Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
Thomas_Eichelbu
Advisor

How does Image auto-clone really work? How often does a SGM needs to reboot?

Hello fellow Check Mates, 

 

an interesting question i have received from a Maestro customer: "how often does a newly added SGM really needs to reboot?"

We saw the following:
A SGM was added after a RMA, and it booted 4 times! we collected the LOM output and saw all steps.
it took over 30min for the SGM to become active and start to forward traffic.
which is far from the marketing slides from Maestro, promising something below 10min 🙂 Yes its marketing.

the system was in Dual Site, VSX/VSLS with 2 VS, Running R81.10 Take 78.

the orig. installer details on the SMO:

show installer packages
Check_Point_R81_10_JHF_T66_155_MAIN_Bundle_T1_FULL.tgz Installed as part of
Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T66_FULL.tgz Installed as part of
Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T78_FULL.tgz Installed
Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T79_FULL.tgz Available for Download
SecurePlatform_HOTFIX_R81_10_JHF_T78_330_MAIN_GA_FULL.tgz Installed
fw1_wrapper_HOTFIX_R81_10_JHF_T78_859_MAIN_GA_FULL.tgz Installed

the SGM says:
show installer packages imported
** ************************************************************************* **
** Hotfixes **
** ************************************************************************* **
Display name Type
Check_Point_R81_10_JHF_T66_155_MAIN_Bundle_T1_FULL.tgz Hotfix
Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T78_FULL.tgz Hotfix
SecurePlatform_HOTFIX_R81_10_JHF_T78_330_MAIN_GA_FULL.tgz Package
fw1_wrapper_HOTFIX_R81_10_JHF_T78_859_MAIN_GA_FULL.tgz Package

show installer packages
** ************************************************************************* **
** Hotfixes **
** ************************************************************************* **
Display name Status
Check_Point_R81_10_JHF_T66_155_MAIN_Bundle_T1_FULL.tgz Installed as part of
Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T66_FULL.tgz Installed as part of
Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T78_FULL.tgz Installed
Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T79_FULL.tgz Available for Download
SecurePlatform_HOTFIX_R81_10_JHF_T78_330_MAIN_GA_FULL.tgz Installed
fw1_wrapper_HOTFIX_R81_10_JHF_T78_859_MAIN_GA_FULL.tgz Installed

so what is the SGM really doing when he was added to the Security Group and "apply" has been pressed.
we saw it took 8 minutes to "wait"; we saw an "rsync"operation was running.
does it mean all imported hotfixes from the CPUSE repository will be sent to the new SGM and then installed one after another?
where is the "imaging"  happening in the command  "set smo image auto-clone state on" command?


since we have VSX and a few VS on top we can accept a longer reboot ...
but 30min? is this normal?
does the SGM really installs all of the HFA/costum hotfixes one after another?
what if we have many many hotfixes and custom hotfixes installed, does it really reboots for every Hotfix?
will the "apply" button in the Security Group will initiate a factory reset to whipe all unwanted configuration off the appliance?
so two reboots seem to be the minimum then?

and if CPUSE says
Installed as part of
Installed as part of
Installed as part of

does is really install all those previous Hotfixes too?
or is this required to be able to install hotfixes, even when they came via "image auto-clone"?

who has a good technical explanation of this?

 

best regards
Thomas

(1)
Who rated this post