Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ratnesh_Singh
Explorer

Policy push on security gateway cluster

Hi Team,

I need some clarification. When we are installing policy on security gateway cluster configured in HA (Active/ Standby) .On which gateway policy will get install 1st . Standby or Active or both in parallel . Thanks 

0 Kudos
2 Replies
the_rock
Legend
Legend

I could be wrong when I say this, but I dont believe there is a method to it. I had seen many times where backup member gets policy first, but then in lots of cases, its master that gets done before backup.

0 Kudos
Juan_
Collaborator

Hi Ratnesh,

It really doesn't make a difference, policy will start applying once the active gets it, whilst the standby is on-freeze and not getting data connections.

 

Having said that, Which one "installs first" will depend on many factors but mainly:

 

  • Which member gets the policy files on $FWDIR/state/__tmp/FW1 first
    • This will depend if the standby is a silent standby, or independent with different network speeds from manager to active and manager to standby
  • Which one processes those files first
    • Here, as you guess, will depend on the resources available. In general, a standby member is idler than the active so it installs the policy first.

Hope that helps.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events