<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fetch policy automatically on 1490 appliance from management server in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71185#M2759</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have 20 - 1490 appliance that i manage from the management server r80.10.&lt;/P&gt;&lt;P&gt;the install policy on 1490 is slowly so i want to check if there is an option,&lt;/P&gt;&lt;P&gt;when i install policy on all 1490 appliance from the management server it take 30-40 minutes,&lt;/P&gt;&lt;P&gt;if i install only on 1 -1490 it takes 5-6 minutes.&lt;/P&gt;&lt;P&gt;to fetch the policy automatically?&lt;/P&gt;&lt;P&gt;let say every 24hours,&lt;/P&gt;&lt;P&gt;so every change i make on the access policy in the management server will fetch automatically.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a good way to do it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Wed, 25 Dec 2019 04:48:57 GMT</pubDate>
    <dc:creator>yishaia</dc:creator>
    <dc:date>2019-12-25T04:48:57Z</dc:date>
    <item>
      <title>Fetch policy automatically on 1490 appliance from management server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71185#M2759</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have 20 - 1490 appliance that i manage from the management server r80.10.&lt;/P&gt;&lt;P&gt;the install policy on 1490 is slowly so i want to check if there is an option,&lt;/P&gt;&lt;P&gt;when i install policy on all 1490 appliance from the management server it take 30-40 minutes,&lt;/P&gt;&lt;P&gt;if i install only on 1 -1490 it takes 5-6 minutes.&lt;/P&gt;&lt;P&gt;to fetch the policy automatically?&lt;/P&gt;&lt;P&gt;let say every 24hours,&lt;/P&gt;&lt;P&gt;so every change i make on the access policy in the management server will fetch automatically.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a good way to do it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 04:48:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71185#M2759</guid>
      <dc:creator>yishaia</dc:creator>
      <dc:date>2019-12-25T04:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch policy automatically on 1490 appliance from management server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71192#M2760</link>
      <description>The issue here is that your policy needs to be compiled first, that is done when you push policy, after that it is attempted to be pushed to all gateways selected and set ready for those gateways to be picked up.&lt;BR /&gt;What I don't know is, what happens when you push it only to 1 or 2 gateways, will the others also pick it up? &lt;BR /&gt;The embedded boxes always check themselves if there is a newer policy for them through the 'Phone Home' principle, they do that every 20 minutes.</description>
      <pubDate>Wed, 25 Dec 2019 08:38:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71192#M2760</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-12-25T08:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch policy automatically on 1490 appliance from management server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71193#M2761</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply,&lt;/P&gt;&lt;P&gt;i tried to do it,&lt;/P&gt;&lt;P&gt;i pushed the policy to 1 - 1490 gateway and waited for 24hours,&lt;/P&gt;&lt;P&gt;the other 1490 appliance did not get the policy,&lt;/P&gt;&lt;P&gt;its works only if i install it directly to the gateway from the management,&lt;/P&gt;&lt;P&gt;any way to solve it?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 08:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71193#M2761</guid>
      <dc:creator>yishaia</dc:creator>
      <dc:date>2019-12-25T08:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch policy automatically on 1490 appliance from management server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71199#M2762</link>
      <description>The thing is that there will be a table on the management server that will be checked to see which policy version should be loaded on that particular gateway. If you could manipulate that table the gateways should still pick up the newer policy.&lt;BR /&gt;&lt;BR /&gt;Another approach is to push the policy by means of the API, it will still take the long time, but would not bother you.</description>
      <pubDate>Wed, 25 Dec 2019 14:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71199#M2762</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-12-25T14:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch policy automatically on 1490 appliance from management server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71201#M2763</link>
      <description>&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a way to make the management\gateway to install policy automatically every day at 02:00?&lt;/P&gt;&lt;P&gt;can you explain me how to do it by script / API?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 14:23:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71201#M2763</guid>
      <dc:creator>yishaia</dc:creator>
      <dc:date>2019-12-25T14:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch policy automatically on 1490 appliance from management server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71202#M2764</link>
      <description>The problem is still that you have to push the policy to the gateway before it can be fetched in this manner.&lt;BR /&gt;&lt;BR /&gt;In addition to potentially scripting the policy install, if your management is R80.20+, you can do this via SmartLSM.&lt;BR /&gt;In this case, you push policy to a profile, which all the 1490 appliances are assigned to.&lt;BR /&gt;This should be fairly quick—a few minutes versus the 40 or so to push to each gateway in sequence.&lt;BR /&gt;The gateways will pick up the new policy next time it fetches from management.</description>
      <pubDate>Wed, 25 Dec 2019 17:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Fetch-policy-automatically-on-1490-appliance-from-management/m-p/71202#M2764</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-25T17:09:16Z</dc:date>
    </item>
  </channel>
</rss>

