<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194430#M32540</link>
    <description>&lt;P&gt;Yes, the Security Gateway keeps working regardless on the Security Management.&lt;/P&gt;
&lt;P&gt;When you Install Policy, the policy is sent to the Security Gateway were it is installed "locally".&lt;/P&gt;
&lt;P&gt;You can check that the policy is installed using the following commands:&lt;/P&gt;
&lt;P&gt;For &lt;STRONG&gt;Access Control &lt;/STRONG&gt;Policy use &lt;STRONG&gt;fw stat&lt;/STRONG&gt; or &lt;STRONG&gt;cpstat fw&amp;nbsp;&lt;/STRONG&gt;commands&lt;/P&gt;
&lt;P&gt;For &lt;STRONG&gt;Threat Prevention &lt;/STRONG&gt;Policy&amp;nbsp;use&amp;nbsp;&lt;STRONG&gt;fw stat -b AMW&lt;/STRONG&gt; command&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both will show the policy name and when it was installed&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Oct 2023 17:42:40 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2023-10-06T17:42:40Z</dc:date>
    <item>
      <title>If management server goes down, will the gateway still be able to filter(accept/deny) the traffic?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194423#M32537</link>
      <description>If the management server goes down, will the gateway still be able to filter the traffic as per the policy package target installation? Since the policy package resides on the management server I wanted to understand how the gateway could filter the traffic.</description>
      <pubDate>Fri, 06 Oct 2023 16:27:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194423#M32537</guid>
      <dc:creator>praveshnayal</dc:creator>
      <dc:date>2023-10-06T16:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194428#M32539</link>
      <description>&lt;P&gt;Yes, gateways will filter traffic just fine.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 17:20:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194428#M32539</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-10-06T17:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194430#M32540</link>
      <description>&lt;P&gt;Yes, the Security Gateway keeps working regardless on the Security Management.&lt;/P&gt;
&lt;P&gt;When you Install Policy, the policy is sent to the Security Gateway were it is installed "locally".&lt;/P&gt;
&lt;P&gt;You can check that the policy is installed using the following commands:&lt;/P&gt;
&lt;P&gt;For &lt;STRONG&gt;Access Control &lt;/STRONG&gt;Policy use &lt;STRONG&gt;fw stat&lt;/STRONG&gt; or &lt;STRONG&gt;cpstat fw&amp;nbsp;&lt;/STRONG&gt;commands&lt;/P&gt;
&lt;P&gt;For &lt;STRONG&gt;Threat Prevention &lt;/STRONG&gt;Policy&amp;nbsp;use&amp;nbsp;&lt;STRONG&gt;fw stat -b AMW&lt;/STRONG&gt; command&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both will show the policy name and when it was installed&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 17:42:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194430#M32540</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-10-06T17:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194464#M32547</link>
      <description>&lt;P&gt;What happens is that gateway will enforce latest policy pushed to it from the management server. If mgmt server went down, traffic would still work just fine through the firewall, but huge downside to it is that you would not be able to make any further changes to the policy. as smart console would not be accessible.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 03:09:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194464#M32547</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-08T03:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194465#M32548</link>
      <description>&lt;P&gt;If i remember correctly, you should pay big attention to CRL fetching. VPN between FW on same management could potentially be disrupted if there is no communication during the 24h fetching period.&lt;/P&gt;
&lt;P&gt;Anyone can confirm or not?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 07:42:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194465#M32548</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-10-08T07:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194469#M32549</link>
      <description>&lt;P&gt;Yes, that rings a bell, though couple of times mgmt was down for a customer, we never had that issue, but it could happen, for sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 11:13:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194469#M32549</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-08T11:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194471#M32550</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;curious about if the connection is lost between FW and Management. What will happens?&lt;/P&gt;&lt;P&gt;Last time i experinced with this in 80.x all the traffic was blocked by the FW. is it expected behaviour?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 11:23:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194471#M32550</guid>
      <dc:creator>Fabz</dc:creator>
      <dc:date>2023-10-08T11:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194472#M32551</link>
      <description>&lt;P&gt;Connection to Security Management Server should not affect the Security Policy that is installed on the Security Gateway.&lt;/P&gt;
&lt;P&gt;Perhaps this was a case where connection was lost, SIC was reset which then installs the Initial Policy.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 11:30:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194472#M32551</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-10-08T11:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194473#M32552</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;is 100% right. I would also say if there was a SIC issue, if sic is reset, then by default, it loads initial policy, which pretty muchblocks anything, except web UI on port 443 and ssh.&lt;/P&gt;
&lt;P&gt;Tal, PLEASE be safe mate, Im praying for tolerance and peace over there &lt;span class="lia-unicode-emoji" title=":dove:"&gt;🕊&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":dove:"&gt;🕊&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 12:25:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194473#M32552</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-08T12:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194474#M32553</link>
      <description>&lt;P&gt;Btw, I found an old notes I had back in R77 days when customer had this issue and mgmt was down for 3 days, but they told me after all VPN tunnels stayed up and there was no traffic issue. Mind you, there was no cp to cp vpn tunnels, so as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54489"&gt;@CheckPointerXL&lt;/a&gt;&amp;nbsp;said, its possible if mgmt is down for more than 24 hours, if you have any cp to cp s2s vpn tunnels, they may not work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 13:22:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194474#M32553</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-08T13:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194475#M32554</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 13:37:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194475#M32554</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-10-08T13:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194476#M32555</link>
      <description>&lt;P&gt;This is true; I've had this happen to me before, but that is on the condition that all devices being used are managed from the same Manager.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 13:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194476#M32555</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-10-08T13:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194477#M32556</link>
      <description>&lt;P&gt;Never had that happen to me, but what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54489"&gt;@CheckPointerXL&lt;/a&gt;&amp;nbsp;mentioned about CRL is 100% true.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 13:58:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194477#M32556</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-08T13:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: If management server goes down, will the gateway still be able to filter(accept/deny) the traffi</title>
      <link>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194567#M32567</link>
      <description>&lt;P&gt;While the gateway will continue to pass traffic per the last installed policy, VPNs will fail after a period of time.&lt;BR /&gt;This is because the Internal CA resides on the Management Server and gateways/clients reach out to the CRL to validate the certificate.&lt;BR /&gt;For Site-to-Site VPNs, they will continue to work for 24 hours.&lt;BR /&gt;Remote Access clients (regardless of auth method) use the CRL and may fail.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that clears things up.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 19:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/If-management-server-goes-down-will-the-gateway-still-be-able-to/m-p/194567#M32567</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-09T19:43:41Z</dc:date>
    </item>
  </channel>
</rss>

