What has to be taken into consideration when configuring Management HA?
A.
The Database revisions will not be synchronized between the management servers
B.
SmartConsole must be closed prior to synchronize changes in the objects database
C.
If you wanted to use Full Connectivity Upgrade, you must change the Implied Rules to allow FW1_cpredundant to pass before the Firewall Control Connections.
D.
For Management Server synchronization, only External Virtual Switches are supported. So, if you wanted to employ Virtual Routers instead, you have to reconsider your design.
I think that A is correct. From CCSE R80 Guide:
Initially, the Primary and Secondary Security Management Servers must be manually synchronized. If additional Standby servers are installed, configure automatic synchronization in the Global Properties. Once the Secondary Security Management Server has been installed and manually synchronized, the Primary and Secondary are both prepared to function as the Active Security Management Server.
Answer A is NOT correct. Official info states : Management High Availability uses the built-in revisions technology and allows the High Availability procedure to synchronize only the changes done since the last synchronization.
Source : https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Overview-Management-High-Availability.htm?Highlight=revision
Confirmation on A not being the correct answer here ( video from Checkpoint ) : https://youtu.be/HFxcGew2OOA ... the only issue I face now, what is then correct answer then :'(
from CCSE R80 guide:
For Management HA to function properly, the following data is backed up and synchronized:
•Network Security Management Databases (such as the Network Objects, policy settings, and the Security Policy itself)
•Configuration and Internal Certificate Authority (ICA) data (such as Objects and Users databases, certificate information, and the CRL, which is available to be fetched by the Check Point Security Gateways)
•Endpoint Security databases, if applicable
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Hernan_Mella
5 months, 1 week agoAmathai1803
11 months agoH13n
1 year, 3 months agoAnni_CCSA
1 year, 6 months agoAnni_CCSA
1 year, 2 months agolcorona76
1 year, 6 months agoNikolas
2 years, 1 month agoAnubhaw
2 years, 1 month ago