The big difference when comparing centrally managed SMB to a standard CP Gateway is that we have no policy install, but rather a policy pull from the device - very appropriate for DAIP configurations ! The SMB GW asks the Management every 5 minutes if the policy has changed - see the corresponding entries in /var/log/log/sfwd.elg:
[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] Fetching Security Policy from '172.27.39.198'
[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] Local Security Policy is Up-To-Date.
[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:06:59] The Security Policy was not installed because it is the same as the Policy already on the Module.
[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] Fetching Threat Prevention Policy from '172.27.39.198'
[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] Local Threat Prevention Policy is Up-To-Date.
[sfwd 4538 2000560128]@zwelfhundertr[19 Mar 10:07:24] The Threat Prevention Policy was not installed because it is the same as the Policy already on the Module.
Firmware upgrade check can also be found in sfwd.elg - it is logged additionally also in
/var/log/log/check_available_firmware.elg:
[check_available_firmware 5451 1996578816]@zwelfhundertr[14 Mar 13:35:53] check_available_firmware: Thu Mar 14 13:35:53 2019
[check_available_firmware 6332 2011901952]@zwelfhundertr[14 Mar 16:11:28] check_available_firmware: Thu Mar 14 16:11:28 2019
Licenses are synced with UserCenter every hour - see /var/log/log/uc_activation.elg:
[uc_activation 7732 1998979072]@zwelfhundertr[19 Mar 5:22:07] uc_activation: Tue Mar 19 05:22:07 2019
main: setting do_refresh
UCACT_write_blades: g_n_items=12 g_lic_exp=null pnp_stat=TP_EXPIRED_LIC
UCACT_write_blades: lic_exist=1 lic_exp=Feb 4, 2020
[uc_activation 7944 2006491136]@zwelfhundertr[19 Mar 6:22:03] uc_activation: Tue Mar 19 06:22:03 2019
main: setting do_refresh
UCACT_write_blades: g_n_items=12 g_lic_exp=null pnp_stat=TP_EXPIRED_LIC
UCACT_write_blades: lic_exist=1 lic_exp=Feb 4, 2020
TED wants all 12 hours his License refreshment, see /var/log/log/ted.elg:
[ 12673 2002706432][16 Mar 2:13:54] [TE_TRACE]: Starting licenses refreshment
[ 12673 2002706432][16 Mar 14:13:54] [TE_TRACE]: Starting licenses refreshment
[ 12673 2002706432][17 Mar 2:13:54] [TE_TRACE]: Starting licenses refreshment
So we can see that there is really a lot of work to do even for the small ones 😉
Also see this list SMB documents for more.
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist