<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Removing Blades from Offline gatway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/117901#M75970</link>
    <description>&lt;P&gt;Thanks Tobias, I will try this out, I think we might have tested it. But since our aws production is suffering during the delay period we did not have much time to test.&amp;nbsp; I will recreate the issue in a lab env en try it.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2021 08:04:12 GMT</pubDate>
    <dc:creator>RasmusH</dc:creator>
    <dc:date>2021-05-07T08:04:12Z</dc:date>
    <item>
      <title>Removing Blades from Offline gatway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/117547#M75968</link>
      <description>&lt;P&gt;Hi Checkmates!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have an issue with our management(MDS) when an Identity Awareness -blade is not disabled/removed before the gate is taken offline.&lt;BR /&gt;ex:&lt;BR /&gt;One of our gateways was taken offline. And all gates in our environment has IA-blade enabled for the sake of being able to handle network tags from AWS and Azure. (Data Center Objects).&lt;BR /&gt;&lt;BR /&gt;But when a gate with IA is not responsive you get a time out in the round robin update of data center objects/tags&lt;BR /&gt;&lt;BR /&gt;Checkpoint management server error:&lt;BR /&gt;"&lt;BR /&gt;03/05/21 11:16:27,565 ERROR datacenter.util.CommandExec [gateway-updater_&amp;lt;GATEWAYNAME&amp;gt;]: Command '[/opt/CPshrd-R80.40/bin/cprid_util, -server, &amp;lt;GW-IP&amp;gt;, putfile, -local_file, /opt/CPmds-R80.40/customers/cma2/CPsuite-R80.40/fw1/tmp/GATEWAYNAME_vsecUpdate.sh, -remote_file, /tmp/GATEWAYNAME_vsecUpdate.sh]' failed with code 3. Stdout=''. Stderr=''.&lt;BR /&gt;"&lt;BR /&gt;"&lt;BR /&gt;03/05/21 12:03:04,605 ERROR ida.api.IDACpridRequestSenderClient [gateway-updater_GATEWAYNAME]: Failure 1/5 to send script file to gateway ip:&amp;nbsp;&amp;lt;GW-IP&amp;gt;&lt;BR /&gt;"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;During the period the server tries to update this gateway, all other updates is at a standstill. So with our AWS environment that is constantly changing&amp;nbsp;IP's the deploys etc get slowed down with about 1 minute every 60 sec. (def update interval.)&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;When like in this case a gate is offline&amp;nbsp;and have IA activated. You can't simply uncheck the IA blade and install, since you can't install a offline GW. We have had other cases when gates is&amp;nbsp;decommissioned and we missed to disable IA before it was shut down. Then we solved it; removing the cluster completely&amp;nbsp;from the management.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there a solution to disable the blade on a Offline Gateway in the management config or a better workaround for this issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 03 May 2021 12:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/117547#M75968</guid>
      <dc:creator>RasmusH</dc:creator>
      <dc:date>2021-05-03T12:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Blades from Offline gatway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/117651#M75969</link>
      <description>&lt;P&gt;Have you tried disabling IA blade in the offline gateways and do an "Install database" afterwards?&lt;/P&gt;
&lt;P&gt;I guess this would inform management about disabled IA blade for this gateway.&lt;/P&gt;
&lt;P&gt;I've never tested this, so this is just a wild guess.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 15:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/117651#M75969</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-05-04T15:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Blades from Offline gatway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/117901#M75970</link>
      <description>&lt;P&gt;Thanks Tobias, I will try this out, I think we might have tested it. But since our aws production is suffering during the delay period we did not have much time to test.&amp;nbsp; I will recreate the issue in a lab env en try it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 08:04:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/117901#M75970</guid>
      <dc:creator>RasmusH</dc:creator>
      <dc:date>2021-05-07T08:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Blades from Offline gatway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/135891#M75971</link>
      <description>&lt;P&gt;Unfortunately this did not help. Even disabling IA blade and installing database, did not help our issue.&amp;nbsp;&lt;BR /&gt;Still get:&amp;nbsp;&lt;/P&gt;&lt;P&gt;779 ERROR ida.api.IDACpridRequestSenderClient [gateway-updater_GATEWAYNAME]: Failure 3/3 to send script file to gateway ip: GATEWAY-IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;780 ERROR ida.requests.IDARequestsSender [gateway-updater_GATEWAYNAME]: Error while attempt to connect to server: GATEWAY-IP&lt;BR /&gt;&lt;BR /&gt;Making slow update/deploys on new instances in aws. Since the TAG's don't update in the management the instances don't get the correct access. Like a auto-scaled service and we get interruptions in or services.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We are now looking (since R81) on changing the timeouts and retires in the cloud_proxy config.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 09:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Removing-Blades-from-Offline-gatway/m-p/135891#M75971</guid>
      <dc:creator>RasmusH</dc:creator>
      <dc:date>2021-12-09T09:29:31Z</dc:date>
    </item>
  </channel>
</rss>

