| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi There I have checkpoint NG AI running on SPLAT in distibuted model. Have 2 firewall modules in Active/standby cluster. After I install HFA17 on the redundant firewall enforcement and reboot I can no longer run cphastat and see the status of the active firewall. When I run cphastat it only can see the local firewall which says its ready (with no load). Is this normal? Normally after a HF I can still run this command before I upgarde my other firewall and see the status of both. |
| |||
| I have seen this with my customers as well. HFA_17 appears to do this. If you use 'cphaprob state' it will show something about doing an upgrade. As far as I can see you have to upgrade the other appliance before they see each other. |
| |||
| Thanks for this. My only issue is that after I install the hotfix I lose connection to the enforcement module even though it is installing the correct firewall policy. I am hesitant to upgrade both as this seems very different from every other Hotfix. Did you hotfix both the active and standby modules? What was the outcome? |
| |||
| Quote:
|
| |||
| Yeap - upgraded smartcenter first (after I install hfa17 on one of the enforcement module's and restart the system it installs the lastest policy successfully when it restarts). I have installed hotfixes many times and normally they run extremely smoothly. I have currently rolled back to HFA16 which operates as normal. Obviolusly I could try and install the hotfix on both enforcement modules to see what happens however this means downtime if its not successful which I am concerned about. It seems very strange that after the hotfix is installed on the backup module it can no longer be managed from remote machines and no longer sees any cluster partner when I run cphaprob. Is anyone running SPLAT in cluster environment installed HFA17 without the above issues? I am considering just waiting for HFA18 otherwise.... |
![]() |
| Thread Tools | |
| Display Modes | |
| |