<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway Cluster Failover procedure in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132105#M74197</link>
    <description>&lt;P&gt;I know some people do cpstop as well, but personally, Im not big fan of doing it that way, since it removes the currently installed policy. I would definitely follow what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;suggested. Besides, it is vendor recommended.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 12:21:18 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-10-19T12:21:18Z</dc:date>
    <item>
      <title>Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131883#M74185</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Years ago we had a 3rd party support vendor managing our checkpoint firewalls, and they used to failover traffic in a cluster by downing one of the members.&lt;/P&gt;&lt;P&gt;On a support call with checkpoint for some issue, we were advised by the checkpoint engineer not to do that, but to change the member priority in the management cluster object and install policy, so we have been using that process ever since.&lt;/P&gt;&lt;P&gt;On another support call recently with a new set of checkpoint engineers we have been told that process is not recommended for cluster failover.&lt;/P&gt;&lt;P&gt;What method do you all use, and is there a documented recommended process we should be following?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 09:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131883#M74185</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-10-17T09:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131886#M74186</link>
      <description>&lt;P&gt;Each has its merits depending on the scenario that you're working in, what's the context of the event warranting the failover?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 11:31:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131886#M74186</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-10-17T11:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131887#M74187</link>
      <description>&lt;P&gt;We use it in all cases where we want traffic to use the other box in a cluster, either for maintenance or troubleshooting&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 11:34:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131887#M74187</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-10-17T11:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131890#M74188</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do not know if this is what you were looking for, but the official documentation has a section on&amp;nbsp;&lt;STRONG&gt;How to Initiate Cluster&amp;nbsp;Failover:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/How-to-initiate-cluster-failover.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/How-to-initiate-cluster-failover.htm&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It also leads to a Best Practice SK:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Best Practices - Manual fail-over in ClusterXL&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk55081" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk55081&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="No_Page_Break_Inside"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Sun, 17 Oct 2021 13:04:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131890#M74188</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2021-10-17T13:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131898#M74189</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;That matches what we heard from support engineers this week&lt;/P&gt;&lt;P&gt;I guess my other question now is were we the only people who changed priority and pushed policy as a means of adjusting traffic through the clusters?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 13:15:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131898#M74189</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-10-17T13:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131902#M74190</link>
      <description>&lt;P&gt;Can depend on the resolver groups involved, in some organisations not everyone will have direct CLI access to a Firewall cluster member.&lt;/P&gt;
&lt;P&gt;The other method also needs an extra step to return the node to a standby state as you would be aware.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 13:31:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131902#M74190</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-10-17T13:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131914#M74191</link>
      <description>&lt;P&gt;I would agree 100% with what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;said in this thread. I had been doing it same way for years and never an issue. Essentially, if you run clusterXL_admin down on current active, it will become standby and when you run clusterXL_admin up, it will still stay standby, so definitely in my opinion, safest way of doing a failover. Im not sure what different engineers told you, but I am positive this is recommended Check Point process.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 21:00:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131914#M74191</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-17T21:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131916#M74192</link>
      <description>&lt;P&gt;How is it if you using "switch to higher priority cluster member" on member recovery, if doing the clusterXL_admin up, i think it switches over at that time. (not 100% sure)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 21:39:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131916#M74192</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2021-10-17T21:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131918#M74193</link>
      <description>&lt;P&gt;Thanks for all the replies. They prompted another question.&lt;/P&gt;&lt;P&gt;If I admin down 1 box in the cluster, what happens if the other box suffers a failure?&lt;/P&gt;&lt;P&gt;Perhaps I should have specified circumstances when traffic might be on the other member for some period of time?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 22:22:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131918#M74193</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-10-17T22:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131919#M74194</link>
      <description>&lt;P&gt;That is very unlikely scenario...I mean, what are the chances if you were using say ISP redundancy and you downed one link to test 2nd one and 2nd one went down right after? Thats literally less than 1% possibility...highly unlikely.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 23:01:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/131919#M74194</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-17T23:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132037#M74195</link>
      <description>&lt;P&gt;Well, it depends... clusterXL_admin down creates a failed cluster resource, making the cluster member "less healthy" than the other.&lt;/P&gt;&lt;P&gt;Small failures like interfaces going down should not make it active again, but if the other fails completely (crashes or reboots), it still becomes active attention.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 07:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132037#M74195</guid>
      <dc:creator>Arne_Boettger</dc:creator>
      <dc:date>2021-10-19T07:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132087#M74196</link>
      <description>&lt;P&gt;I guess that it would be interesting to take into consideration also the cluster type, like VRRP and/or ClusterXL for instance.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 11:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132087#M74196</guid>
      <dc:creator>rrbranco</dc:creator>
      <dc:date>2021-10-19T11:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132105#M74197</link>
      <description>&lt;P&gt;I know some people do cpstop as well, but personally, Im not big fan of doing it that way, since it removes the currently installed policy. I would definitely follow what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;suggested. Besides, it is vendor recommended.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 12:21:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132105#M74197</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-19T12:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132107#M74198</link>
      <description>&lt;P&gt;You can run cpstop with specific flags that maintain the policy and connection table:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sk113045&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113045" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113045&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;[Expert@HostName:0]# cpstop -fwflag -proc&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Running this command will stop Check Point daemons and Security Servers, while maintaining the active Security Policy running in the Check Point kernel. Rules with generic Allow/Reject/Drop actions, based on services, will continue to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or if you want to load the Default Filter:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;[Expert@HostName:0]# cpstop -fwflag -default&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Running this command will stop Check Point daemons and Security Servers. The active Security Policy running in the Check Point kernel will be replaced with the Default Filter policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also see:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CLI_ReferenceGuide/Topics-CLIG/FWG/cpstop.htm?Highlight=cpstop" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CLI_ReferenceGuide/Topics-CLIG/FWG/cpstop.htm?Highlight=cpstop&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;cpstop -fwflag -proc&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Shuts down&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_cp variable"&gt;Check Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;processes&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Keeps the currently loaded kernel policy&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Maintains the Connections table, so that after you run the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="MCXref xref" href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CLI_ReferenceGuide/Topics-CLIG/FWG/cpstart.htm" data-mc-conditions="Condition-Tag-Set-Deliverables.Deliverable_CLIG" target="_blank"&gt;cpstart&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command, you do not experience dropped packets because they are "out of state"&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 19 Oct 2021 12:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132107#M74198</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2021-10-19T12:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Cluster Failover procedure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132141#M74199</link>
      <description>&lt;P&gt;Thanks for that, was not aware of the sk, but thats helpful!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 17:17:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-Cluster-Failover-procedure/m-p/132141#M74199</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-19T17:17:02Z</dc:date>
    </item>
  </channel>
</rss>

