<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shutting Down Checkpoint ClusterXL in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17370#M1319</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you check out the ClusterXL Admin guide, it suggests that cphastop should only be run by cpstop.&lt;/P&gt;&lt;P&gt;As such, a&amp;nbsp;cpstop would probably be safer as it stops all related processes/sync and a bit quicker than a reboot.&lt;/P&gt;&lt;P&gt;After you've swapped the cables, you can do a cpstart.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 21 Apr 2018 04:24:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-04-21T04:24:49Z</dc:date>
    <item>
      <title>Shutting Down Checkpoint ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17367#M1316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a couple of&amp;nbsp;simple questions regarding the shut down procedure for a checkpoint cluster.&amp;nbsp;I have a 2 node Cluster running in HA new mode (not legacy) in active/standby non bridge mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;If I&amp;nbsp;need to move the hardware or rerack, etc, and need to completely power off the gateways/cluster. What is the proper process to gracefully shutdown all nodes in a cluster?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If I am moving the internal interfaces to a new core switch on both checkpoint gateways in the cluster and thereby need to physically disconnect all interfaces on both gateways at the same time, what is the proper way to do this without causing an unwanted failover?&amp;nbsp; Should I completely power off the gateways or just shutdown the cluster software via some method?&amp;nbsp;Something else? &amp;nbsp;How would I do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2018 14:59:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17367#M1316</guid>
      <dc:creator>jwmac</dc:creator>
      <dc:date>2018-04-20T14:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting Down Checkpoint ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17368#M1317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For temporarily shutting down individual nodes of a cluster,&amp;nbsp;there is no special procedure.&lt;/P&gt;&lt;P&gt;Make sure the unit is halted using the "halt" command on the CLI or similar using the Gaia WebUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm curious why you think you need to disconnect ALL interfaces rather than, say, the ones you're changing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, how long will it take to physically swap the cables?&lt;/P&gt;&lt;P&gt;That will probably determine the best approach to take.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2018 17:24:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17368#M1317</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-20T17:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting Down Checkpoint ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17369#M1318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have both nodes connected via 802.3ad LAG to the core switches that will be replaced.&amp;nbsp; These&amp;nbsp;bonds are what handle all internal traffic.&amp;nbsp;What I mean by ALL interfaces is I will be disconnecting these bonded interfaces which connect to the core.&amp;nbsp; It will probably take at least a minute to&amp;nbsp;move&amp;nbsp;the interfaces to the new core switches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want to cause an inadvertent failover when I move the interfaces on the Master gateway which is why I ask question 2. Ideally I would like to temporarily stop/disable the cluster to prevent a failover from happening when moving the interfaces on the master, not sure how to do this.&amp;nbsp; Should I halt the standby node?&amp;nbsp; Would cphastop work and then run cphastart after moving interfaces?&amp;nbsp; I want to make sure I have the safest procedure..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2018 22:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17369#M1318</guid>
      <dc:creator>jwmac</dc:creator>
      <dc:date>2018-04-20T22:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting Down Checkpoint ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17370#M1319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you check out the ClusterXL Admin guide, it suggests that cphastop should only be run by cpstop.&lt;/P&gt;&lt;P&gt;As such, a&amp;nbsp;cpstop would probably be safer as it stops all related processes/sync and a bit quicker than a reboot.&lt;/P&gt;&lt;P&gt;After you've swapped the cables, you can do a cpstart.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2018 04:24:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17370#M1319</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-21T04:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting Down Checkpoint ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17371#M1320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm also curious about this:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;EM style="background-color: #ffffff; color: #333333;"&gt;...need to physically disconnect all interfaces on both gateways at the same time, what is the proper way to do this without causing an unwanted failover?&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;I see you're worried about preventing fail-overs in the cluster. However, if you're going to shutdown all the members, and also to disconnect the interfaces from both at the same time, why worring about fail-overs? I just want to be sure I'm understanding the situation &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2018 08:50:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Shutting-Down-Checkpoint-ClusterXL/m-p/17371#M1320</guid>
      <dc:creator>Victor_MR</dc:creator>
      <dc:date>2018-04-21T08:50:58Z</dc:date>
    </item>
  </channel>
</rss>

