<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do I need to install policy after each HOTFIX upgrade? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219328#M36548</link>
    <description>&lt;P&gt;I would say 100% you dont need to, because gateways will fetch last known policy from the mgmt server. The only time I had seen happen otherwise is when you do major upgrade, say from R80.40 to R81.20, where after reboot, it loads initial policy, so you need to unload it and install real one from mgmt server. In one instance, I even had customer tell me it loaded whats called "default filter", which literaally block everything and you need to console in, run fw unloadloca, but thats super RARE.&lt;/P&gt;
&lt;P&gt;Either way, I always advise people to have physical access, just to be on the safe side.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2024 21:04:34 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-07-01T21:04:34Z</dc:date>
    <item>
      <title>Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219286#M36539</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a query that&amp;nbsp;&lt;STRONG&gt;do I need to install policy after each upgrade?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;And if yes then both cluster members or the Firewall which is upgraded/not upgraded selected for policy push? I am not sure if HotFix upgrade requires policy install step. I have MDS managing all the firewalls.&lt;/P&gt;&lt;P&gt;Earlier when I did policy install step it was when OS was upgraded R77 to 81. I have change the version name from r77 to r81 in Gateway Cluster Properties--&amp;gt;General Properties--&amp;gt;Platform---&amp;gt;Version and then push the policy.&lt;/P&gt;&lt;P&gt;I followed these steps while upgrading from R77.30 to R81 take 392:&lt;/P&gt;&lt;P&gt;Start with Passive Firewall(ideally)&lt;BR /&gt;Install latest/recommended Deployment Agent(DA) if installation is not automatically enabled on the firewalls&lt;BR /&gt;Upload/Copy of IOS Image on the concerned firewall&lt;BR /&gt;Verify IOS Image - Check_Point_R81_T392&lt;BR /&gt;After successful verification - Upgrade FW with IOS image&lt;BR /&gt;Upload Hot Fix - Check_Point_R81_JUMBO_HF_MAIN_Bundle_T77&lt;BR /&gt;Verify uploaded Hot Fix_Bundle_T77&lt;BR /&gt;After successful verification, Install Hot Fix&lt;BR /&gt;Change Name to R81 on MDS&lt;BR /&gt;Policy Push for version R81 after First Firewall IOS &amp;amp; HF upgrade&lt;BR /&gt;Revert to Clish Mode in the both Firewalls CLI&lt;/P&gt;&lt;P&gt;Repeat same steps for Active Firewalls&lt;BR /&gt;Policy Push for version R81 after First Firewall IOS &amp;amp; HF upgrade&lt;BR /&gt;Make sure Primary Firewall is now active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 15:31:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219286#M36539</guid>
      <dc:creator>MVS_VF</dc:creator>
      <dc:date>2024-07-01T15:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219314#M36545</link>
      <description>&lt;P&gt;Installing policy is required on version upgrades because the policy compilation is different for each version.&lt;BR /&gt;This is not the case for hotfix installations.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 19:00:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219314#M36545</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-01T19:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219326#M36547</link>
      <description>&lt;H2&gt;Prerequisites&lt;/H2&gt;
&lt;P&gt;To use Central Deployment:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;A policy must be installed on the target&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_clmbs variable"&gt;Cluster Members&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Central-Deployment-of-Software-Packages.htm?Highlight=jumbo" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Central-Deployment-of-Software-Packages.htm?Highlight=jumbo&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Would recommended to the same if you for example Jumbo update the server that manages the gateways. Maybe during the versions something changed regarding policy push so you want to push policy.&lt;/P&gt;
&lt;P&gt;For normal Jumbo updates via CLISH or CPUSE I would also do it just to be sure but it is not needed. Jumbo update can finish and just run fine without push. But in my opinion it is also a form of a health check after jumbo.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 20:37:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219326#M36547</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-01T20:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219328#M36548</link>
      <description>&lt;P&gt;I would say 100% you dont need to, because gateways will fetch last known policy from the mgmt server. The only time I had seen happen otherwise is when you do major upgrade, say from R80.40 to R81.20, where after reboot, it loads initial policy, so you need to unload it and install real one from mgmt server. In one instance, I even had customer tell me it loaded whats called "default filter", which literaally block everything and you need to console in, run fw unloadloca, but thats super RARE.&lt;/P&gt;
&lt;P&gt;Either way, I always advise people to have physical access, just to be on the safe side.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 21:04:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219328#M36548</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-01T21:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219330#M36549</link>
      <description>&lt;P&gt;For the context and I hope&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;will correct me if Im mistaken, but I believe this is how it works with policy:&lt;/P&gt;
&lt;P&gt;1) FW will always get policy from the mgmt first&lt;/P&gt;
&lt;P&gt;2) If 1 fails, then it will try fetch locally stored one in $FWDIR/state/_tmp/FW1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) If 1 and 2 fail, then it would load initial policy, which allows ssh AND web UI, but ONLY on port 443&lt;/P&gt;
&lt;P&gt;4) if all fails, then most likely default filter will be applied, which block everything, including ssh and web UI&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 21:16:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219330#M36549</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-01T21:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219336#M36550</link>
      <description>&lt;P&gt;I believe this is still how it works after all these years &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 21:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219336#M36550</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-01T21:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219337#M36551</link>
      <description>&lt;P&gt;I figured, but have to confirm from the BEST! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 22:05:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219337#M36551</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-01T22:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to install policy after each HOTFIX upgrade?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219465#M36583</link>
      <description>&lt;P&gt;Note that this is about the policy push in the middle of a major or minor version upgrade (when you have only upgraded one member). That's definitely not needed for jumbos.&lt;/P&gt;
&lt;P&gt;You should push policy at the end, once both members are updated.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 17:52:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Do-I-need-to-install-policy-after-each-HOTFIX-upgrade/m-p/219465#M36583</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-07-02T17:52:05Z</dc:date>
    </item>
  </channel>
</rss>

