<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SMB appliances regular updates and policy pulls in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47640#M1850</link>
    <description>&lt;P&gt;The big difference when comparing centrally managed SMB to a standard CP Gateway is that we have no policy install, but rather a policy pull from the device - very appropriate for DAIP configurations ! The SMB GW asks the Management every 5 minutes if the policy has changed - see the corresponding entries in &lt;EM&gt;/var/log/log/sfwd.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] Fetching Security Policy from '172.27.39.198'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] Local Security Policy is Up-To-Date.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] The Security Policy was not installed because it is the same as the Policy already on the Module.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] Fetching Threat Prevention Policy from '172.27.39.198'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] Local Threat Prevention Policy is Up-To-Date.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] The Threat Prevention Policy was not installed because it is the same as the Policy already on the Module.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Firmware upgrade check can also be found in &lt;EM&gt;sfwd.elg&lt;/EM&gt; - it is logged additionally also in&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;/var/log/log/check_available_firmware.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[check_available_firmware 5451 1996578816]@zwelfhundertr[14 Mar 13:35:53] check_available_firmware: Thu Mar 14 13:35:53 2019&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[check_available_firmware 6332 2011901952]@zwelfhundertr[14 Mar 16:11:28] check_available_firmware: Thu Mar 14 16:11:28 2019&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Licenses are synced with UserCenter every hour - see&lt;EM&gt; /var/log/log/uc_activation.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[uc_activation 7732 1998979072]@zwelfhundertr[19 Mar 5:22:07] uc_activation: Tue Mar 19 05:22:07 2019&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;main: setting do_refresh&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: g_n_items=12 g_lic_exp=null pnp_stat=TP_EXPIRED_LIC&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: lic_exist=1 lic_exp=Feb 4, 2020&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[uc_activation 7944 2006491136]@zwelfhundertr[19 Mar 6:22:03] uc_activation: Tue Mar 19 06:22:03 2019&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;main: setting do_refresh&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: g_n_items=12 g_lic_exp=null pnp_stat=TP_EXPIRED_LIC&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: lic_exist=1 lic_exp=Feb 4, 2020&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;TED wants all 12 hours his License refreshment, see &lt;EM&gt;/var/log/log/ted.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 12673 2002706432][16 Mar 2:13:54] [TE_TRACE]: Starting licenses refreshment &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 12673 2002706432][16 Mar 14:13:54] [TE_TRACE]: Starting licenses refreshment &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 12673 2002706432][17 Mar 2:13:54] [TE_TRACE]: Starting licenses refreshment&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;So we can see that there is really a lot of work to do even for the small ones &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMB_Policy.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/303i1DCE2AC4D668BE64/image-size/large?v=v2&amp;amp;px=999" role="button" title="SMB_Policy.png" alt="SMB_Policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="times new roman,times"&gt;Also see&amp;nbsp;this list &lt;A class="page-link lia-link-navigation lia-custom-event" href="https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/SMB-documents/m-p/57239#M2222/jump-to/first-unread-message" target="_blank"&gt;SMB documents&lt;/A&gt;&amp;nbsp;for more.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 13:23:37 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-07-02T13:23:37Z</dc:date>
    <item>
      <title>SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47640#M1850</link>
      <description>&lt;P&gt;The big difference when comparing centrally managed SMB to a standard CP Gateway is that we have no policy install, but rather a policy pull from the device - very appropriate for DAIP configurations ! The SMB GW asks the Management every 5 minutes if the policy has changed - see the corresponding entries in &lt;EM&gt;/var/log/log/sfwd.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] Fetching Security Policy from '172.27.39.198'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] Local Security Policy is Up-To-Date.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] The Security Policy was not installed because it is the same as the Policy already on the Module.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] Fetching Threat Prevention Policy from '172.27.39.198'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] Local Threat Prevention Policy is Up-To-Date.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] The Threat Prevention Policy was not installed because it is the same as the Policy already on the Module.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Firmware upgrade check can also be found in &lt;EM&gt;sfwd.elg&lt;/EM&gt; - it is logged additionally also in&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;/var/log/log/check_available_firmware.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[check_available_firmware 5451 1996578816]@zwelfhundertr[14 Mar 13:35:53] check_available_firmware: Thu Mar 14 13:35:53 2019&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[check_available_firmware 6332 2011901952]@zwelfhundertr[14 Mar 16:11:28] check_available_firmware: Thu Mar 14 16:11:28 2019&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Licenses are synced with UserCenter every hour - see&lt;EM&gt; /var/log/log/uc_activation.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[uc_activation 7732 1998979072]@zwelfhundertr[19 Mar 5:22:07] uc_activation: Tue Mar 19 05:22:07 2019&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;main: setting do_refresh&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: g_n_items=12 g_lic_exp=null pnp_stat=TP_EXPIRED_LIC&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: lic_exist=1 lic_exp=Feb 4, 2020&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[uc_activation 7944 2006491136]@zwelfhundertr[19 Mar 6:22:03] uc_activation: Tue Mar 19 06:22:03 2019&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;main: setting do_refresh&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: g_n_items=12 g_lic_exp=null pnp_stat=TP_EXPIRED_LIC&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;UCACT_write_blades: lic_exist=1 lic_exp=Feb 4, 2020&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;TED wants all 12 hours his License refreshment, see &lt;EM&gt;/var/log/log/ted.elg&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 12673 2002706432][16 Mar 2:13:54] [TE_TRACE]: Starting licenses refreshment &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 12673 2002706432][16 Mar 14:13:54] [TE_TRACE]: Starting licenses refreshment &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 12673 2002706432][17 Mar 2:13:54] [TE_TRACE]: Starting licenses refreshment&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;So we can see that there is really a lot of work to do even for the small ones &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMB_Policy.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/303i1DCE2AC4D668BE64/image-size/large?v=v2&amp;amp;px=999" role="button" title="SMB_Policy.png" alt="SMB_Policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="times new roman,times"&gt;Also see&amp;nbsp;this list &lt;A class="page-link lia-link-navigation lia-custom-event" href="https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/SMB-documents/m-p/57239#M2222/jump-to/first-unread-message" target="_blank"&gt;SMB documents&lt;/A&gt;&amp;nbsp;for more.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 13:23:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47640#M1850</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-07-02T13:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47700#M1851</link>
      <description>Gunther,&lt;BR /&gt;Do you know if the fw fetch on SMB can be forced? We recently had a 1100 gateway that just did not want to update it's policy and finally after a reboot and push on a fixed IP, I was able to replace the policy, it just did not update before that.</description>
      <pubDate>Tue, 19 Mar 2019 12:11:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47700#M1851</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-19T12:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47723#M1852</link>
      <description>&lt;P&gt;Yes, see sk117473: Manual policy fetch on SMB device&lt;/P&gt;
&lt;P&gt;# &lt;CODE&gt;fw -d fetch&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 13:38:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47723#M1852</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-19T13:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47730#M1853</link>
      <description>Nope, that is a debug, but still uses the local policy, does not force a fetch from management.</description>
      <pubDate>Tue, 19 Mar 2019 13:51:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47730#M1853</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-19T13:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47747#M1854</link>
      <description>&lt;P&gt;Yes, it is debug for much more fun &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;[Expert@zwelfhundertr]# fw fetch&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;Fetching Security Policy from '172.27.39.198'&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;Local Security Policy is Up-To-Date.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;Installing Security Policy...&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;Installing Security Policy Succeeded.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;Done.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;[Expert@zwelfhundertr]#&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Also possible to use as fw fetch &amp;lt;ip address of mgmt&amp;gt;. According to&amp;nbsp;sk119332, Security policy changes must be pushed to the Security Gateway before they will be implemented by an "&lt;EM&gt;fw fetch&lt;/EM&gt;" command. The "&lt;EM&gt;fw fetch&lt;/EM&gt;" compares the &lt;EM&gt;compiled&lt;/EM&gt; policy on the&amp;nbsp;Security Management server&amp;nbsp;with the latest policy on the Security Gateway.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 14:48:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47747#M1854</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-19T14:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47762#M1855</link>
      <description>Gunther,&lt;BR /&gt;&lt;BR /&gt;I am aware of how it should work, but in some cases you did make changes and the gateway (in our case) just kept saying the local was up to date and the GUI showed a policy installed at 10:30 while we made changes at 10:45 and pushed policy, log was flowing, but at 11:00 it was still showing that the 10:30 policy was loaded.&lt;BR /&gt;Doing the fw fetch also said local security policy is up to date.&lt;BR /&gt;Hence I wanted to see if there is a way to Force the fetch and discard the local copy.</description>
      <pubDate>Tue, 19 Mar 2019 15:22:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47762#M1855</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-19T15:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47894#M1857</link>
      <description>Here you should involve TAC - policy install is done to make the GW use the new rules, so such a behaviour is a bug !</description>
      <pubDate>Wed, 20 Mar 2019 07:50:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47894#M1857</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-20T07:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47900#M1858</link>
      <description>Please also consult sk119332 !</description>
      <pubDate>Wed, 20 Mar 2019 08:35:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47900#M1858</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-20T08:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances regular updates and policy pulls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47905#M1859</link>
      <description>&lt;P&gt;What i also know is the clish variant: # fetch policy mgmt-ipv4-address x.x.x.x#&lt;/P&gt;
&lt;P&gt;But i fear that also here only the compiled policy from SMS is checked and local policy not discarded ! But of course we have a method to achive what you want:&lt;/P&gt;
&lt;P&gt;- switch Security Management to local mode&lt;BR /&gt;- switch back to central mamagement&lt;BR /&gt;- re-establish SIC with the SMS&lt;BR /&gt;- Security policy is loded from SMS and installed&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 09:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-regular-updates-and-policy-pulls/m-p/47905#M1859</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-20T09:03:06Z</dc:date>
    </item>
  </channel>
</rss>

