<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS error affecting CP updates in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69297#M5299</link>
    <description>&lt;P&gt;Another vote for&amp;nbsp; sk43807.&amp;nbsp; Had a couple of instances where I had this exact issue, and step 4 of the aforementioned SK resolved it for me each time.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2019 11:53:11 GMT</pubDate>
    <dc:creator>Ruan_Kotze</dc:creator>
    <dc:date>2019-12-04T11:53:11Z</dc:date>
    <item>
      <title>DNS error affecting CP updates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69286#M5296</link>
      <description>&lt;P&gt;Hello all.&lt;/P&gt;&lt;P&gt;My second question here.&amp;nbsp; Hopefully I will supply all the necessary information.&lt;/P&gt;&lt;P&gt;My organisation has a ClusterXL HA pair of 5900 appliances running R80.20 Jumbo HF take 118.&amp;nbsp; I have noticed on SmartConsole Gateways &amp;amp; Servers that the standby node is showing an error.&amp;nbsp; Looking at the Device Status of the node, the IPS, Anti-Bot &amp;amp; Anti-Virus blades are displaying 'Error: Update failed. Contract entitlement check failed.&amp;nbsp;Could not reach"updates.checkpoint.com". Check DNS and Proxy configuration on the gateway'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have connected via SSH to both nodes in the cluster and verified that I can ping external and internal endpoints from both nodes.&amp;nbsp; I entered Expert mode on both nodes&amp;nbsp;and ran&amp;nbsp;dig against a known internal and external domain name.&amp;nbsp; This was successful on the active node but failed on the problematic standby node with 'connection timed out; no servers could be reached'.&lt;/P&gt;&lt;P&gt;I power cycled the standby node this morning.&amp;nbsp; I am now seeing Connection Alerts in the SmartConsole log for DNS queries originating from the problematic gateway.&amp;nbsp; The reason is 'Firewall - Domain resolving error.&amp;nbsp;Check DNS configuration on the gateway (0)'.&amp;nbsp; We are not using domain objects.&lt;/P&gt;&lt;P&gt;Both HA nodes have identical NAT and policy.&lt;/P&gt;&lt;P&gt;I have reviewed &lt;A href="https://community.checkpoint.com/t5/General-Topics/DNS-Error-Message/m-p/62048#M12598" target="_blank" rel="noopener"&gt;DNS Error Message &lt;/A&gt;&amp;nbsp;but it does not appear relevant.&lt;/P&gt;&lt;P&gt;It may be unrelated, but there is a noticeable delay between entering the username and the password prompt appearing when accessing the problematic node via ssh.&lt;/P&gt;&lt;P&gt;I'm wondering what else I can test before pushing the issue out to TAC.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 11:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69286#M5296</guid>
      <dc:creator>AndyDixon</dc:creator>
      <dc:date>2019-12-04T11:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: DNS error affecting CP updates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69292#M5298</link>
      <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43807&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43807&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is what would work through.&amp;nbsp; &amp;nbsp;The SK it relates too is more about access to the standby box.&lt;/P&gt;&lt;P&gt;Doesn't happen everytime but this SK has resolved everytime has happened, sometimes the kernel parameter enough other times have to do the Rules to Not Hide Traffic from the box behind the Cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 11:34:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69292#M5298</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-12-04T11:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNS error affecting CP updates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69297#M5299</link>
      <description>&lt;P&gt;Another vote for&amp;nbsp; sk43807.&amp;nbsp; Had a couple of instances where I had this exact issue, and step 4 of the aforementioned SK resolved it for me each time.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 11:53:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69297#M5299</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2019-12-04T11:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: DNS error affecting CP updates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69350#M5307</link>
      <description>&lt;P&gt;Thanks both.&lt;/P&gt;&lt;P&gt;I followed the SK you referenced and step 4 resolved the issue for me.&amp;nbsp; Apologies, I didn't find that SK when I was carrying out initial investigations.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 16:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69350#M5307</guid>
      <dc:creator>AndyDixon</dc:creator>
      <dc:date>2019-12-04T16:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNS error affecting CP updates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69354#M5309</link>
      <description>&lt;P&gt;Not a problem, I was just looking for an SK that I knew existed and was struggling to find it.&amp;nbsp; &amp;nbsp;Sometimes the SK searching can be "interesting" as don't always get back what looking for.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 16:45:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69354#M5309</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-12-04T16:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS error affecting CP updates</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69360#M5314</link>
      <description>Another way to deal with this issue is to create 2 no-NAT rules, as your standby gateway traffic is hidden behind the cluster IP, when you add a rule that says when traffic is originating from the gateway (add a rule for each cluster member) to any, use original (as long as you objects have the external IP on them, otherwise create 2 objects with the Internet IP's and use those objects in the no-NAT rules).</description>
      <pubDate>Wed, 04 Dec 2019 18:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-error-affecting-CP-updates/m-p/69360#M5314</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-12-04T18:09:10Z</dc:date>
    </item>
  </channel>
</rss>

