<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Generic Data Centre Object not copying to Maestro SGM in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/244698#M3243</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not 100% percent sure about that, this kind of files must been copied to the other members automatically.&lt;/P&gt;
&lt;P&gt;If you check the s&lt;EM&gt;how smo image md5sum&lt;/EM&gt; what is the output? The md5sum's are tehe same?&lt;/P&gt;
&lt;P&gt;A workaround can be to copy the relevant files to each SGM with &lt;STRONG&gt;#asg_cp2blades&lt;/STRONG&gt; command&lt;/P&gt;
&lt;P&gt;You can expant the script with this line.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Mar 2025 14:12:55 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-03-25T14:12:55Z</dc:date>
    <item>
      <title>Generic Data Centre Object not copying to Maestro SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/244622#M3239</link>
      <description>&lt;P&gt;Evening,&lt;/P&gt;
&lt;P&gt;We've recently deployed a new Maestro stack that comprises the following:&lt;/P&gt;
&lt;P&gt;2 x MHO-140s (single site)&lt;/P&gt;
&lt;P&gt;3 x 9800 SGMs&lt;/P&gt;
&lt;P&gt;VSX mode enabled&lt;/P&gt;
&lt;P&gt;R81.20 T84&lt;/P&gt;
&lt;P&gt;1 x VFW&lt;/P&gt;
&lt;P&gt;We've configured both a Generic Data Centre Object &amp;amp; a Cisco ACI object to use the ESGs and ExternalEPGs in firewall policy. The GDO points to a JSON file stored in GitHub that contains the ExternalEPG information (we had to use this as a workaround due to the Cisco ACI object lacking the ability to query ExternalEPGs). The VFW policy uses the ESGs &amp;amp; ExternalEPGs as source &amp;amp; destination objects.&lt;/P&gt;
&lt;P&gt;Connectivity testing commenced today, with intermittent results. I could see in the logs that some traffic was being accepted and some being dropped by the cleanup rule. Further analysis showed that the accepted traffic was for the SMO (member ID 1_1) and all dropped traffic was on members 1_2 &amp;amp; 1_3 (side note - it would be great if this field could be selected as a view option in dashboard!).&lt;/P&gt;
&lt;P&gt;When logging into the SMO, switching to vsenv 1 and running dynamic_objects -cfo_show, the contents/IP ranges of the GDO object are displayed as expected. When moving to members 2 &amp;amp; 3 and switching to vsenv 1, the dynamic_objects -cfo_show command returns a "File not found" message.&lt;/P&gt;
&lt;P&gt;I assumed that the SMO would have copied the GDO objects to the other SGMs, but it would appear that's not happening.&lt;/P&gt;
&lt;P&gt;Has anyone seen this behaviour before? Or have any suggestions as to why the GDO objects aren't being copied to all members?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 21:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/244622#M3239</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2025-03-24T21:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Data Centre Object not copying to Maestro SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/244698#M3243</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not 100% percent sure about that, this kind of files must been copied to the other members automatically.&lt;/P&gt;
&lt;P&gt;If you check the s&lt;EM&gt;how smo image md5sum&lt;/EM&gt; what is the output? The md5sum's are tehe same?&lt;/P&gt;
&lt;P&gt;A workaround can be to copy the relevant files to each SGM with &lt;STRONG&gt;#asg_cp2blades&lt;/STRONG&gt; command&lt;/P&gt;
&lt;P&gt;You can expant the script with this line.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 14:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/244698#M3243</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-25T14:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Data Centre Object not copying to Maestro SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/245028#M3256</link>
      <description>&lt;P&gt;Hi Akos,&lt;/P&gt;
&lt;P&gt;We've figured out the issue. The vsecUpdate.sh script that's execute on the SMO via cpridutil via the MDS has an error in the logic. The vsecUpdate.sh script adds the dynamic objects to $FWDIR/tmp, however the script is trying to sync the object to the other SGMs in the /tmp directory.&lt;/P&gt;
&lt;P&gt;This is fixed in R81.20 T79.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 23:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/245028#M3256</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2025-03-27T23:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Data Centre Object not copying to Maestro SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/245038#M3257</link>
      <description>&lt;P&gt;Do you mean JHF T97 as you were already running T84 based on the original post?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 22:55:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/245038#M3257</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-03-27T22:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Generic Data Centre Object not copying to Maestro SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/245039#M3258</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I believe it's T79 on the MDS (we're currently running T76). Apologies, should have clarified that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 23:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Generic-Data-Centre-Object-not-copying-to-Maestro-SGM/m-p/245039#M3258</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2025-03-27T23:15:21Z</dc:date>
    </item>
  </channel>
</rss>

