<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no_hide_services_ports &amp;amp; Management HA in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/211813#M35117</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54489"&gt;@CheckPointerXL&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can confirm that the table.def&amp;nbsp; 100% sync'd over to the standby management when we made our changes.&amp;nbsp; &amp;nbsp;Only had to touch the primary active node.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2024 00:54:25 GMT</pubDate>
    <dc:creator>Scottc98</dc:creator>
    <dc:date>2024-04-19T00:54:25Z</dc:date>
    <item>
      <title>no_hide_services_ports &amp; Management HA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/209460#M34688</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have a issue with radius working properly on a cluster and need to ensure that the source-ip used matches the NAS-ip.&amp;nbsp; &amp;nbsp; My understanding in the past is to follow&amp;nbsp;&lt;SPAN&gt;sk31832 and modify the table.def file globally&amp;nbsp; and add in "&amp;lt;1812, 17&amp;gt;" , save and then install policy on the devices to take affect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i.e.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;before&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;no_hide_services_ports&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;{&amp;nbsp;&amp;lt;4500,17&amp;gt;,&amp;nbsp;&amp;lt;500,&amp;nbsp;17&amp;gt;,&amp;nbsp;&amp;lt;259,&amp;nbsp;17&amp;gt;,&amp;nbsp;&amp;lt;1701,&amp;nbsp;17&amp;gt;,&amp;nbsp;&amp;lt;5500,&amp;nbsp;17&amp;gt;};&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;after&lt;/P&gt;&lt;P&gt;no_hide_services_ports&amp;nbsp;=&amp;nbsp;{&amp;nbsp;&amp;lt;4500,17&amp;gt;,&amp;nbsp;&amp;lt;500,&amp;nbsp;17&amp;gt;,&amp;nbsp;&amp;lt;259,&amp;nbsp;17&amp;gt;,&amp;nbsp;&amp;lt;1701,&amp;nbsp;17&amp;gt;,&amp;nbsp;&amp;lt;5500,&amp;nbsp;17&amp;gt;, &amp;lt;1812, 17&amp;gt;};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&amp;nbsp;is this still the only way to achieve this in R81.10 or R81.20?&amp;nbsp;&amp;nbsp;&lt;OL&gt;&lt;LI&gt;Feels like we should be able to do this on some no hide nat rule in each access policy verses setting this globally for all gateways.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;In a SMS management HA setup, does both Management servers need to be updated manually or is this synchronized over the secondary if edited on the primary member?&lt;OL&gt;&lt;LI&gt;Only had to do this in the past on a single SMS server and can't see to find any docs that touches to this point.&lt;/LI&gt;&lt;LI&gt;If it synchronizes, is that done automatically or is it something having to be driven by some 'install database' on both servers?&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Being that this type of change affects all GWs, is there any ill affect to any VSX clusters?&lt;OL&gt;&lt;LI&gt;I have not setup radius on those R81.10 VSX clusters (VSLS) yet but wanted to be sure.&lt;OL&gt;&lt;LI&gt;it seems per documentation that this modification "IS" a requirement before I do set it up here (Accurate?)&lt;OL&gt;&lt;LI&gt;REF:&amp;nbsp;&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_VSX_AdminGuide/Topics-VSXG/Working-with-Authentication.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_VSX_AdminGuide/Topics-VSXG/Working-with-Authentication.htm&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 00:38:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/209460#M34688</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2024-03-22T00:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: no_hide_services_ports &amp; Management HA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/209491#M34698</link>
      <description>&lt;P&gt;Management HA does not sync changes to .def files, so you'll have to do this on both.&lt;BR /&gt;Don't believe this has a negative impact on VSX.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 15:07:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/209491#M34698</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-22T15:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: no_hide_services_ports &amp; Management HA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/210281#M34816</link>
      <description>&lt;P&gt;are you sure? i converted different standalone mds to ha and i'm pretty sure it sync'd different .def files...&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 13:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/210281#M34816</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-04-02T13:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: no_hide_services_ports &amp; Management HA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/211813#M35117</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54489"&gt;@CheckPointerXL&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can confirm that the table.def&amp;nbsp; 100% sync'd over to the standby management when we made our changes.&amp;nbsp; &amp;nbsp;Only had to touch the primary active node.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 00:54:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/no-hide-services-ports-amp-Management-HA/m-p/211813#M35117</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2024-04-19T00:54:25Z</dc:date>
    </item>
  </channel>
</rss>

