CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 2 of 2

Thread: How does "Fetch Policy" work on small appliances centrally managed in r80.10

  1. #1
    Join Date
    2017-02-06
    Posts
    16
    Rep Power
    0

    Default How does "Fetch Policy" work on small appliances centrally managed in r80.10

    We have about 100 CP1100 and 1430 gateways being managed in R80.10. Each one is set to "fetch" policy every two hours. I have recently made changes and noticed they are not actually getting the changes, I was wondering if this has changed from 77.30?

    Detail...

    I made a change to a firewall policy to block all traffic from a particular desktop last week as a test. I saved the policy but did not specifically push it to the firewall. The PC traffic was not blocked even after a week, when I finally pushed it to the checkpoint itself. The 1430 never "fetched" the new policy.

    In another instance, I added a workstation to a group object. The group has access to ping the remote checkpoints and their modems. I published the change and installed the main policy (not the policy on the remote locations), and again, the change was not effective.

    Is it a requirement now to install the policy to all the remote locations to get a new policy on them? Is the fetch option no longer working in R80.10? I don't recall having to push policy to every gateway in r77.30 under SmartProvisioning, is that something SP did behind the scenes?

    Any insight is greatly appreciated.

    terri

  2. #2
    Join Date
    2007-03-30
    Location
    DFW, TX
    Posts
    428
    Rep Power
    19

    Default Re: How does "Fetch Policy" work on small appliances centrally managed in r80.10

    Edges used a policy fetch system. On the SmartCenter, "pushing" policy to the Edge (or an LSM profile for a group of Edges) instead compiles it, saves it locally on the SmartCenter, then sends the Edge a signal to do an out-of-cycle policy fetch. I don't have experience with GAiA Embedded, but I suspect the boxes work similarly. If I'm right, the files the firewall fetches are updated on policy "push", not when you simply save.

Similar Threads

  1. "Active Attention" and mismatched "Required interfaces"
    By SteveL in forum Clustering (Security Gateway HA and ClusterXL)
    Replies: 5
    Last Post: 2012-08-21, 15:47
  2. "enrollment failed" message in iphone "Checkpoint mobile" application
    By flruiz in forum IPsec VPN Blade (Virtual Private Networks)
    Replies: 4
    Last Post: 2011-06-30, 11:04
  3. What is purpose of "edges" in "Objects" on a network object?
    By RayPesek in forum Security Management Server (Formerly SmartCenter Server ((Formerly Management Server))
    Replies: 2
    Last Post: 2009-02-05, 12:55
  4. "fw stat" and "cpstat fw" show different time zones
    By cciesec2006 in forum Check Point SecurePlatform (SPLAT)
    Replies: 0
    Last Post: 2008-10-24, 09:33
  5. Replies: 0
    Last Post: 2008-02-22, 03:31

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •