<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Only one chassis receives the policy after making changes on SmartProvisioning in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247073#M3351</link>
    <description>&lt;P&gt;I believe SmartProvisioning (aka SmartLSM) is not supported with Maestro until R82&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk148074" target="_blank" rel="noopener"&gt;sk148074 - Known Limitations for Scalable Platforms R80.20SP - R81.20 (Maestro Appliances and Chassis)&lt;/A&gt;&lt;/P&gt;
&lt;DIV class="table-wrapper"&gt;
&lt;TABLE id="SP_limitationTable" class="footnote" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#d6dff0" data-darkreader-inline-bgcolor=""&gt;
&lt;TD width="12%"&gt;ID&lt;/TD&gt;
&lt;TD width="8%"&gt;Product&lt;/TD&gt;
&lt;TD width="60%"&gt;Description&lt;/TD&gt;
&lt;TD width="10%"&gt;Found in&lt;/TD&gt;
&lt;TD width="10%"&gt;Resolved In&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="SubTitle" bgcolor="#d6dff0" data-darkreader-inline-bgcolor=""&gt;
&lt;TD colspan="5"&gt;SmartProvisioning&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;01511158&lt;/TD&gt;
&lt;TD&gt;All&lt;/TD&gt;
&lt;TD&gt;Scalable Platforms do not support SmartProvisioning management.&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk94686" target="_blank" rel="noopener"&gt;R76SP&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181127" target="_blank" rel="noopener"&gt;R82&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;</description>
    <pubDate>Wed, 23 Apr 2025 08:09:18 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2025-04-23T08:09:18Z</dc:date>
    <item>
      <title>Only one chassis receives the policy after making changes on SmartProvisioning</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/246815#M3339</link>
      <description>&lt;P&gt;Hello everyone.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a dual site setup with R81.10 JHF Take 172.&lt;/P&gt;
&lt;P&gt;We noticed that when we make a change on SmartProvisioning and install the policy, only the active chassis receives the policy and updates the policy singature.&lt;/P&gt;
&lt;P&gt;For example,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Global] clish &amp;gt; asg policy verify -a&lt;/P&gt;
&lt;P&gt;+----------------------------------------------------------------------+&lt;BR /&gt;|Policy Verification |&lt;BR /&gt;+-------+-------------------+---------------+-----------------+--------+&lt;BR /&gt;|SGM |Policy Name |Policy Date |Policy Signature |Status |&lt;BR /&gt;+-------+-------------------+---------------+-----------------+--------+&lt;BR /&gt;|1_01 |Standard |14Apr25 09:44 |49c54a3e2 |Failed |&lt;BR /&gt;|2_01 |Standard |14Apr25 09:44 |e96b2c0b7 |Failed |&lt;BR /&gt;+-------+-------------------+---------------+-----------------+--------+&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when we install a policy without making any changes on SmartProvisioning, everything works, all gateways receive policy, same policy signatures. Example,&lt;/P&gt;
&lt;P&gt;+----------------------------------------------------------------------+&lt;BR /&gt;|Policy Verification |&lt;BR /&gt;+-------+-------------------+---------------+-----------------+--------+&lt;BR /&gt;|SGM |Policy Name |Policy Date |Policy Signature |Status |&lt;BR /&gt;+-------+-------------------+---------------+-----------------+--------+&lt;BR /&gt;|1_01 |Standard |17Apr25 01:17 |fde3508f3 |Success |&lt;BR /&gt;|2_01 |Standard |17Apr25 01:17 |fde3508f3 |Success |&lt;BR /&gt;+-------+-------------------+---------------+-----------------+--------+&lt;/P&gt;
&lt;P&gt;We have been consistently able to replicate this. We thought it may be some sync problems, but policy installation without SP works perfectly fine, so it doesn't look like a sync issue. At leasst not when a normal policy is pushed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;asg diag verify only shows "&lt;SPAN&gt;Policy signature doesn't match on all SGMs" error&amp;nbsp; and everything else is just "Passed". And we see that only after a policy push that contains a change in SP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I'm not experienced in SmartProvisioning, maybe it has its own policy push mechanism besides SmartConsole or SmartUpdate. But I stand corrected here.&lt;/P&gt;
&lt;P&gt;As always, any ideas are deeply appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 09:43:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/246815#M3339</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-04-18T09:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Only one chassis receives the policy after making changes on SmartProvisioning</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247014#M3347</link>
      <description>&lt;TABLE class="TableStyle-TP_Table_Notes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_prov variable"&gt;SmartProvisioning&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is not available for members of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_slsm variable"&gt;SmartLSM&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SmartProvisioning_AdminGuide/Topics-SPROVG/Introduction-to-SmartProvisioning.htm#" data-mc-state="closed" data-aria-describedby="baa2308e-d497-4809-9bf4-009ccf880a8a" target="_blank"&gt;cluster&lt;/A&gt;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dario_Perez_0-1745333177851.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30286iC76A89762D10178E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Dario_Perez_0-1745333177851.gif" alt="Dario_Perez_0-1745333177851.gif" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;.&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SmartProvisioning_AdminGuide/Topics-SPROVG/Introduction-to-SmartProvisioning.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SmartProvisioning_AdminGuide/Topics-SPROVG/Introduction-to-SmartProvisioning.htm&lt;/A&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 22 Apr 2025 14:46:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247014#M3347</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2025-04-22T14:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Only one chassis receives the policy after making changes on SmartProvisioning</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247071#M3350</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3205"&gt;@Dario_Perez&lt;/a&gt;&amp;nbsp;Thank you for pointing to that note. Now I have more questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I understand that statement correctly, I can manage a cluster via SmartLSM, but I can't manage individual members in a cluster. But even if that's the case, I'm having hard time understanding the difference between installing policy on a cluster and a single security group. Maybe I'm wrong in assuming that policy gets installed on a single object with a single IP (like the active member of a cluster or SMO in a security group).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In our case both chassis have the same security group, so it appears as a single gateway on SmartConsole (even simpler than a cluster).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Does that limitation really apply to security groups distributed to two chassis as well?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 07:55:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247071#M3350</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-04-23T07:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Only one chassis receives the policy after making changes on SmartProvisioning</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247073#M3351</link>
      <description>&lt;P&gt;I believe SmartProvisioning (aka SmartLSM) is not supported with Maestro until R82&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk148074" target="_blank" rel="noopener"&gt;sk148074 - Known Limitations for Scalable Platforms R80.20SP - R81.20 (Maestro Appliances and Chassis)&lt;/A&gt;&lt;/P&gt;
&lt;DIV class="table-wrapper"&gt;
&lt;TABLE id="SP_limitationTable" class="footnote" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#d6dff0" data-darkreader-inline-bgcolor=""&gt;
&lt;TD width="12%"&gt;ID&lt;/TD&gt;
&lt;TD width="8%"&gt;Product&lt;/TD&gt;
&lt;TD width="60%"&gt;Description&lt;/TD&gt;
&lt;TD width="10%"&gt;Found in&lt;/TD&gt;
&lt;TD width="10%"&gt;Resolved In&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="SubTitle" bgcolor="#d6dff0" data-darkreader-inline-bgcolor=""&gt;
&lt;TD colspan="5"&gt;SmartProvisioning&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;01511158&lt;/TD&gt;
&lt;TD&gt;All&lt;/TD&gt;
&lt;TD&gt;Scalable Platforms do not support SmartProvisioning management.&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk94686" target="_blank" rel="noopener"&gt;R76SP&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181127" target="_blank" rel="noopener"&gt;R82&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 23 Apr 2025 08:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247073#M3351</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-04-23T08:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Only one chassis receives the policy after making changes on SmartProvisioning</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247082#M3352</link>
      <description>&lt;P&gt;Interesting. I will confirm with TAC whether this is related to our case.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 08:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Only-one-chassis-receives-the-policy-after-making-changes-on/m-p/247082#M3352</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-04-23T08:34:58Z</dc:date>
    </item>
  </channel>
</rss>

