The installation procedures from Command Line is quite simple:
- Transfer the Jumbo Hotfix Accumulator to the machine /var/tmp folder
- Unpack the Jumbo Hotfix Accumulator:
[Expert@CP-1]# cd /var/tmp
[Expert@CP-1]# tar zxvf Check_Point_R77.10.linux.tgz
- Install the Jumbo Hotfix Accumulator:
[Expert@CP-1]# ./UnixInstallScript
Note: The script will stop all of Check Point services (cpstop
) - read the output on the screen. - Reboot the machine.
- Verify Installation with Command "cpinfo -y all"
Symptoms:Â
I followed those steps and installed this Jumbo Hotfix on both cluster members at the same time also rebooted them at the same time. But after waited a couple of minutes, one of cluster members shows disconnected from Smartview Monitor.
When I ssh-ed into device and checked cluster status it shows ok. Also I were able to reach management server interface from problem cluster member. From the output of "cpinfo -y all " also shows the hotfix has been installed correctly.Â
[Expert@CP-DMZ-1:0]# cpinfo -y all
------------------------
Hotfix versions
------------------------
[FW1]Â
 HOTFIX_R77_10Â
 HOTFIX_R77_HF_HA10_005Â
  HOTFIX_GYPSY_HF_BASE_021Â
[SecurePlatform]Â
 HOTFIX_R77_10_GAIA_GHOST_833Â
  HOTFIX_GYPSY_HF_BASE_021Â
[SPSHARED]Â
 No hotfixes..
[CVPN]Â
 HOTFIX_R77_10Â
 HOTFIX_GYPSY_HF_BASE_021Â
[PPACK]Â
 HOTFIX_R77_10Â
 HOTFIX_GYPSY_HF_BASE_021Â
[CPinfo]Â
 No hotfixes..
[SmartLog]Â
 HOTFIX_R77_10Â
[rtm]Â
 No hotfixes..
Troubleshooting:
I went back to SmartDashboard and checked SIC status and found it was out of SIC. I was confusing what could cause the SIC lost from this cluster member. Should I reset SIC?
SmartView Tracker saved me this time. There is one log shows firewall policy inconsistencies existing between cluster members.
Number: Â Â Â Â Â Â 7250420
Date: Â Â Â Â Â Â Â Â 16Aug2015
Time: Â Â Â Â Â Â Â Â 10:09:07
Origin: Â Â Â Â Â Â Â CP-DMZ-1
Type: Â Â Â Â Â Â Â Â Log
Action: Â Â Â Â Â Â Â
Information: Â Â Â sync: Inconsistencies exist between policies installed on the cluster members. Please reinstall the policy on the cluster.
Product: Â Â Â Â Â Â Security Gateway/Management
Product Family: Network
Policy Info: Â Â Â Â Policy Name: defaultfilter
             Created at: Sun Aug 16 07:12:25 2015
             Installed from: CP-Management
Solutions:
I quickly pushed policy to cluster and it was failed because SIC error as shown below.
Amazing thing is this firewall policy push resolved SIC issue. Both firewall cluster members show green and OK status in Smartview Monitor.Â
No comments:
Post a Comment