<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rename VSX cluster member in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/60093#M9819</link>
    <description>&lt;P&gt;We now created a procedure for the rename in lab:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT&gt;Add dummy node with "vsx_util add_member"&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Remove the original node with "vsx_util remove_member"&lt;BR /&gt;This will generate an error regarding SIC communicatio&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Edit '$FWDIR/conf/objects_5_0.C', find the dummy gateway object and related child objects and change the status and SIC information&lt;BR /&gt;&amp;nbsp;=&amp;gt; Change 'connection_state (uninitialized)' to 'connection_state (communicating)'&lt;BR /&gt;&amp;nbsp;=&amp;gt; Change the ':sic_name ()' to a normal value ':sic_name ("CN=Test_tmp,O=gw-2c1401..962djh")' in our test&lt;BR /&gt;&amp;nbsp;=&amp;gt; For the child object, in this test there’s only one VS named VG1, so the corresponding sic_name is ':sic_name ("CN=Test_tmp_VG1,O=gw-2c1401..962djh")'&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Run 'vsx_util remove_member' again to remove the original node, this will generate another error (not being able to communicate with the dummy node)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Reset or reïnstall the original node (in our lab we used 'reset_gw' in 'vsenv 0')&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Following sk101674, edit '$FWDIR/conf/objects_5_0.C'&lt;BR /&gt;=&amp;gt; find :operation_type (add_remove_member) and delete the blocks where the status is not OK [:status (OK)]&lt;BR /&gt;=&amp;gt; Save the file and exit&lt;BR /&gt;=&amp;gt; Remove the SmartConsole cache and restart the checkpoint services:&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; cd $FWDIR/conf/&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; rm CPMILinks*&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; cpstop&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; cpstart&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Add the original node again under the new using 'vsx_util add_member', this should run ok now&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;FONT&gt;Restore the configuration on the renamed node using 'vsx_util reconfigure'&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Remove the dummy node using 'vsx_util remove_member'&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Verify in SmartDashboard&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Test policy push&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;FONT&gt;We will keep this procedure as backup scenario for production, for production we will create a VM with with 10 nics and add this VM as a third node while reinstalling the original node.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;Any feedback is welcome!&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Aug 2019 08:22:17 GMT</pubDate>
    <dc:creator>Raf_Brands</dc:creator>
    <dc:date>2019-08-12T08:22:17Z</dc:date>
    <item>
      <title>rename VSX cluster member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55607#M9813</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;Our customer's wants to upgrade his environment from R77.30 to R80.20.&lt;/P&gt;&lt;P&gt;Problem is: he has a VSX cluster with cluster members named 'fw1' and 'fw2'. After importing the SMS database to a new R80.20 management server the Validations tab tells us that "more than one object named fw1 exists" (the other being a default service FW1).&lt;/P&gt;&lt;P&gt;Long story short: we have to rename VSX cluster member 'fw1' before we can consider upgrading. In my lab I experimented with vsx_util:&lt;/P&gt;&lt;P&gt;- vsx_util add_member to add a Dummy gateway&lt;/P&gt;&lt;P&gt;- vsx_util remove_member to remove fw1&lt;/P&gt;&lt;P&gt;but this can't be used: "A previous remove member operation did not complete for..." because there is no SIC with the Dummy gateway, which also prevents policy installs to the remaining VSX member.&lt;/P&gt;&lt;P&gt;TAC told us to use vsx_provisioning_tool (and to contact Professional Services &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;), but after reading the documentation and testing some commands I don't see how that would work.&lt;/P&gt;&lt;P&gt;Anyone?&lt;/P&gt;&lt;P&gt;Ph.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 11:47:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55607#M9813</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2019-06-12T11:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: rename VSX cluster member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55631#M9814</link>
      <description>&lt;P&gt;If I remember correctly you when you turn on the following VSX debugs it skips the provisioning process and allows you to make changes without communication:&lt;/P&gt;&lt;P&gt;#fw debug fwm on TDERROR_ALL_VSXM_DBG_SKIP_PING=INFO&lt;BR /&gt;#&amp;nbsp;fw debug fwm on TDERROR_ALL_VSXM_DBG_SKIP_INSTALL=INFO&lt;BR /&gt;#fw debug fwm on TDERROR_ALL_VSXM_DBG_SKIP_PULL_SIC=INFO&lt;/P&gt;&lt;P&gt;Make changes to VSX gateway&lt;/P&gt;&lt;P&gt;Disable debugs with #fw debug fwm off&lt;/P&gt;&lt;P&gt;Might try this in your lab to see if it will let you delete.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 16:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55631#M9814</guid>
      <dc:creator>Alejandro_Mont1</dc:creator>
      <dc:date>2019-06-12T16:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: rename VSX cluster member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55639#M9815</link>
      <description>&lt;P&gt;Thanks Alejandro, I'll test it tomorrow!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 18:19:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55639#M9815</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2019-06-12T18:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: rename VSX cluster member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55682#M9816</link>
      <description>&lt;P&gt;I'm afraid this didn't solve it. Still getting:&lt;/P&gt;&lt;P&gt;"Previous remove member operation was not completed. Run 'vsx_util remove_member' again to resume operation."&lt;/P&gt;&lt;P&gt;I'll dive a bit deeper still maybe removing the whole cluster &amp;amp; recreating it will be the only solution.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 09:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55682#M9816</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2019-06-13T09:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: rename VSX cluster member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55692#M9817</link>
      <description>When you run the 'vsx_util remove_member' again, you can abort the previous operation. Then you can try it again.&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Jun 2019 11:03:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/55692#M9817</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-13T11:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: rename VSX cluster member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/56023#M9818</link>
      <description>&lt;P&gt;Going to test further with TAC.&lt;/P&gt;&lt;P&gt;I'll post the solution here, maybe it will come in handy for someone else later on.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 06:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/56023#M9818</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2019-06-18T06:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: rename VSX cluster member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/60093#M9819</link>
      <description>&lt;P&gt;We now created a procedure for the rename in lab:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT&gt;Add dummy node with "vsx_util add_member"&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Remove the original node with "vsx_util remove_member"&lt;BR /&gt;This will generate an error regarding SIC communicatio&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Edit '$FWDIR/conf/objects_5_0.C', find the dummy gateway object and related child objects and change the status and SIC information&lt;BR /&gt;&amp;nbsp;=&amp;gt; Change 'connection_state (uninitialized)' to 'connection_state (communicating)'&lt;BR /&gt;&amp;nbsp;=&amp;gt; Change the ':sic_name ()' to a normal value ':sic_name ("CN=Test_tmp,O=gw-2c1401..962djh")' in our test&lt;BR /&gt;&amp;nbsp;=&amp;gt; For the child object, in this test there’s only one VS named VG1, so the corresponding sic_name is ':sic_name ("CN=Test_tmp_VG1,O=gw-2c1401..962djh")'&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Run 'vsx_util remove_member' again to remove the original node, this will generate another error (not being able to communicate with the dummy node)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Reset or reïnstall the original node (in our lab we used 'reset_gw' in 'vsenv 0')&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Following sk101674, edit '$FWDIR/conf/objects_5_0.C'&lt;BR /&gt;=&amp;gt; find :operation_type (add_remove_member) and delete the blocks where the status is not OK [:status (OK)]&lt;BR /&gt;=&amp;gt; Save the file and exit&lt;BR /&gt;=&amp;gt; Remove the SmartConsole cache and restart the checkpoint services:&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; cd $FWDIR/conf/&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; rm CPMILinks*&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; cpstop&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; cpstart&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Add the original node again under the new using 'vsx_util add_member', this should run ok now&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;FONT&gt;Restore the configuration on the renamed node using 'vsx_util reconfigure'&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Remove the dummy node using 'vsx_util remove_member'&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Verify in SmartDashboard&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT&gt;Test policy push&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;FONT&gt;We will keep this procedure as backup scenario for production, for production we will create a VM with with 10 nics and add this VM as a third node while reinstalling the original node.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;Any feedback is welcome!&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 08:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rename-VSX-cluster-member/m-p/60093#M9819</guid>
      <dc:creator>Raf_Brands</dc:creator>
      <dc:date>2019-08-12T08:22:17Z</dc:date>
    </item>
  </channel>
</rss>

