| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Wanted to share my recent experience since there didn't seem to be a whole lot out there about this issue. It ended up being a "try this" and it worked kind of episode. So here goes: I had inherited a primary and secondary Smart Center Server running R55. The secondary was not syncing with the primary. The secondary showed as unreachable in the Policy | Managment High Availability screen. When I would try to manually sync, I would get the error that the peer was not reachable. It showed it was synchronized on this screen, but a visit to the secondary server showed policies hadn't updated in a long time. To make a long story short, it turned out the $FWDIR/conf/mgmtha.conf and $FWDIR/conf/mgmtha_stack files were to blame. The mgmtha.conf file on the secondary server existed, but was 0 bytes. The primary one looked ok. The process to fix this problem follows: 1. Backup the mgmtha.conf and mgmtha_stack files on both SMS boxes. 2. Perform a cpstop on both servers. 3. Delete the mgmtha.conf and mgmtha_stack files on both boxes. 4. Perform a cpstart on both servers. 5. The restart regenerates the files on both servers. After doing this, the status showed as reachable and not sychronized. Performing a manual sync worked and now the updated policies all appear on the secondary server. As a side note, one indicator that your Management HA configuration isn't working, is if you try logging into the Smart Dashboard on the secondary server and you are not asked if you want to take it from standby to active or read-only. When it was broken, this pop-up box never appeared when we would log onto the secondary server and it acted just like a primary server. Another indicator of the problem was seen in the audit log whenever a policy was modified and you have automatic sync turned on. The audit log would show that the peer did not syncronize when the policy was saved. Hope this helps someone else as the information out there at Checkpoint and stuff found via Google was not very helpful! |
![]() |
| Thread Tools | |
| Display Modes | |
| |