This website uses Cookies. Click Accept to agree to our website's cookie use as described in our Privacy Policy. Click Preferences to customize your cookie settings.
I know that one of the SGMs get's the SMO role. I remember this is regarding to the port number used for downlinks. I searched through knowledgebase and community but I'm not able to find such information.
Can anyone give me a hint to the documentation how the process is working which SGM get's the SMO role.
It has nothing to do with port numbers, it's purely based on SGM IDs, which are simply allocated in order of SGMs being added to the group. So adding a new appliance won't change which one the SMO is, unless you don't already have an SGM 1_1.
And even if that were the case, the new one wouldn't assume SMO role until after it has synchronised everything and become active, so there's still no impact to it.
In Check Point Maestro, theSingle Management Object (SMO)is a technology that manages the Security Group as one large Security Gateway with one management IP address. TheActive Security Group Member with the lowest ID numberis automatically assigned to be the SMO.
To verify which Security Group Member is elected as the SMO, you can use the following command:
asg stat -i tasks
This command will display the distribution of tasks among the Security Group Members, including the SMO task.
Example Output in a Maestro Single Site Configuration:
Thanks @Danny for the detailed explanations. We want to add a a new SGM to an existing SG. But we have to use a downlink port with a lower port number then the already used. I think the SGM which holds the SMO role should stay on the same SGM, but we want to be sure.
I remember someone posted here that the SMO role building process has something todo with the port numbers, tha's why I'm a little bit confuesed
It has nothing to do with port numbers, it's purely based on SGM IDs, which are simply allocated in order of SGMs being added to the group. So adding a new appliance won't change which one the SMO is, unless you don't already have an SGM 1_1.
And even if that were the case, the new one wouldn't assume SMO role until after it has synchronised everything and become active, so there's still no impact to it.