<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manual transfer policy from SMS to GW in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187703#M31425</link>
    <description>&lt;P&gt;SIC will not go through VPN by default.&lt;BR /&gt;The reason for this is simple: if the VPN is down, you will be unable to manage the gateway.&lt;BR /&gt;Which is the precise situation you have here.&lt;BR /&gt;You will need to get SIC working without VPN first.&lt;BR /&gt;Without that, this will never work.&lt;/P&gt;
&lt;P&gt;The following thread provides some pointers on managing a gateway over a VPN with SIC:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Managing-a-gateway-over-VPN/m-p/13674/highlight/true#M2423" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Managing-a-gateway-over-VPN/m-p/13674/highlight/true#M2423&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2023 14:19:12 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-07-26T14:19:12Z</dc:date>
    <item>
      <title>Manual transfer policy from SMS to GW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187560#M31396</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I have many gateways on my SMS, including a remote gateway that currently has no network connectivity until I set a policy on it. However, I cannot set the policy because of this issue. Can you please advise if there is a way to manually extract the policy file from the SMS and place it onto the gateway, then restart the gateway to install from local policy file?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 15:54:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187560#M31396</guid>
      <dc:creator>Andrey_Gl</dc:creator>
      <dc:date>2023-07-25T15:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Manual transfer policy from SMS to GW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187644#M31409</link>
      <description>&lt;P&gt;The Security Gateway does have a policy installed before it is connected to the Security Management Server called "Initial Policy":&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/The-Initial-Policy.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/The-Initial-Policy.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 09:09:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187644#M31409</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-07-26T09:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Manual transfer policy from SMS to GW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187645#M31410</link>
      <description>&lt;P&gt;Assuming that the GW has internet connectivity and the current policy enables no access to it, this may be resolved by issuing fw unloadlocal from GW CLI, see &lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-unloadlocal.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-unloadlocal.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 09:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187645#M31410</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-26T09:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Manual transfer policy from SMS to GW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187651#M31411</link>
      <description>&lt;P&gt;The gateway is only accessible through VPN, but VPN cannot be established because the gateway is not aware of it. A policy needs to be installed instead of removing it.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 09:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187651#M31411</guid>
      <dc:creator>Andrey_Gl</dc:creator>
      <dc:date>2023-07-26T09:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Manual transfer policy from SMS to GW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187655#M31413</link>
      <description>&lt;P&gt;There's still something not clear here. How can it be accessible through VPN when it is still not connected to the Security Management Server and part of a VPN Community?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first connection to it is always SIC which requires direct connectivity to the Security Gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 10:15:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187655#M31413</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-07-26T10:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Manual transfer policy from SMS to GW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187659#M31414</link>
      <description>&lt;P&gt;You could attempt something like below via api, but no guarantee it will work, if SIC is not even established (im just guessing here, as I dont have all the details)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/#cli/install-policy~v1.9%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/#cli/install-policy~v1.9%20&lt;/A&gt;&lt;/P&gt;
&lt;H3 class="examples"&gt;Examples&lt;/H3&gt;
&lt;DIV class="examples-container"&gt;
&lt;DIV&gt;
&lt;H4&gt;install-policy&lt;/H4&gt;
&lt;A class="btn-toggle-collapse-next ar_open" target="_blank"&gt;v&lt;/A&gt;
&lt;DIV class="collapse in"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="example-sec-title"&gt;Command&lt;/P&gt;
&lt;PRE class="code"&gt;mgmt_cli install-policy policy-package "standard" access true threat-prevention true targets.1 "corporate-gateway"  --format json
 • "--format json" is optional. By default the output is presented in plain text.&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 Jul 2023 11:53:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187659#M31414</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-26T11:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Manual transfer policy from SMS to GW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187703#M31425</link>
      <description>&lt;P&gt;SIC will not go through VPN by default.&lt;BR /&gt;The reason for this is simple: if the VPN is down, you will be unable to manage the gateway.&lt;BR /&gt;Which is the precise situation you have here.&lt;BR /&gt;You will need to get SIC working without VPN first.&lt;BR /&gt;Without that, this will never work.&lt;/P&gt;
&lt;P&gt;The following thread provides some pointers on managing a gateway over a VPN with SIC:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Managing-a-gateway-over-VPN/m-p/13674/highlight/true#M2423" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Managing-a-gateway-over-VPN/m-p/13674/highlight/true#M2423&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:19:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-transfer-policy-from-SMS-to-GW/m-p/187703#M31425</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-26T14:19:12Z</dc:date>
    </item>
  </channel>
</rss>

