<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MDS leaks information to other CMA’s in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161678#M70528</link>
    <description>&lt;P&gt;No this is not the case. In my example it shows up for two: TARGET CMAs.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Nov 2022 13:38:34 GMT</pubDate>
    <dc:creator>pabu</dc:creator>
    <dc:date>2022-11-09T13:38:34Z</dc:date>
    <item>
      <title>MDS leaks information to other CMA’s</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161668#M70526</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;One of my customers run into a strange scenario using MDS (multi-domain server) with a VSX cluster. All running on R81.10 with jumbo GA take 78.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If we create a new VLAN interface in one of &lt;/SPAN&gt;our virtual systems &lt;SPAN&gt;(without doing a policy install&lt;/SPAN&gt;, changed on VS gateway object only&lt;SPAN&gt;), we see in the audit log this interface is created &lt;/SPAN&gt;also &lt;SPAN&gt;within other CMAs. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In &lt;/SPAN&gt;my&lt;SPAN&gt; view this should never be &lt;/SPAN&gt;the case&lt;SPAN&gt;. It seems to be randomly determined in which CMA it is&lt;/SPAN&gt; also&lt;SPAN&gt; created according audit log. It's not really created. We can reproduce this in our lab environment&lt;/SPAN&gt;, added a screenshot&lt;SPAN&gt;.&lt;/SPAN&gt; This screenshot is made in my lab environment where I added a fictional interface bond1.99. The global MDS audit log shows this interface is added in one more CMA’s! This is random behavior. We saw scenarios added to three other CMA’s!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are we dealing with a bug…? Or is this by design…?&lt;/SPAN&gt; What is the experience of the community?&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Regards, Paul&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 12:20:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161668#M70526</guid>
      <dc:creator>pabu</dc:creator>
      <dc:date>2022-11-09T12:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: MDS leaks information to other CMA’s</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161672#M70527</link>
      <description>&lt;P&gt;The only case when it makes sense is if the logs appear on both MAIN and TARGET CMAs. MAIN is one managing the physical VSX object. TARGET is one with the actual VS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check if this is not the case and let us know.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 12:31:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161672#M70527</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-09T12:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: MDS leaks information to other CMA’s</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161678#M70528</link>
      <description>&lt;P&gt;No this is not the case. In my example it shows up for two: TARGET CMAs.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 13:38:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161678#M70528</guid>
      <dc:creator>pabu</dc:creator>
      <dc:date>2022-11-09T13:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: MDS leaks information to other CMA’s</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161681#M70529</link>
      <description>&lt;P&gt;Are those CMAs both have VSs defined on the same cluster? If yes, is there any automatic topology propagation set between those VSs?&lt;BR /&gt;&lt;BR /&gt;If the answer is no, then please open a TAC case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 13:59:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161681#M70529</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-09T13:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: MDS leaks information to other CMA’s</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161736#M70530</link>
      <description>&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;Yes the VS are part of the same cluster (we have just one cluster in this labenvironment):&lt;/P&gt;&lt;P&gt;- Topology Calculation (Calculate topology automatically based on routing informatoin) is enabled on the MAIN CMA, disabled on the TARGET CMA's&lt;/P&gt;&lt;P&gt;- On the interface: "Propagate route to adjacent VD" is disabled&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards, Paul&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 08:22:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MDS-leaks-information-to-other-CMA-s/m-p/161736#M70530</guid>
      <dc:creator>pabu</dc:creator>
      <dc:date>2022-11-10T08:22:00Z</dc:date>
    </item>
  </channel>
</rss>

