Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
BikeMan
Collaborator
Jump to solution

Polcy load at boot

Hello,

May be I am in the wrong section... I will see if I get any answer.

I have an old appliance 14xx still managed by our MDM (yes I know EOL....). Now I have to upgrade MDM to R82.10 and this version is no more supporting 14xx appliances. 

If I remove this appliance from the database (or if the MDM/CMA is no more reachable) will the latest policy remain on the appliance ?

What if I reboot this appliance ? It will load the Initial Policy or it will keep the old policy ?

Thanks for your help.

 

0 Kudos
1 Solution

Accepted Solutions
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

So, there's kind of two different possible scenarios. If a gateway loses contact with the management server, it will keep on keeping on, retaining the policy on reboot as long as it starts up properly, until something else happens and it doesn't anymore. In your case though, if you delete the gateway from the management server, the gateway will try to talk to it and learn that its SIC cert is revoked. This is less charted waters, most of us won't have tried this scenario, and we don't want to tell you 'yea mate she'll be right' and leave you in the lurch should you suddenly have a with no policy on it. It won't suddenly unload the policy upon learning that its SIC is revoked, but I don't know what it will do on reboot. Hence we offer safer alternatives. 

View solution in original post

10 Replies
simonemantovani
MVP Platinum
MVP Platinum

It should load the latest installed policy.

0 Kudos
BikeMan
Collaborator

Thanks for answering.

Also think "it should" but I would prefer "it will". And since hard and soft are EOL, unable to raise a ticket.

Lesley
MVP Platinum
MVP Platinum

Now system is central managed, these boxes can also be locally managed. With local mgmt, the rules and logs stay on the local box and you dont need a MDM anymore. Note: CRL check will fail towards mgmt, this is needed for site to site vpn between Check Point to Check Point. CRL check can be disabled. 

During reboot it will reach out to mgmt but also during normal operations it will check if there is a new policy and will fetch it. if there is nothing to fetch box will not load a default policy.

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
BikeMan
Collaborator

Hi,

Probably I have not been clear enough.

Currently device is running with policy name "policy-from-cma".

Then I do not allow communication with the CMA anymore.

Then rebooting appliance. Is it going to load a local copy of "policy-from-cma" of load the default policy ?

 

Rgds,

 

0 Kudos
simonemantovani
MVP Platinum
MVP Platinum

It will load a local copy of "policy-from-cma"

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

It will work until it doesn't, at which point you won't be able to easily fix it. I think Lesley has the right idea - take the time to properly plan to reset it into Locally Managed mode and do it on your schedule, instead of waiting until it decides you need to do it.

0 Kudos
BikeMan
Collaborator

Hi,

Happy to read everybody. But still no answer...

Question is about boot process and policy load. Not about what I should do or not.

Rgds,

 

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

So, there's kind of two different possible scenarios. If a gateway loses contact with the management server, it will keep on keeping on, retaining the policy on reboot as long as it starts up properly, until something else happens and it doesn't anymore. In your case though, if you delete the gateway from the management server, the gateway will try to talk to it and learn that its SIC cert is revoked. This is less charted waters, most of us won't have tried this scenario, and we don't want to tell you 'yea mate she'll be right' and leave you in the lurch should you suddenly have a with no policy on it. It won't suddenly unload the policy upon learning that its SIC is revoked, but I don't know what it will do on reboot. Hence we offer safer alternatives. 

BikeMan
Collaborator

This is the more accurate answer I had. I will deal with it.

0 Kudos
PhoneBoy
Admin
Admin

Even though it's not officially supported, it's quite possible that you will still be able to manage and install policy on your 1400 from R82.10 assuming the object existed prior to the upgrade.
At least that's been the case in the past when we've deprecated support for a given appliance/version as the underlying "Backward Compatibility" packages are still there.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events