156-215.80 · Question #333
If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security…
The correct answer is A. Rename the hostname of the Standby member to match exactly the hostname of the Active. When the Active Security Management Server is still operational, renaming the standby hostname is not part of the graceful failover procedure and should not be performed.
Question
If the Active Security Management Server fails or if it becomes necessary to change the Active to Standby, the following steps must be taken to prevent data loss. Providing the Active Security Management Server is responsible, which of these steps should NOT be performed:
Options
- ARename the hostname of the Standby member to match exactly the hostname of the Active
- BChange the Standby Security Management Server to Active.
- CChange the Active Security Management Server to Standby.
- DManually synchronize the Active and Standby Security Management Servers.
How the community answered
(43 responses)- A56% (24)
- B5% (2)
- C14% (6)
- D26% (11)
Why each option
When the Active Security Management Server is still operational, renaming the standby hostname is not part of the graceful failover procedure and should not be performed.
Renaming the standby member's hostname to match the active is only relevant in a disaster recovery scenario where the active server is completely unrecoverable and cannot be demoted cleanly. When the active server is still responsible and functional, the correct procedure is to manually sync, demote the active to standby, then promote the standby - no hostname changes are needed. Performing a hostname rename unnecessarily risks identity conflicts and is explicitly excluded from the planned failover steps.
Promoting the standby to active is a required failover step to restore management continuity after the active is demoted.
Demoting the active server to standby is a required step to ensure a clean, controlled role transition without split-brain conditions.
Manual synchronization is required before switching roles to ensure both servers share identical policy and object databases, preventing data loss.
Concept tested: Check Point SMS High Availability planned failover steps
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/HA-New-Active-Member.htm
Topics
Community Discussion
No community discussion yet for this question.