is that when i am trying to backup gateway config via TFTP server this works only for active members, for standby nodes this fails. I am able to backup both SMS without any issue. Is there something i am missing. Fyi, TFTP Server is on the same subnet as the management network of all gateways. Also i've created the firewall policies required. Could you please assist on what i am missing?&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 10:41:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248621#M48576</guid>
      <dc:creator>katsarasd</dc:creator>
      <dc:date>2025-05-12T10:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248622#M48577</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96220"&gt;@katsarasd&lt;/a&gt;&amp;nbsp;I moved your post to the more appropriate space and also fixed the label.&lt;/P&gt;
&lt;P&gt;In the cluster, connections from Standby member through a cluster interface may fail because they are NAT-ed behind VIP.&lt;BR /&gt;&lt;BR /&gt;There are two options here:&lt;BR /&gt;1. use a private interface to open a connection to a backup server&lt;/P&gt;
&lt;P&gt;2. Apply a workaround mentioned in&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk169975" target="_self"&gt;&lt;SPAN&gt;sk169975&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would suggest the second option, as it is much simpler to move forward and does not require any network change.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 10:44:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248622#M48577</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-05-12T10:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248625#M48579</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TFTP Server is on the same subnet as gateways management interface. Is there something additional i need to specify ?&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 10:57:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248625#M48579</guid>
      <dc:creator>katsarasd</dc:creator>
      <dc:date>2025-05-12T10:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248628#M48580</link>
      <description>&lt;P&gt;Even if it is on the same network, if the GW is communicating with it on a cluster interface, it will be NAT-ed behind a VIP address. Did you read the SK I suggested?&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248628#M48580</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-05-12T11:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248629#M48581</link>
      <description>&lt;P&gt;You are abe to ping the TFTP server from the STANDBY member?&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:07:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248629#M48581</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-05-12T11:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248630#M48582</link>
      <description>&lt;P&gt;Yes standby members can ping tftp server&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:08:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248630#M48582</guid>
      <dc:creator>katsarasd</dc:creator>
      <dc:date>2025-05-12T11:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248636#M48583</link>
      <description>&lt;P&gt;Maybe can you do a telnet test to the&amp;nbsp; TFTP server? Maybe there is a service which is not TFTP, and you can make a test. Only the TFTP is failing?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:16:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248636#M48583</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-05-12T11:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248638#M48584</link>
      <description>&lt;P&gt;I tried nc -v &amp;lt;server ip address&amp;gt; rdp port&lt;BR /&gt;for active member connection works&lt;BR /&gt;for standby members connection timeout&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248638#M48584</guid>
      <dc:creator>katsarasd</dc:creator>
      <dc:date>2025-05-12T11:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248640#M48585</link>
      <description>&lt;P&gt;As I already mentioned, look into the SK. You will have to create No-NAT rule for the standby to work.&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:27:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248640#M48585</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-05-12T11:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248646#M48587</link>
      <description>&lt;P&gt;Sorry, but i am bit confused.&lt;/P&gt;&lt;P&gt;The cause of the issue of the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk169975" target="_self" rel="noreferrer"&gt;&lt;SPAN&gt;sk169975 &lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;is of the no-nat rules. You mention above that i'll need to create no-nat rules for standby, it's not clear to me. sorry for the trouble.&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248646#M48587</guid>
      <dc:creator>katsarasd</dc:creator>
      <dc:date>2025-05-12T11:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248648#M48588</link>
      <description>&lt;P&gt;Appears as Val had said its just a simple no-nat rule, thats it, does not need any other network changes.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248648#M48588</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-12T11:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248669#M48597</link>
      <description>&lt;P&gt;No worries, the SK is indeed describing a bit different case, but it does have a link to the solution you need:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk34180" target="_self"&gt;&lt;SPAN&gt;sk34180&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Please check it is clear enough, and let me know if it helps.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 13:43:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248669#M48597</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-05-12T13:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248671#M48599</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96220"&gt;@katsarasd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did some more checking on this and found below sk...not sure if it may apply to you, but worth confirming.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181866" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181866&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 14:04:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-backup/m-p/248671#M48599</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-12T14:04:08Z</dc:date>
    </item>
  </channel>
</rss>

