<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to resize Check Point Cloudguard NGFW High-Availability Cluster in Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197558#M5934</link>
    <description>&lt;P&gt;Procedure to upgrade Azure CKP Cloudguard firewalls (tested on R80.40)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[1] Connect to SSH on each of the Firewalls in the cluster&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [a] Evaluate the cluster is working and take not of the current Primary member&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # cphaprob state&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # cphaprob roles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ID         Role

1 (local)  Master
2          Non-Master&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [b] Check current core count and distribution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # fw ctl get int fwlic_num_of_allowed_cores&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # fw ctl multik stat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [c] Check current contents of &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; file&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cat /var/opt/fw.boot/boot.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe1:0]# cat /var/opt/fw.boot/boot.conf
CTL_IPFORWARDING        1
DEFAULT_FILTER_PATH     /etc/fw.boot/default.bin
KERN_INSTANCE_NUM       3
COREXL_INSTALLED        1
KERN6_INSTANCE_NUM      2
IPV6_INSTALLED  0
CORE_OVERRIDE   4&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[2] Connect to &lt;STRONG&gt;portal.azure.com&lt;/STRONG&gt; and locate the Firewall VM’s. Proceed to stop the standby member identified at step [1][a] as &lt;STRONG&gt;Non-Master&lt;/STRONG&gt; or &lt;STRONG&gt;Standby&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;[3] On the Firewall VM’s properties - &lt;STRONG&gt;Browse to Settings &amp;gt; Size &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Pick the new VM size of choice:&lt;/P&gt;&lt;P&gt;In our case we need 16 cores&lt;/P&gt;&lt;P&gt;Reference: &lt;A href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.checkpoint.com%2Fresults%2Fsk%2Fsk109360%23Pricing%2520in%2520Azure%2520Marketplace&amp;amp;data=05%7C01%7Ccvarlan%40ptc.com%7C2fe687a49f604ef4a38608dbd3ec1076%7Cb9921086ff774d0d828acb3381f678e2%7C0%7C0%7C638336783128361165%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;amp;sdata=wAcEVT3ddxTfDV2w75DlrbQZiiCuLQMfJP0yWndBwb8%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk109360#Pricing%20in%20Azure%20Marketplace&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[4] Press the &lt;STRONG&gt;Resize&lt;/STRONG&gt; button&lt;/P&gt;&lt;P&gt;[5] Once the machine is resized you can Start the VM and check cluster status&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Browse to Overview and press the &lt;STRONG&gt;Start&lt;/STRONG&gt; button.&lt;/P&gt;&lt;P&gt;Once the VM has started check cluster status and core distribution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cphaprob role
ID         Role

1          Master
2 (local)  Non-Master

[Expert@ckpupgrademe2:0]# cphaprob state

Cluster Mode:   High Availability (Active Up) with IGMP Membership

ID         Unique Address  Assigned Load   State          Name

1          10.8.1.5        100%            ACTIVE         CKPUPGRADEME1
2 (local)  10.8.1.6        0%              STANDBY        CKPUPGRADEME2

Active PNOTEs: None

Last member state change event:
   Event Code:                 CLUS-114802
   State change:               DOWN -&amp;gt; STANDBY
   Reason for state change:    There is already an ACTIVE member in the cluster (member 1)
   Event time:                 Tue Nov  7 11:15:18 2023

Cluster failover count:
   Failover counter:           0
   Time of counter reset:      Tue Nov  7 03:07:17 2023 (reboot)

[Expert@ckpupgrademe2:0]#
[Expert@ckpupgrademe2:0]# fw ctl multik stat
ID | Active  | CPU    | Connections | Peak
----------------------------------------------
 0 | Yes     | 15     |          22 |       39
 1 | Yes     | 14     |          31 |       41
 2 | Yes     | 13     |          34 |       41
[Expert@ckpupgrademe2:0]#&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Looks like the second member still has only 3 FW workers. But it has all the 16 cores.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cat /proc/cpuinfo  | grep proc
processor       : 0
processor       : 1
processor       : 2
processor       : 3
processor       : 4
processor       : 5
processor       : 6
processor       : 7
processor       : 8
processor       : 9
processor       : 10
processor       : 11
processor       : 12
processor       : 13
processor       : 14
processor       : 15&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[6] Check the contents of the &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cat /var/opt/fw.boot/boot.conf

CTL_IPFORWARDING        1
DEFAULT_FILTER_PATH     /etc/fw.boot/default.bin
KERN_INSTANCE_NUM       3
COREXL_INSTALLED        1
KERN6_INSTANCE_NUM      2
IPV6_INSTALLED  0
CORE_OVERRIDE   16&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This means that it sees all the cores but limits number of Kernel Instances to 3. If the two cluster members have different core numbers you would have issues with cluster sync. We do now have full cluster functionality even if the VMs are of different sizes so we can switch this member to active and perform the same steps before finally editing the boot.conf file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[7] Switchover the cluster from Primary to Standby.&lt;/P&gt;&lt;P&gt;[a] Connect via SSH to the current Primary [Active] member&lt;/P&gt;&lt;P&gt;[b] Run the “# &lt;EM&gt;clusterXL_admin down&lt;/EM&gt;” command&lt;/P&gt;&lt;P&gt;[c] Confirm that the cluster has been switched over&lt;/P&gt;&lt;P&gt;[8] Perform steps [1] -&amp;gt; [6] on the new Standby member.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;[9] Edit &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; and make sure to correct the number of &lt;STRONG&gt;KERN_INSTANCE_NUM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cat /var/opt/fw.boot/boot.conf
CTL_IPFORWARDING        1
DEFAULT_FILTER_PATH     /etc/fw.boot/default.bin
KERN_INSTANCE_NUM       14
COREXL_INSTALLED        1
KERN6_INSTANCE_NUM      2
IPV6_INSTALLED  0
CORE_OVERRIDE   16&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[10] Reboot the firewall to apply the changes. Now check the number of cores&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe1:0]# fw ctl multik stat
Kernel fw_0: CPU 15
Kernel fw_1: CPU 14
Kernel fw_2: CPU 13
Kernel fw_3: CPU 12
Kernel fw_4: CPU 11
Kernel fw_5: CPU 10
Kernel fw_6: CPU 9
Kernel fw_7: CPU 8
Kernel fw_8: CPU 7
Kernel fw_9: CPU 6
Kernel fw_10: CPU 5
Kernel fw_11: CPU 4
Kernel fw_12: CPU 3
Kernel fw_13: CPU 2
Daemon cprid: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon mpdaemon: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon fwd: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon in.asessiond: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon lpd: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon core_uploader: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon cprid: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon cpd: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Interface enP38308p0s2: has multi queue enabled
Interface enP47606p0s2: has multi queue enabled&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[11] At this point the cluster would not work as one member has more FW instances than the other. Connect to the Primary member and perform the edit on &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; and reboot. Once the Primary member is rebooted, the remaining cluster member with modified core **bleep** will now become primary and once the second member comes back online the cluster will be functioning normally.&lt;/P&gt;&lt;P&gt;[12] Push policy and check logs to confirm normal operation.&lt;/P&gt;&lt;P&gt;[13] Futher optimization&lt;/P&gt;&lt;P&gt;[a] Edit Affinity $FWDIR/conf/fwaffinity.conf and allocate cores to specific interfaces. Also keep in mind you need to allocate at least one core to FWD for heavy logging.&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;/STRONG&gt;You should not go over the total VM core limit. If you are allocating cores to SND and FWD decrease the Kernel instance number to provide enough usable cores and not oversubscribe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 08:07:27 GMT</pubDate>
    <dc:creator>cezar_varlan1</dc:creator>
    <dc:date>2023-11-09T08:07:27Z</dc:date>
    <item>
      <title>How to resize Check Point Cloudguard NGFW High-Availability Cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197558#M5934</link>
      <description>&lt;P&gt;Procedure to upgrade Azure CKP Cloudguard firewalls (tested on R80.40)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[1] Connect to SSH on each of the Firewalls in the cluster&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [a] Evaluate the cluster is working and take not of the current Primary member&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # cphaprob state&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # cphaprob roles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ID         Role

1 (local)  Master
2          Non-Master&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [b] Check current core count and distribution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # fw ctl get int fwlic_num_of_allowed_cores&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # fw ctl multik stat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [c] Check current contents of &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; file&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cat /var/opt/fw.boot/boot.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe1:0]# cat /var/opt/fw.boot/boot.conf
CTL_IPFORWARDING        1
DEFAULT_FILTER_PATH     /etc/fw.boot/default.bin
KERN_INSTANCE_NUM       3
COREXL_INSTALLED        1
KERN6_INSTANCE_NUM      2
IPV6_INSTALLED  0
CORE_OVERRIDE   4&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[2] Connect to &lt;STRONG&gt;portal.azure.com&lt;/STRONG&gt; and locate the Firewall VM’s. Proceed to stop the standby member identified at step [1][a] as &lt;STRONG&gt;Non-Master&lt;/STRONG&gt; or &lt;STRONG&gt;Standby&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;[3] On the Firewall VM’s properties - &lt;STRONG&gt;Browse to Settings &amp;gt; Size &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Pick the new VM size of choice:&lt;/P&gt;&lt;P&gt;In our case we need 16 cores&lt;/P&gt;&lt;P&gt;Reference: &lt;A href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.checkpoint.com%2Fresults%2Fsk%2Fsk109360%23Pricing%2520in%2520Azure%2520Marketplace&amp;amp;data=05%7C01%7Ccvarlan%40ptc.com%7C2fe687a49f604ef4a38608dbd3ec1076%7Cb9921086ff774d0d828acb3381f678e2%7C0%7C0%7C638336783128361165%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;amp;sdata=wAcEVT3ddxTfDV2w75DlrbQZiiCuLQMfJP0yWndBwb8%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk109360#Pricing%20in%20Azure%20Marketplace&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[4] Press the &lt;STRONG&gt;Resize&lt;/STRONG&gt; button&lt;/P&gt;&lt;P&gt;[5] Once the machine is resized you can Start the VM and check cluster status&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Browse to Overview and press the &lt;STRONG&gt;Start&lt;/STRONG&gt; button.&lt;/P&gt;&lt;P&gt;Once the VM has started check cluster status and core distribution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cphaprob role
ID         Role

1          Master
2 (local)  Non-Master

[Expert@ckpupgrademe2:0]# cphaprob state

Cluster Mode:   High Availability (Active Up) with IGMP Membership

ID         Unique Address  Assigned Load   State          Name

1          10.8.1.5        100%            ACTIVE         CKPUPGRADEME1
2 (local)  10.8.1.6        0%              STANDBY        CKPUPGRADEME2

Active PNOTEs: None

Last member state change event:
   Event Code:                 CLUS-114802
   State change:               DOWN -&amp;gt; STANDBY
   Reason for state change:    There is already an ACTIVE member in the cluster (member 1)
   Event time:                 Tue Nov  7 11:15:18 2023

Cluster failover count:
   Failover counter:           0
   Time of counter reset:      Tue Nov  7 03:07:17 2023 (reboot)

[Expert@ckpupgrademe2:0]#
[Expert@ckpupgrademe2:0]# fw ctl multik stat
ID | Active  | CPU    | Connections | Peak
----------------------------------------------
 0 | Yes     | 15     |          22 |       39
 1 | Yes     | 14     |          31 |       41
 2 | Yes     | 13     |          34 |       41
[Expert@ckpupgrademe2:0]#&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Looks like the second member still has only 3 FW workers. But it has all the 16 cores.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cat /proc/cpuinfo  | grep proc
processor       : 0
processor       : 1
processor       : 2
processor       : 3
processor       : 4
processor       : 5
processor       : 6
processor       : 7
processor       : 8
processor       : 9
processor       : 10
processor       : 11
processor       : 12
processor       : 13
processor       : 14
processor       : 15&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[6] Check the contents of the &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cat /var/opt/fw.boot/boot.conf

CTL_IPFORWARDING        1
DEFAULT_FILTER_PATH     /etc/fw.boot/default.bin
KERN_INSTANCE_NUM       3
COREXL_INSTALLED        1
KERN6_INSTANCE_NUM      2
IPV6_INSTALLED  0
CORE_OVERRIDE   16&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This means that it sees all the cores but limits number of Kernel Instances to 3. If the two cluster members have different core numbers you would have issues with cluster sync. We do now have full cluster functionality even if the VMs are of different sizes so we can switch this member to active and perform the same steps before finally editing the boot.conf file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[7] Switchover the cluster from Primary to Standby.&lt;/P&gt;&lt;P&gt;[a] Connect via SSH to the current Primary [Active] member&lt;/P&gt;&lt;P&gt;[b] Run the “# &lt;EM&gt;clusterXL_admin down&lt;/EM&gt;” command&lt;/P&gt;&lt;P&gt;[c] Confirm that the cluster has been switched over&lt;/P&gt;&lt;P&gt;[8] Perform steps [1] -&amp;gt; [6] on the new Standby member.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;[9] Edit &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; and make sure to correct the number of &lt;STRONG&gt;KERN_INSTANCE_NUM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe2:0]# cat /var/opt/fw.boot/boot.conf
CTL_IPFORWARDING        1
DEFAULT_FILTER_PATH     /etc/fw.boot/default.bin
KERN_INSTANCE_NUM       14
COREXL_INSTALLED        1
KERN6_INSTANCE_NUM      2
IPV6_INSTALLED  0
CORE_OVERRIDE   16&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[10] Reboot the firewall to apply the changes. Now check the number of cores&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@ckpupgrademe1:0]# fw ctl multik stat
Kernel fw_0: CPU 15
Kernel fw_1: CPU 14
Kernel fw_2: CPU 13
Kernel fw_3: CPU 12
Kernel fw_4: CPU 11
Kernel fw_5: CPU 10
Kernel fw_6: CPU 9
Kernel fw_7: CPU 8
Kernel fw_8: CPU 7
Kernel fw_9: CPU 6
Kernel fw_10: CPU 5
Kernel fw_11: CPU 4
Kernel fw_12: CPU 3
Kernel fw_13: CPU 2
Daemon cprid: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon mpdaemon: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon fwd: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon in.asessiond: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon lpd: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon core_uploader: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon cprid: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Daemon cpd: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15
Interface enP38308p0s2: has multi queue enabled
Interface enP47606p0s2: has multi queue enabled&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[11] At this point the cluster would not work as one member has more FW instances than the other. Connect to the Primary member and perform the edit on &lt;STRONG&gt;boot.conf&lt;/STRONG&gt; and reboot. Once the Primary member is rebooted, the remaining cluster member with modified core **bleep** will now become primary and once the second member comes back online the cluster will be functioning normally.&lt;/P&gt;&lt;P&gt;[12] Push policy and check logs to confirm normal operation.&lt;/P&gt;&lt;P&gt;[13] Futher optimization&lt;/P&gt;&lt;P&gt;[a] Edit Affinity $FWDIR/conf/fwaffinity.conf and allocate cores to specific interfaces. Also keep in mind you need to allocate at least one core to FWD for heavy logging.&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;/STRONG&gt;You should not go over the total VM core limit. If you are allocating cores to SND and FWD decrease the Kernel instance number to provide enough usable cores and not oversubscribe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 08:07:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197558#M5934</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2023-11-09T08:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to resize Check Point Cloudguard NGFW High-Availability Cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197584#M5935</link>
      <description>&lt;P&gt;Nice&lt;/P&gt;
&lt;P&gt;Thank you for sharing&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 12:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197584#M5935</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2023-11-09T12:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to resize Check Point Cloudguard NGFW High-Availability Cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197645#M5936</link>
      <description>&lt;P&gt;See also:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk149512" target="_self"&gt;sk149512: How to resize CloudGuard VMs to allocate additional CPU cores&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 22:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197645#M5936</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-09T22:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to resize Check Point Cloudguard NGFW High-Availability Cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197674#M5937</link>
      <description>&lt;P&gt;Yes, this one works too. I tried to remember why this was not enough and the reason is on my last production upgrade I hit some kind of an issue where cpconfig was unable to write to the file. Going back through my notes here is what happened then:&lt;BR /&gt;&lt;BR /&gt;# We tried to edit the&amp;nbsp;/etc/fw.boot/boot.conf file in order to change the KERN_INSTANCE_NUM to 6 but we were getting the permission error.&lt;BR /&gt;&lt;BR /&gt;# As discussed when we change the CoreXL settings then the changes are pushed in the file boot.conf and due to permission issue the changes are not pushing and that's why cores was not increasing in CoreXL&lt;BR /&gt;&lt;BR /&gt;# There was a lock on the file boot.conf in order to release the lock we ran below command:-&lt;BR /&gt;&lt;BR /&gt;chattr -i boot.conf&lt;BR /&gt;&lt;BR /&gt;# After unlocking the file we did the changes through cpconfig and enable the 6 fw workers and post rebooting the gateway we could see that CoreXL is now enable with 6 cores on both the gateway. Also we enable the Multi-Queue&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 08:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-to-resize-Check-Point-Cloudguard-NGFW-High-Availability/m-p/197674#M5937</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2023-11-10T08:04:47Z</dc:date>
    </item>
  </channel>
</rss>

