VSX Cluster Member fails to load the local VSX configuration in the following scenario:
- VSX Cluster is managed by Multi-Domain Security Management Server.
- Global Objects for Primary and Backup Domain Management Servers were defined and used in the policy.
Chain of events:
- By design, Cluster Member tries to pull the policy/configuration from the peer member and from the Security Management Server / Domain Management Server based on the IP addresses of the relevant objects in SmartDashboard.
- Each connection between Check Point machines is based on SIC.
- VSX Cluster Member is able to obtain the SIC Name of the peer VSX Cluster Member, but pulling of VSX configuration is not allowed from peer VSX Cluster Members.
- VSX Cluster Member fails to obtain the SIC Name of its Primary and Backup Domain Management Servers because (by design) their Global Objects do not have such attribute (SIC Name). This fails the pulling of VSX configuration from the Management Server.
- As a result, the entire fetch process fails.