<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connections after cluster failure test in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-after-cluster-failure-test/m-p/22973#M1751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, can you help me? We have the following problem.&lt;BR /&gt;The client has an Active/Standby cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I turn off the active node, the standby normally takes over the environment.&lt;BR /&gt;With this action, the gateways switch function.&lt;/P&gt;&lt;P&gt;The node that was active becomes standby and the standby is active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far, no problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The problem occurs when I unplug the node that was previously standby and became active.&lt;/P&gt;&lt;P&gt;At that point, users' Internet access stops happening.&lt;BR /&gt;When applying policy, how the connections are reestablished.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some information:&lt;/P&gt;&lt;P&gt;1. In the log, the connections appear as Accept;&lt;BR /&gt;2. If a user accesses a banned site, the banned access page is displayed;&lt;BR /&gt;3. External publications work smoothly;&lt;BR /&gt;4. It is possible to ping in stations that do not navigate.&lt;BR /&gt;5. Servers that are in the DMZ do not face the problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I created a rule above the web filtering rule and this host does not face the problem.&lt;BR /&gt;Apparently the problem has to do with user sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@gw01:0]# cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 10.255.1.18 100% Active&lt;BR /&gt;2 (local) 10.255.1.17 0% Standby&lt;/P&gt;&lt;P&gt;Local member is in current state since Tue Aug 28 14:15:10 2018&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@gw02:0]# cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 (local) 10.255.1.18 100% Active&lt;BR /&gt;2 10.255.1.17 0% Standby&lt;/P&gt;&lt;P&gt;Local member is in current state since Tue Aug 28 12:12:54 2018&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Aug 2018 17:45:59 GMT</pubDate>
    <dc:creator>Carlos_Silva</dc:creator>
    <dc:date>2018-08-28T17:45:59Z</dc:date>
    <item>
      <title>Connections after cluster failure test</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-after-cluster-failure-test/m-p/22973#M1751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, can you help me? We have the following problem.&lt;BR /&gt;The client has an Active/Standby cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I turn off the active node, the standby normally takes over the environment.&lt;BR /&gt;With this action, the gateways switch function.&lt;/P&gt;&lt;P&gt;The node that was active becomes standby and the standby is active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far, no problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The problem occurs when I unplug the node that was previously standby and became active.&lt;/P&gt;&lt;P&gt;At that point, users' Internet access stops happening.&lt;BR /&gt;When applying policy, how the connections are reestablished.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some information:&lt;/P&gt;&lt;P&gt;1. In the log, the connections appear as Accept;&lt;BR /&gt;2. If a user accesses a banned site, the banned access page is displayed;&lt;BR /&gt;3. External publications work smoothly;&lt;BR /&gt;4. It is possible to ping in stations that do not navigate.&lt;BR /&gt;5. Servers that are in the DMZ do not face the problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I created a rule above the web filtering rule and this host does not face the problem.&lt;BR /&gt;Apparently the problem has to do with user sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@gw01:0]# cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 10.255.1.18 100% Active&lt;BR /&gt;2 (local) 10.255.1.17 0% Standby&lt;/P&gt;&lt;P&gt;Local member is in current state since Tue Aug 28 14:15:10 2018&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@gw02:0]# cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 (local) 10.255.1.18 100% Active&lt;BR /&gt;2 10.255.1.17 0% Standby&lt;/P&gt;&lt;P&gt;Local member is in current state since Tue Aug 28 12:12:54 2018&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 17:45:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-after-cluster-failure-test/m-p/22973#M1751</guid>
      <dc:creator>Carlos_Silva</dc:creator>
      <dc:date>2018-08-28T17:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Connections after cluster failure test</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-after-cluster-failure-test/m-p/22974#M1752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You didn't mention the version/patch level of the gateway, which is almost always a relevant detail.&lt;/P&gt;&lt;P&gt;It also seems like you're using App Control/URL Filtering, but did not explicitly state this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would open&amp;nbsp;a TAC case and have them investigate in more detail.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 23:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-after-cluster-failure-test/m-p/22974#M1752</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-28T23:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Connections after cluster failure test</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-after-cluster-failure-test/m-p/22975#M1753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon, thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 23:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connections-after-cluster-failure-test/m-p/22975#M1753</guid>
      <dc:creator>Carlos_Silva</dc:creator>
      <dc:date>2018-08-30T23:49:00Z</dc:date>
    </item>
  </channel>
</rss>

