<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Time synchronization between orchestrator and its SGMs - does it matter? in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260177#M3703</link>
    <description>&lt;P&gt;Hello Maestro Community&lt;/P&gt;&lt;P&gt;I would welcome any thoughts on an issue we are currently trying to fathom with Check Point partners and TAC.&lt;/P&gt;&lt;P&gt;We should have a dual site set up each having a single MHO140 with 2 attached 7000 gateways. At the moment the sync between the 2 sites is down, so we are effectively running in a production / disaster recovery mode which requires manual intervention to switch between sites.&lt;/P&gt;&lt;P&gt;As it happens we had a problem with the production site last Monday and had to flip over to the disaster recovery site.&lt;/P&gt;&lt;P&gt;We need to determine what went wrong with the&amp;nbsp; production site. However this needs to be done without bringing up the production orchestrator services as this causes a split brain situation which affects our users. So the production orchestrator has had an 'orchd stop' executed on it.&lt;/P&gt;&lt;P&gt;TAC has logged in and has taken away some logs to analyse.&lt;/P&gt;&lt;P&gt;Whilst they are doing this, I've noticed that the system time on the production orchestrator is showing as 4th January 2009.&amp;nbsp; It was rebooted trying to resolve our issue when it happened. The boot time shows as 00:00 1 Jan 2009. Even though NTP is set up, I expect this difference in time is much too big to be resolved by NTP adjustments.&lt;/P&gt;&lt;P&gt;The system time of the SGMs is correct - 17th October 2025.&lt;/P&gt;&lt;P&gt;At last here's the question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would this massive time difference between the orchestrator and its attached gateways matter? And would it prevent the SMS from seeing the SMO - as this is what I'm told was happening after the incident and before flipping over to the DR site.&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Oct 2025 13:23:22 GMT</pubDate>
    <dc:creator>T_Letts</dc:creator>
    <dc:date>2025-10-17T13:23:22Z</dc:date>
    <item>
      <title>Time synchronization between orchestrator and its SGMs - does it matter?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260177#M3703</link>
      <description>&lt;P&gt;Hello Maestro Community&lt;/P&gt;&lt;P&gt;I would welcome any thoughts on an issue we are currently trying to fathom with Check Point partners and TAC.&lt;/P&gt;&lt;P&gt;We should have a dual site set up each having a single MHO140 with 2 attached 7000 gateways. At the moment the sync between the 2 sites is down, so we are effectively running in a production / disaster recovery mode which requires manual intervention to switch between sites.&lt;/P&gt;&lt;P&gt;As it happens we had a problem with the production site last Monday and had to flip over to the disaster recovery site.&lt;/P&gt;&lt;P&gt;We need to determine what went wrong with the&amp;nbsp; production site. However this needs to be done without bringing up the production orchestrator services as this causes a split brain situation which affects our users. So the production orchestrator has had an 'orchd stop' executed on it.&lt;/P&gt;&lt;P&gt;TAC has logged in and has taken away some logs to analyse.&lt;/P&gt;&lt;P&gt;Whilst they are doing this, I've noticed that the system time on the production orchestrator is showing as 4th January 2009.&amp;nbsp; It was rebooted trying to resolve our issue when it happened. The boot time shows as 00:00 1 Jan 2009. Even though NTP is set up, I expect this difference in time is much too big to be resolved by NTP adjustments.&lt;/P&gt;&lt;P&gt;The system time of the SGMs is correct - 17th October 2025.&lt;/P&gt;&lt;P&gt;At last here's the question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would this massive time difference between the orchestrator and its attached gateways matter? And would it prevent the SMS from seeing the SMO - as this is what I'm told was happening after the incident and before flipping over to the DR site.&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 13:23:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260177#M3703</guid>
      <dc:creator>T_Letts</dc:creator>
      <dc:date>2025-10-17T13:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Time synchronization between orchestrator and its SGMs - does it matter?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260182#M3704</link>
      <description>&lt;P&gt;From my knowledge, that matters regardless of the system/hardware. Its related to policy install, cluster, vpn...&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 14:42:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260182#M3704</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-17T14:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Time synchronization between orchestrator and its SGMs - does it matter?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260194#M3705</link>
      <description>&lt;P&gt;If you have trouble seeing the SMO from Smart Console it is related to SIC. Communication between SMO and SMS is via SIC connection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_smss variable"&gt;Security Management Servers&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and managed&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;must synchronize their system clocks.&lt;/P&gt;
&lt;P&gt;This is important for these reasons:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R80.20SP/WebAdminGuides/EN/CP_R80.20SP_Maestro_Gaia_AdminGuide/Topics-Maestro-Gaia/Time.htm?Highlight=ntp#" data-mc-state="closed" data-aria-describedby="ea0aed19-a77a-4599-a051-1de3bd2ac46c" target="_blank"&gt;SIC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;trust can fail if devices are not synchronized correctly.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R80.20SP/WebAdminGuides/EN/CP_R80.20SP_Maestro_Gaia_AdminGuide/Topics-Maestro-Gaia/Time.htm?Highlight=ntp#" data-mc-state="closed" data-aria-describedby="b57b4f79-0aac-4a1e-b973-1e07c12a38ad" target="_blank"&gt;ClusteR&lt;/A&gt;&lt;/P&gt;
&amp;nbsp;&lt;SPAN&gt;synchronization requires precise clock synchronization between members.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_sme variable"&gt;SmartEvent&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Correlation uses time stamps that must be synchronized to approximately one a second.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;To make sure that cron jobs run at the correct time.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;To do certificate validation for applications based on the correct time.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The SGM sync the time between them. Note on SGM there is no ntpd running:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On a Security Group, the&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;ntpd&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;daemon does&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;run. Instead, the&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;cpd&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;daemon runs a scheduled task called&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;UpdateTimeViaNTP&lt;/CODE&gt;&lt;SPAN&gt;. This task runs a special shell script called&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;$SMODIR/scripts/asg_ntp_update_time&lt;/CODE&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also what you state is correct, if the time difference is to big between the NTP server and local time a NTP sync will not happen. Change the time manually, like 5 minutes before or after real current time. Configure NTP and then check if it changes.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 18:26:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260194#M3705</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-10-17T18:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Time synchronization between orchestrator and its SGMs - does it matter?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260196#M3706</link>
      <description>&lt;P&gt;Sounds logical!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 18:27:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260196#M3706</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-17T18:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Time synchronization between orchestrator and its SGMs - does it matter?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260292#M3708</link>
      <description>&lt;P&gt;I don't know that it matters too much between MHOs and SGMs, but it might matter between MHOs. It certainly does in R82 because the MHOs set up trust between themselves with certificates, so if the time is wildly out their self-generated certs won't be valid between each other. For whatever reason, MHOs out of the box have their clocks set wildly back and need to be manually set before NTP can take over to manage. Always good to check the time zone too, it defaults to New York and is commonly not changed, and NTP doesn't set the time zone.&lt;/P&gt;
&lt;P&gt;MHO time won't affect SMO/SMS comms, the SGMs handle time by themselves, and are generally pretty good out of the box. That said, SIC required time to be pretty close, as Lesley has explained, so NTP is always a good idea for any CP device.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 02:00:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Time-synchronization-between-orchestrator-and-its-SGMs-does-it/m-p/260292#M3708</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-10-20T02:00:45Z</dc:date>
    </item>
  </channel>
</rss>

