<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fetching policy failed when running sp_upgrade script in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240898#M3186</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;No, VS0 is on the same network as the SmartCenter.&lt;BR /&gt;&lt;BR /&gt;I think Implied Rules are the issue. Will try again with Implied Rules enabled.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 13:25:13 GMT</pubDate>
    <dc:creator>Martijn</dc:creator>
    <dc:date>2025-02-11T13:25:13Z</dc:date>
    <item>
      <title>Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/229234#M2905</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;This week we tried to upgrade a Maestro set from R81.10 take 165 to R81.20 take 84. Because the Security Groups are configured with LACP bonds, I could not use the Zero Downtime (MVC) procedure and used the Minimum Downtime procedure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I followed the steps described in the R81.20 Maestro Admin guide and all seems to go OK. Orchestrators (MHO-140) where upgraded without any issues. Also the upgrade of the first member in the Security Group went OK and was succesfully upgraded to R81.20. But then things went wrong.&lt;/P&gt;
&lt;P&gt;When running the sp_upgrade script on the upgraded member, the fetching of the policy failed:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Fetching the policy from the Management Server and installing it... Failed on members 1_1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Fetching the policy from xx.xx.xx.xx and installing it... Failed on members 1_1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Enter the IP address of the Management Server that manages this Security Group:xx.xx.xx.xx&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Fetching the policy from xx.xx.xx.xx and installing it... Failed on members 1_1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Try to run 'sp_upgrade' again in few seconds. If the problem persists, contact support.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I have tried to run the command with the --NO-MVC option and got the same problem.&lt;/P&gt;
&lt;P&gt;Performed a verify and that seems to be OK.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[Expert@xxxxxxxxxxx-ch01-01:0]# sp_upgrade --verify&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Starting the Security Group Pre-Upgrade Verifier:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Enter the IP address of the Management Server that manages this Security Group:xx.xx.xx.xx&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Cluster State: Failed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Check the state of the following Security Group members. Make sure they are in Active state before proceeding with the upgrade or remove them from the Security Group.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;1_01&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Connectivity to Management Server: Passed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;LACP: Passed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Disk Space: Passed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;The Security Group failed the Pre-Upgrade Verifier tests. Do not continue with the upgrade until you fix all the detected issues.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;The upgraded member was Down, but according to the Admin guide, that was expected. Also all verification earlier in the procedure reported an OK status.&lt;/P&gt;
&lt;P&gt;In the end we had to revert the whole upgrade on the Security Group. Orchestrators are still on R81.20.&lt;BR /&gt;&lt;BR /&gt;Did I miss something? Followed the procedure by the letter and double checked every step with the customer.&lt;BR /&gt;Anyone had the same issue when upgrading?&lt;BR /&gt;&lt;BR /&gt;What can we do the next time we plan this upgrade? Are the LACP bonds affecting the upgrade?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 08:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/229234#M2905</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2024-10-09T08:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/229323#M2910</link>
      <description>&lt;P&gt;Do you manage the system over an LACP-bond? Try switching to magg or change the bonding type to active/backup temporarily.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 21:03:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/229323#M2910</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2024-10-09T21:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/229337#M2913</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I forgot to mention that. Production bonding groups (uplinks) are LACP. MAGG is Active/Backup.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 07:06:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/229337#M2913</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2024-10-10T07:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240659#M3180</link>
      <description>&lt;P&gt;Hi Martijn,&lt;/P&gt;&lt;P&gt;I have the same problem, SG is VSX and the connection from SG to MGMT is through a VS, I think the problem is that there is no connection to MGMT, so it can't take policies and when you upgrade it doesn't take policies, so it doesn't do anything.&lt;/P&gt;&lt;P&gt;How did you manage to solve it? I had this problem yesterday.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 20:55:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240659#M3180</guid>
      <dc:creator>77Madness77</dc:creator>
      <dc:date>2025-02-06T20:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240777#M3184</link>
      <description>&lt;P&gt;The connection between VSX and management server is through one of the VSs that the VSX hosts? This is not a supported deployment for any VSX setup, maestro or otherwise, upgrades will always fail in this scenario.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 05:15:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240777#M3184</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-02-10T05:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240898#M3186</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;No, VS0 is on the same network as the SmartCenter.&lt;BR /&gt;&lt;BR /&gt;I think Implied Rules are the issue. Will try again with Implied Rules enabled.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 13:25:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240898#M3186</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-02-11T13:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240995#M3189</link>
      <description>&lt;P&gt;I have heard of issues with VSX upgrades and implied rules being disabled, I think specifically the 'allow control connections' one.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 08:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/240995#M3189</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-02-12T08:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching policy failed when running sp_upgrade script</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/245679#M3289</link>
      <description>&lt;P&gt;Just had a similar issue, solution was to manually copy the policy files from the Manager to the upgraded members and run sp_upgrade with fetch from tmp flag.&lt;/P&gt;&lt;P&gt;Solution was associated with &lt;SPAN&gt;&lt;A class="" title="https://support.checkpoint.com/results/sk/sk180402" href="https://support.checkpoint.com/results/sk/sk180402" target="_blank" rel="noreferrer noopener"&gt;sk180402&lt;/A&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;I just think the upgraded members couldn't connect to the manager or viceversa for some reason.&lt;BR /&gt;&lt;BR /&gt;My setup connects to the manager via uplink bond (acitve backup thoug), so maybe it doesn't like the fact that there is no management itnerface, not sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 10:39:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Fetching-policy-failed-when-running-sp-upgrade-script/m-p/245679#M3289</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2025-04-04T10:39:14Z</dc:date>
    </item>
  </channel>
</rss>

