<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro SMO asg diag verify &amp;gt; clock fail in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/166148#M1327</link>
    <description>&lt;P&gt;Hi Todd,&lt;BR /&gt;&lt;BR /&gt;I experienced the same behavior after upgrade from R80.30SP to R81.10.&lt;BR /&gt;Did it happen in the same context on your side?&lt;BR /&gt;&lt;BR /&gt;Cheeers&lt;BR /&gt;Sven&lt;/P&gt;</description>
    <pubDate>Tue, 27 Dec 2022 12:36:56 GMT</pubDate>
    <dc:creator>Sven_Glock</dc:creator>
    <dc:date>2022-12-27T12:36:56Z</dc:date>
    <item>
      <title>Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/165928#M1323</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I connect to the SMO via ssh, MOTD displayed the following message:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Warning: System diagnostics failed on the following tests: Clock, ARP Consistency.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Then I found 3 SGM clock was different.&lt;/P&gt;&lt;P&gt;1_01:&lt;BR /&gt;Fri Dec 23 15:49:58 2022 CST&lt;/P&gt;&lt;P&gt;1_02:&lt;BR /&gt;Fri Dec 23 15:52:04 2022 CST&lt;/P&gt;&lt;P&gt;1_03:&lt;BR /&gt;Fri Dec 23 15:50:33 2022 CST&lt;/P&gt;&lt;P&gt;Can I know how big the time difference between SGM will affect the operation ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 08:18:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/165928#M1323</guid>
      <dc:creator>todd</dc:creator>
      <dc:date>2022-12-23T08:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/165929#M1324</link>
      <description>&lt;P&gt;I haven't found anything in the docs nor SKs regarding how much time difference as acceptable.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172245" target="_self"&gt;sk172245&lt;/A&gt; -&amp;nbsp;Network Time Protocol (NTP) on Maestro&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk179385" target="_self"&gt;sk179385&lt;/A&gt; -&amp;nbsp;Time is not synchronised between Security Group Members although NTP is used&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 23 Dec 2022 08:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/165929#M1324</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-12-23T08:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/165946#M1325</link>
      <description>&lt;P&gt;Hi Danny,&lt;/P&gt;&lt;P&gt;NTP information is very helpful.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 09:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/165946#M1325</guid>
      <dc:creator>todd</dc:creator>
      <dc:date>2022-12-23T09:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/166148#M1327</link>
      <description>&lt;P&gt;Hi Todd,&lt;BR /&gt;&lt;BR /&gt;I experienced the same behavior after upgrade from R80.30SP to R81.10.&lt;BR /&gt;Did it happen in the same context on your side?&lt;BR /&gt;&lt;BR /&gt;Cheeers&lt;BR /&gt;Sven&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 12:36:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/166148#M1327</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2022-12-27T12:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/166154#M1330</link>
      <description>&lt;P&gt;Good question, always wondered about that.&amp;nbsp; Poking around in the documentation, older code versions seem to indicate that the clock must be matched within one second for proper functionality which is clearly not correct; this statement has been softened in later versions.&amp;nbsp; I have personally seen operational cluster members that were several hours off from each other and it didn't seem to have an adverse effect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a sampling of what the documentation says:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;R76 Multi-Domain Admin Guide:&lt;/EM&gt;&lt;BR /&gt;Multi-Domain Server (including dedicated Multi-Domain Log Servers) system clocks must be synchronized to the nearest second. When adding another Multi-Domain Server to your deployment, synchronize its clock with the other Multi-Domain Server before installing the Multi-Domain Security Management package.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;R77 ClusterXL Guide:&lt;/EM&gt;&lt;BR /&gt;For VPN cluster members, synchronize member clocks accurately to within one second of each other. If these members are constantly up and running it is usually enough to set the time once. More reliable synchronization can be achieved using NTP or some other time synchronization services supplied by the operating system. Cluster member clock synchronization is not applicable for non VPN cluster functionality.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;R81.20 ClusterXL Guide:&lt;/EM&gt;&lt;BR /&gt;Features, such as VPN, only function properly when the clocks of all of the Cluster Members are synchronized.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;sk41513:&lt;/EM&gt;&lt;BR /&gt;SIC failures can occur if the firewall and management module clocks are not correctly synchronized. The clocks do not have to match exactly, but they should match within a few minutes. Both your management module and firewall module should synchronize to an external time source via NTP.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Quantum Spark R80.20.40 CLI Reference:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;set vpn site-to-site advanced-settings period-before-crl-valid &amp;lt;threshold&amp;gt;&lt;/P&gt;
&lt;P&gt;Configures the time (in seconds), during which a certificate is considered valid prior to the time set by the Certificate Authority. This is to allow a wider window for CRL validity in case of mismatch in clock on the VPN sites.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 14:39:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/166154#M1330</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-12-27T14:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/166185#M1331</link>
      <description>&lt;P&gt;Hi Sven,&lt;/P&gt;&lt;P&gt;We haven't try to set NTP because customer is very cautious about changing the setting. Currently, we will use manual setting&amp;nbsp; of the clock.&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 02:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/166185#M1331</guid>
      <dc:creator>todd</dc:creator>
      <dc:date>2022-12-28T02:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/174353#M1454</link>
      <description>&lt;P&gt;Just for completion: In my case the root cause of sgms running out of time sync is caused by a bug fixed in R81.10 JHF93 (PRJ-43601,PRJ-43213)&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 13:03:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/174353#M1454</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2023-03-10T13:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SMO asg diag verify &gt; clock fail</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/174444#M1456</link>
      <description>&lt;P&gt;Thanks for your information!&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 11:05:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SMO-asg-diag-verify-gt-clock-fail/m-p/174444#M1456</guid>
      <dc:creator>todd</dc:creator>
      <dc:date>2023-03-11T11:05:18Z</dc:date>
    </item>
  </channel>
</rss>

