<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Resetting SIC after adding secondary Management server and doing failover in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Resetting-SIC-after-adding-secondary-Management-server-and-doing/m-p/61078#M84331</link>
    <description>&lt;P&gt;No, it is not normal. You have to install policy from both managements. You can try to initiate full sync manually and install the database from Primary management (first installed), install policy from Primary and after that try to do switch to the Secondary management and check SIC status from Secondary.&lt;/P&gt;
&lt;P&gt;if does not help, check routing on both managements and the gateways. Try to perform tcpdump on the gateway to see if SIC port reached the gateway.&lt;/P&gt;</description>
    <pubDate>Sat, 24 Aug 2019 06:31:39 GMT</pubDate>
    <dc:creator>JozkoMrkvicka</dc:creator>
    <dc:date>2019-08-24T06:31:39Z</dc:date>
    <item>
      <title>Resetting SIC after adding secondary Management server and doing failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Resetting-SIC-after-adding-secondary-Management-server-and-doing/m-p/61073#M84330</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have just finished installing a secondary management server (R80.20). Everything was fully synced and we did the first failover to the secondary management server.&lt;/P&gt;&lt;P&gt;We were not able to install any policies on the firewalls from the secondary management server once it was active. A test of the SIC communication showed that this was failing. We reset the SIC communication on both security gateways in one cluster and then we were able to install a policy from the active management server.&lt;/P&gt;&lt;P&gt;We did a fail back to the primary management server. Once that was active I was able to install a policy to the same security gateway cluster with out have to reset SIC.&lt;/P&gt;&lt;P&gt;Can anyone tell me if this is normal when installing a secondary management server, that SIC needs to be reset on all the security gateways so that they will respond to both the primary and secondary management server?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 21:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Resetting-SIC-after-adding-secondary-Management-server-and-doing/m-p/61073#M84330</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2019-08-23T21:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting SIC after adding secondary Management server and doing failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Resetting-SIC-after-adding-secondary-Management-server-and-doing/m-p/61078#M84331</link>
      <description>&lt;P&gt;No, it is not normal. You have to install policy from both managements. You can try to initiate full sync manually and install the database from Primary management (first installed), install policy from Primary and after that try to do switch to the Secondary management and check SIC status from Secondary.&lt;/P&gt;
&lt;P&gt;if does not help, check routing on both managements and the gateways. Try to perform tcpdump on the gateway to see if SIC port reached the gateway.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Aug 2019 06:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Resetting-SIC-after-adding-secondary-Management-server-and-doing/m-p/61078#M84331</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2019-08-24T06:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting SIC after adding secondary Management server and doing failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Resetting-SIC-after-adding-secondary-Management-server-and-doing/m-p/61193#M84332</link>
      <description>Hello, To be honest I did not install the policy on all the firewalls from the primary management server before we did the failover to do the tests on the secondary management server. This could indeed explain the situation as some firewalls did seem to be communicating with the secondary management server. These could have been the ones that had a firewall policy change pushed to them. Many thanks, Michael</description>
      <pubDate>Mon, 26 Aug 2019 06:59:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Resetting-SIC-after-adding-secondary-Management-server-and-doing/m-p/61193#M84332</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2019-08-26T06:59:38Z</dc:date>
    </item>
  </channel>
</rss>

