<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Polcy load at boot in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279663#M14062</link>
    <description>&lt;P&gt;It will load a local copy of&amp;nbsp;"policy-from-cma"&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2026 13:33:38 GMT</pubDate>
    <dc:creator>simonemantovani</dc:creator>
    <dc:date>2026-07-14T13:33:38Z</dc:date>
    <item>
      <title>Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279623#M14055</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;May be I am in the wrong section... I will see if I get any answer.&lt;/P&gt;&lt;P&gt;I have an old appliance 14xx still managed by our MDM (yes I know EOL....). Now I have to upgrade MDM to R82.10 and this version is no more supporting 14xx appliances.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I remove this appliance from the database (or if the MDM/CMA is no more reachable) will the latest policy remain on the appliance ?&lt;/P&gt;&lt;P&gt;What if I reboot this appliance ? It will load the Initial Policy or it will keep the old policy ?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 08:21:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279623#M14055</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2026-07-14T08:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279625#M14056</link>
      <description>&lt;P&gt;It should load the latest installed policy.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 08:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279625#M14056</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-07-14T08:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279626#M14057</link>
      <description>&lt;P&gt;Thanks for answering.&lt;/P&gt;&lt;P&gt;Also think "it should" but I would prefer "it will". And since hard and soft are EOL, unable to raise a ticket.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 08:53:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279626#M14057</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2026-07-14T08:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279636#M14058</link>
      <description>&lt;P&gt;Now system is central managed, these boxes can also be locally managed. With local mgmt, the rules and logs stay on the local box and you dont need a MDM anymore. Note: CRL check will fail towards mgmt, this is needed for site to site vpn between Check Point to Check Point. CRL check can be disabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;During reboot it will reach out to mgmt but also during normal operations it will check if there is a new policy and will fetch it. if there is nothing to fetch box will not load a default policy.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 11:14:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279636#M14058</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-07-14T11:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279650#M14059</link>
      <description>&lt;P&gt;It will work until it doesn't, at which point you won't be able to easily fix it. I think Lesley has the right idea - take the time to properly plan to reset it into Locally Managed mode and do it on your schedule, instead of waiting until it decides you need to do it.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 12:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279650#M14059</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-07-14T12:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279654#M14060</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Probably I have not been clear enough.&lt;/P&gt;&lt;P&gt;Currently device is running with policy name "policy-from-cma".&lt;/P&gt;&lt;P&gt;Then I do not allow communication with the CMA anymore.&lt;/P&gt;&lt;P&gt;Then rebooting appliance. Is it going to load a local copy of "policy-from-cma" of load the default policy ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 12:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279654#M14060</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2026-07-14T12:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279659#M14061</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Happy to read everybody. But still no answer...&lt;/P&gt;&lt;P&gt;Question is about boot process and policy load. Not about what I should do or not.&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 13:19:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279659#M14061</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2026-07-14T13:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279663#M14062</link>
      <description>&lt;P&gt;It will load a local copy of&amp;nbsp;"policy-from-cma"&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 13:33:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279663#M14062</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-07-14T13:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279664#M14063</link>
      <description>&lt;P&gt;So, there's kind of two different possible scenarios. If a gateway loses contact with the management server, it will keep on keeping on, retaining the policy on reboot as long as it starts up properly, until something else happens and it doesn't anymore. In your case though, if you delete the gateway from the management server, the gateway will try to talk to it and learn that its SIC cert is revoked. This is less charted waters, most of us won't have tried this scenario, and we don't want to tell you 'yea mate she'll be right' and leave you in the lurch should you suddenly have a with no policy on it.&amp;nbsp;It won't suddenly unload the policy upon learning that its SIC is revoked, but I don't know what it will do on reboot. Hence we offer safer alternatives.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 13:39:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279664#M14063</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-07-14T13:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279671#M14065</link>
      <description>&lt;P&gt;This is the more accurate answer I had. I will deal with it.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 13:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279671#M14065</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2026-07-14T13:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Polcy load at boot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279684#M14067</link>
      <description>&lt;P&gt;Even though it's not officially supported, it's quite possible that you will still be able to manage and install policy on your 1400 from R82.10 assuming the object existed prior to the upgrade.&lt;BR /&gt;At least that's been the case in the past when we've deprecated support for a given appliance/version as the underlying "Backward Compatibility" packages are still there.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 15:37:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Polcy-load-at-boot/m-p/279684#M14067</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-07-14T15:37:07Z</dc:date>
    </item>
  </channel>
</rss>

