<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cphaprob -a if show DOWN - Interface Active Check  Current state: problem in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cphaprob-a-if-show-DOWN-Interface-Active-Check-Current-state/m-p/125863#M18267</link>
    <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;since yesterday I have a problem on the secondary gateway, every now and then it happens that it disconnects but then comes back up without problems (never understood why), this time it remained down. I have already followed these sks, (I also put an external link, forgive me if it is not allowed, notify me and I will remove it immediately)&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121337" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121337&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114804" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114804&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.fir3net.com/Firewalls/Checkpoint/clusterxl-shows-active-attention-interface-active-check.html" target="_blank"&gt;https://www.fir3net.com/Firewalls/Checkpoint/clusterxl-shows-active-attention-interface-active-check.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;none of these solved my problem. I leave below a couple of command outputs, the problematic interface is &lt;STRONG&gt;eth1&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;(the eth1 interface is the one that reaches the outside, from which the whole network passes, one of the guides above explains to add the interface to the file $ FWDIR / conf / discntd.if but from what I understand, this file the does it exclude, so I would solve the error but not the malfunction problem, did I understand correctly? other thing, I did not do a cpstop / cpstart of both nodes, only the secondary one with problems, I did the push policy without errors and then I restarted the services but nothing. could i try with a reboot of the machine?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Primary Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 xxx.xxx.xxx.xxx 100% Active&lt;BR /&gt;2 (local) xxx.xxx.xxx.xxx 0% Down&lt;/P&gt;&lt;P&gt;Local member is in current state since Thu Aug 5 12:54:48 2021&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# cphaprob -l list&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem&lt;/P&gt;&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Synchronization&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11896.8 sec&lt;/P&gt;&lt;P&gt;Device Name: Filter&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11896.8 sec&lt;/P&gt;&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11948.7 sec&lt;/P&gt;&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11949.9 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11949 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: cvpnd&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 0.2 sec&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# cphaprob -a if&lt;/P&gt;&lt;P&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 2&lt;/P&gt;&lt;P&gt;eth0 Disconnected non sync(non secured), multicast&lt;BR /&gt;eth1 DOWN (12060 secs) non sync(non secured), multicast&lt;BR /&gt;eth3 UP non sync(non secured), multicast&lt;BR /&gt;eth4 UP sync(secured), multicast&lt;BR /&gt;eth5 UP sync(secured), multicast&lt;BR /&gt;eth2 UP non sync(non secured), multicast&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# clish -c "show interface eth1"&lt;BR /&gt;state on&lt;BR /&gt;mac-addr *********&lt;BR /&gt;type ethernet&lt;BR /&gt;link-state link up&lt;BR /&gt;mtu 1500&lt;BR /&gt;auto-negotiation on&lt;BR /&gt;speed 100M&lt;BR /&gt;ipv6-autoconfig Not configured&lt;BR /&gt;duplex full&lt;BR /&gt;monitor-mode off&lt;BR /&gt;link-speed Not configured&amp;nbsp; &amp;nbsp;&lt;FONT color="#FF0000"&gt; &lt;U&gt;&lt;STRONG&gt;&amp;lt;----&amp;nbsp;on the primary node this is configured as: 1000M / full&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;comments&lt;BR /&gt;ipv4-address **********&lt;BR /&gt;ipv6-address Not Configured&lt;BR /&gt;ipv6-local-link-address Not Configured&lt;/P&gt;&lt;P&gt;Statistics:&lt;BR /&gt;TX bytes:6250676504 packets:56472844 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;RX bytes:10604148265 packets:120388569 errors:0 dropped:0 overruns:0 frame:0&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# ethtool eth1&lt;BR /&gt;Settings for eth1:&lt;BR /&gt;Supported ports: [ TP ]&lt;BR /&gt;Supported link modes: 10baseT/Half 10baseT/Full&lt;BR /&gt;100baseT/Half 100baseT/Full&lt;BR /&gt;1000baseT/Full&lt;BR /&gt;Supports auto-negotiation: Yes&lt;BR /&gt;Advertised link modes: 10baseT/Half 10baseT/Full&lt;BR /&gt;100baseT/Half 100baseT/Full&lt;BR /&gt;1000baseT/Full&lt;BR /&gt;Advertised auto-negotiation: Yes&lt;BR /&gt;Speed: 100Mb/s&lt;BR /&gt;Duplex: Full&lt;BR /&gt;Port: Twisted Pair&lt;BR /&gt;PHYAD: 1&lt;BR /&gt;Transceiver: internal&lt;BR /&gt;Auto-negotiation: on&lt;BR /&gt;Supports Wake-on: pumbg&lt;BR /&gt;Wake-on: d&lt;BR /&gt;Current message level: 0x00000007 (7)&lt;BR /&gt;Link detected: yes&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# ethtool -k eth1&lt;BR /&gt;Offload parameters for eth1:&lt;BR /&gt;Cannot get device udp large send offload settings: Operation not supported&lt;BR /&gt;Cannot get device GRO settings: Operation not supported&lt;BR /&gt;rx-checksumming: on&lt;BR /&gt;tx-checksumming: off&lt;BR /&gt;scatter-gather: off&lt;BR /&gt;tcp segmentation offload: off&lt;BR /&gt;udp fragmentation offload: off&lt;BR /&gt;generic segmentation offload: off&lt;BR /&gt;generic-receive-offload: off&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance for the support&lt;/P&gt;</description>
    <pubDate>Fri, 06 Aug 2021 10:20:20 GMT</pubDate>
    <dc:creator>fabiofabio</dc:creator>
    <dc:date>2021-08-06T10:20:20Z</dc:date>
    <item>
      <title>cphaprob -a if show DOWN - Interface Active Check  Current state: problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cphaprob-a-if-show-DOWN-Interface-Active-Check-Current-state/m-p/125863#M18267</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;since yesterday I have a problem on the secondary gateway, every now and then it happens that it disconnects but then comes back up without problems (never understood why), this time it remained down. I have already followed these sks, (I also put an external link, forgive me if it is not allowed, notify me and I will remove it immediately)&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121337" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121337&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114804" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114804&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.fir3net.com/Firewalls/Checkpoint/clusterxl-shows-active-attention-interface-active-check.html" target="_blank"&gt;https://www.fir3net.com/Firewalls/Checkpoint/clusterxl-shows-active-attention-interface-active-check.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;none of these solved my problem. I leave below a couple of command outputs, the problematic interface is &lt;STRONG&gt;eth1&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;(the eth1 interface is the one that reaches the outside, from which the whole network passes, one of the guides above explains to add the interface to the file $ FWDIR / conf / discntd.if but from what I understand, this file the does it exclude, so I would solve the error but not the malfunction problem, did I understand correctly? other thing, I did not do a cpstop / cpstart of both nodes, only the secondary one with problems, I did the push policy without errors and then I restarted the services but nothing. could i try with a reboot of the machine?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Primary Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 xxx.xxx.xxx.xxx 100% Active&lt;BR /&gt;2 (local) xxx.xxx.xxx.xxx 0% Down&lt;/P&gt;&lt;P&gt;Local member is in current state since Thu Aug 5 12:54:48 2021&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# cphaprob -l list&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem&lt;/P&gt;&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Synchronization&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11896.8 sec&lt;/P&gt;&lt;P&gt;Device Name: Filter&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11896.8 sec&lt;/P&gt;&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11948.7 sec&lt;/P&gt;&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11949.9 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 11949 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: cvpnd&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 0.2 sec&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# cphaprob -a if&lt;/P&gt;&lt;P&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 2&lt;/P&gt;&lt;P&gt;eth0 Disconnected non sync(non secured), multicast&lt;BR /&gt;eth1 DOWN (12060 secs) non sync(non secured), multicast&lt;BR /&gt;eth3 UP non sync(non secured), multicast&lt;BR /&gt;eth4 UP sync(secured), multicast&lt;BR /&gt;eth5 UP sync(secured), multicast&lt;BR /&gt;eth2 UP non sync(non secured), multicast&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# clish -c "show interface eth1"&lt;BR /&gt;state on&lt;BR /&gt;mac-addr *********&lt;BR /&gt;type ethernet&lt;BR /&gt;link-state link up&lt;BR /&gt;mtu 1500&lt;BR /&gt;auto-negotiation on&lt;BR /&gt;speed 100M&lt;BR /&gt;ipv6-autoconfig Not configured&lt;BR /&gt;duplex full&lt;BR /&gt;monitor-mode off&lt;BR /&gt;link-speed Not configured&amp;nbsp; &amp;nbsp;&lt;FONT color="#FF0000"&gt; &lt;U&gt;&lt;STRONG&gt;&amp;lt;----&amp;nbsp;on the primary node this is configured as: 1000M / full&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;comments&lt;BR /&gt;ipv4-address **********&lt;BR /&gt;ipv6-address Not Configured&lt;BR /&gt;ipv6-local-link-address Not Configured&lt;/P&gt;&lt;P&gt;Statistics:&lt;BR /&gt;TX bytes:6250676504 packets:56472844 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;RX bytes:10604148265 packets:120388569 errors:0 dropped:0 overruns:0 frame:0&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# ethtool eth1&lt;BR /&gt;Settings for eth1:&lt;BR /&gt;Supported ports: [ TP ]&lt;BR /&gt;Supported link modes: 10baseT/Half 10baseT/Full&lt;BR /&gt;100baseT/Half 100baseT/Full&lt;BR /&gt;1000baseT/Full&lt;BR /&gt;Supports auto-negotiation: Yes&lt;BR /&gt;Advertised link modes: 10baseT/Half 10baseT/Full&lt;BR /&gt;100baseT/Half 100baseT/Full&lt;BR /&gt;1000baseT/Full&lt;BR /&gt;Advertised auto-negotiation: Yes&lt;BR /&gt;Speed: 100Mb/s&lt;BR /&gt;Duplex: Full&lt;BR /&gt;Port: Twisted Pair&lt;BR /&gt;PHYAD: 1&lt;BR /&gt;Transceiver: internal&lt;BR /&gt;Auto-negotiation: on&lt;BR /&gt;Supports Wake-on: pumbg&lt;BR /&gt;Wake-on: d&lt;BR /&gt;Current message level: 0x00000007 (7)&lt;BR /&gt;Link detected: yes&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;[Expert@module2:0]# ethtool -k eth1&lt;BR /&gt;Offload parameters for eth1:&lt;BR /&gt;Cannot get device udp large send offload settings: Operation not supported&lt;BR /&gt;Cannot get device GRO settings: Operation not supported&lt;BR /&gt;rx-checksumming: on&lt;BR /&gt;tx-checksumming: off&lt;BR /&gt;scatter-gather: off&lt;BR /&gt;tcp segmentation offload: off&lt;BR /&gt;udp fragmentation offload: off&lt;BR /&gt;generic segmentation offload: off&lt;BR /&gt;generic-receive-offload: off&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance for the support&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 10:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cphaprob-a-if-show-DOWN-Interface-Active-Check-Current-state/m-p/125863#M18267</guid>
      <dc:creator>fabiofabio</dc:creator>
      <dc:date>2021-08-06T10:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: cphaprob -a if show DOWN - Interface Active Check  Current state: problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cphaprob-a-if-show-DOWN-Interface-Active-Check-Current-state/m-p/125970#M18287</link>
      <description>&lt;P&gt;What version/JHF level is this?&lt;BR /&gt;Also what specific appliance?&lt;/P&gt;
&lt;P&gt;Is there a specific reason you are using two non-bonded interfaces for sync?&lt;BR /&gt;This has not been the best practice for some time.&lt;/P&gt;
&lt;P&gt;Also the speed on eth1 on the secondary node shows as 100mb...is that correct?&lt;BR /&gt;What precisely is eth1 connected to on both appliances?&lt;BR /&gt;The mismatch in interfaces suggests a configuration/cabling issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 01:12:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cphaprob-a-if-show-DOWN-Interface-Active-Check-Current-state/m-p/125970#M18287</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-09T01:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: cphaprob -a if show DOWN - Interface Active Check  Current state: problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cphaprob-a-if-show-DOWN-Interface-Active-Check-Current-state/m-p/125998#M18294</link>
      <description>&lt;P&gt;you're right, it was a wiring mistake. it always worked but this time it got stuck, after several attempts, it was enough to unplug and reattach the cable from the switch and poof, it's back to work. thanks anyway for the support&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 06:30:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cphaprob-a-if-show-DOWN-Interface-Active-Check-Current-state/m-p/125998#M18294</guid>
      <dc:creator>fabiofabio</dc:creator>
      <dc:date>2021-08-09T06:30:49Z</dc:date>
    </item>
  </channel>
</rss>

