- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Impact "cpstop" SmartCenter (management)
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Impact "cpstop" SmartCenter (management)
Hello to all,
I have a disk space problem on my management server (SamrtCenter) R80.40.
I would like to implement the procedure (https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&eve...) to add a disk in order to increase my log partition.
I would like to know if the "cpstop" command of this procedure will have an impact on my production traffic.
In other words, will this command affect my security gateways?
I hope I have made myself clear.
Thank you in advance for your answers and recommendations.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For a short period of time (e.g. a typical maintenance window of a few hours), having management offline should not impact production traffic.
If management is down for an extended period of time, it can have an impact on:
- Site-to-Site VPNs authenticated using ICA Certificates (VPNs will terminate after 24 hours due to the CRL being unavailable)
- Use of the CloudGuard Controller (see sk115657), which includes the use of Generic Datacenter objects (previous lookups are cached for a time)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For a short period of time (e.g. a typical maintenance window of a few hours), having management offline should not impact production traffic.
If management is down for an extended period of time, it can have an impact on:
- Site-to-Site VPNs authenticated using ICA Certificates (VPNs will terminate after 24 hours due to the CRL being unavailable)
- Use of the CloudGuard Controller (see sk115657), which includes the use of Generic Datacenter objects (previous lookups are cached for a time)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think what @PhoneBoy said is most likely correct. You definitely dont want it to be down for too long, but if you only need to do this and then restart or shut down, I believe thats safe. I had done things like this before where mgmt server was down for up to 30 mins and no issues with production traffic at all.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Kinda goes without saying but you also won't have access to your logs while performing this process, to the extent possible the gateways will buffer logs locally until mgmt returns.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Then it's worth saying that configuring Log Forwarding Settings (gateway/cluster object > Logs > Additional Logging) will be good option to automatically forward these logs on scheduled time back to SMS. Of course if SMS is only log server for these gateways/cluster.
BR
Daniel.
