<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SmartConsole opens in standby (read-only mode) when gateway fails over to backup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66249#M5050</link>
    <description>&lt;P&gt;Am also from this believing that you point your SmartConsole at the CLUSTER IP rather then individual member that is active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you MUST remember here is that in a Full HA solution then you have running&lt;/P&gt;&lt;P&gt;Mgmt HA and Gateway HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just because the Gateway has failed over does not mean that the Management has.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can ( and seen people do this all too easily ) is that they break the Management Synch as fail the Cluster over (ie the Gateway ) then use the Cluster IP to login to the SmartConsole, promote the Standby Management to Active which makes that Active but doesn't make the Other Management part into Standby&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way to stop this is to actually login to SmartConsole using the Member IP of the Firewall.&lt;/P&gt;&lt;P&gt;So you have your Cluster&lt;/P&gt;&lt;P&gt;Member 1 is Active for Gateway and Management&lt;/P&gt;&lt;P&gt;Member 2 is Standby for Gateway and Management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You run clusterXL_admin down on Member 1 which fails the Gateway over to Member 2 but will NOT fail the Management over.&lt;/P&gt;&lt;P&gt;So you now point the SmartConsole IP at Member 1 and login and will be Active and can make policy changes.&lt;/P&gt;&lt;P&gt;Point the SmartConsole IP at Member 2 and login will be Standby or Read-Only mode.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2019 13:39:12 GMT</pubDate>
    <dc:creator>mdjmcnally</dc:creator>
    <dc:date>2019-10-30T13:39:12Z</dc:date>
    <item>
      <title>SmartConsole opens in standby (read-only mode) when gateway fails over to backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66244#M5049</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Standalone Full HA deployment currently running 80.10.&amp;nbsp; Firewalls are not in Production yet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;After simulating a failure to the active firewall and then opening SmartConsole, it opens up in Read-Only mode and I'm unable to make any policy changes whilst the standby firewall is running as the active firewall.&lt;/P&gt;&lt;P&gt;Why is this and how can it be resolved?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 13:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66244#M5049</guid>
      <dc:creator>ken_networks</dc:creator>
      <dc:date>2019-10-30T13:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole opens in standby (read-only mode) when gateway fails over to backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66249#M5050</link>
      <description>&lt;P&gt;Am also from this believing that you point your SmartConsole at the CLUSTER IP rather then individual member that is active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you MUST remember here is that in a Full HA solution then you have running&lt;/P&gt;&lt;P&gt;Mgmt HA and Gateway HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just because the Gateway has failed over does not mean that the Management has.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can ( and seen people do this all too easily ) is that they break the Management Synch as fail the Cluster over (ie the Gateway ) then use the Cluster IP to login to the SmartConsole, promote the Standby Management to Active which makes that Active but doesn't make the Other Management part into Standby&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way to stop this is to actually login to SmartConsole using the Member IP of the Firewall.&lt;/P&gt;&lt;P&gt;So you have your Cluster&lt;/P&gt;&lt;P&gt;Member 1 is Active for Gateway and Management&lt;/P&gt;&lt;P&gt;Member 2 is Standby for Gateway and Management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You run clusterXL_admin down on Member 1 which fails the Gateway over to Member 2 but will NOT fail the Management over.&lt;/P&gt;&lt;P&gt;So you now point the SmartConsole IP at Member 1 and login and will be Active and can make policy changes.&lt;/P&gt;&lt;P&gt;Point the SmartConsole IP at Member 2 and login will be Standby or Read-Only mode.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 13:39:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66249#M5050</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-10-30T13:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole opens in standby (read-only mode) when gateway fails over to backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66252#M5051</link>
      <description>&lt;P&gt;Fool HA deployment is a kind of last available resort if all money has run out.... I would not suggest that to anyone.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 14:00:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66252#M5051</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-30T14:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole opens in standby (read-only mode) when gateway fails over to backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66265#M5052</link>
      <description>&lt;P&gt;If it's provides HA management and HA gateway, why is this deployment not recommended?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 15:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66265#M5052</guid>
      <dc:creator>ken_networks</dc:creator>
      <dc:date>2019-10-30T15:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: SmartConsole opens in standby (read-only mode) when gateway fails over to backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66268#M5053</link>
      <description>&lt;P&gt;Because the Appliances are not really that good for Management purposes.&lt;/P&gt;&lt;P&gt;So you are taking away Gateway Performance by having the Gateway and Management on 1 box.&amp;nbsp; You are buying bigger gateways then you need to allow for the Gateway and Management performance to be acceptable.&lt;/P&gt;&lt;P&gt;You also get people that don't realize that the Management and Gateway HA is seperate so point at the Cluster IP and then complain when the Mgmt Server synch is broken.&amp;nbsp; &amp;nbsp;( had quite a few support calls with that )&lt;/P&gt;&lt;P&gt;If you MUST run with Full HA like this then would suggest that run&lt;/P&gt;&lt;P&gt;Gateway HA - Member 1 Active, Member 2 Standby&lt;/P&gt;&lt;P&gt;Mgmt HA - Member 1 Standby, Member 2 Active&lt;/P&gt;&lt;P&gt;point your SmartConsole at Member 2 IP address NOT the Cluster address.&lt;/P&gt;&lt;P&gt;and remember that Mgmt and Gateway HA may not move together but are separate despite being installed on the same box&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel that they allowed this simply so those 1 to 2 page summary reviews shows that don't need a seperate management server.&lt;/P&gt;&lt;P&gt;Have seen some reviews criticize as not a WebUI driven product but have to install the SmartConsole as well.&lt;/P&gt;&lt;P&gt;About a good idea as the Windows 7 Management Server idea that they went with.&amp;nbsp; &amp;nbsp;Thankfully didn't move with Windows 8 and 10 for that.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 16:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartConsole-opens-in-standby-read-only-mode-when-gateway-fails/m-p/66268#M5053</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-10-30T16:08:11Z</dc:date>
    </item>
  </channel>
</rss>

