<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134271#M20105</link>
    <description>&lt;P&gt;I agree with this statement. Still, two weeks in and not much has progressed.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Nov 2021 14:37:42 GMT</pubDate>
    <dc:creator>Vincent_Croes</dc:creator>
    <dc:date>2021-11-17T14:37:42Z</dc:date>
    <item>
      <title>After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/133904#M19983</link>
      <description>&lt;P&gt;Hi CheckMates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if anyone had the a similar experience as we have. We are upgrading two 23500 appliances running in VSX mode on R80.10.&lt;/P&gt;&lt;P&gt;We succeeded to upgrade both appliances to R80.30 using an in-place upgrade via CPUSE. Everything seems fine however, if we reboot one member (doesn't matter which one) we observe states like DOWN-READY for multiple VSes and this obviously causes impact.&lt;/P&gt;&lt;P&gt;The duration of this state varies but can go from 10 seconds to 30 seconds. In the end, everything recovers and the cluster becomes fully operational.&lt;/P&gt;&lt;P&gt;We have tried the following (and more)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A full R80.30 install + reconfigure results in the same issue&lt;/LI&gt;&lt;LI&gt;Limiting the kernel parameters to the bare minimum&lt;/LI&gt;&lt;LI&gt;Playing with the CCP clustering method (uni, broad and multicast)&lt;/LI&gt;&lt;LI&gt;Changing L2 equipment (both units are connected to a different single switch)&lt;/LI&gt;&lt;LI&gt;Connecting the Sync interface link-local to the other node&lt;/LI&gt;&lt;LI&gt;Checking the CPU / memory load&lt;/LI&gt;&lt;LI&gt;Checking for issues on the NIC's / cables&lt;/LI&gt;&lt;LI&gt;Installing the latest JHF&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note that cpstop; cpstart does&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; result in the same issue. This results in a proper failover and failback! The only solution (during reboot) so far are these two parameters below. No idea why they are needed in our R80.30 configuration.&lt;/P&gt;&lt;P&gt;fwha_dead_timeout_multiplier=12&lt;BR /&gt;fwha_timer_cpha_res=12&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any advice or experience?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 09:29:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/133904#M19983</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-12T09:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/133917#M19985</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can you please confirm some items:&lt;/P&gt;
&lt;P&gt;- what is the portfast mode of all connected switch ports (edge)?&lt;/P&gt;
&lt;P&gt;- is the sync port configured as a bond?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 12:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/133917#M19985</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-11-12T12:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/133928#M19988</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;- 'spanning-tree port type edge trunk'&lt;/P&gt;&lt;P&gt;- No, it uses the native 'Sync' interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note that reverting back to R80.10, the issue is resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 13:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/133928#M19988</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-12T13:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134075#M20036</link>
      <description>&lt;P&gt;Bump. Anyone?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 13:20:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134075#M20036</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-15T13:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134085#M20039</link>
      <description>&lt;P&gt;Just to confirm:&lt;/P&gt;
&lt;P&gt;- you have done full fresh install + vsx_util_reconfigure on both nodes?&lt;/P&gt;
&lt;P&gt;- this does not affect active box - only rebooted node shows various VS states?&lt;/P&gt;
&lt;P&gt;- what does cphaprob stat and cphaprob -a if say on particular VSes, what problem they report?&lt;/P&gt;
&lt;P&gt;- you are not observing packet loss between boxes on sync traffic?&lt;/P&gt;
&lt;P&gt;- do you use virtual switches or routers?&lt;/P&gt;
&lt;P&gt;As far as I remember we never saw anything like that going R80.10 - R80.30. But it's been a while, we have been on R80.40 for quite a while now.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 15:06:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134085#M20039</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-15T15:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134115#M20052</link>
      <description>&lt;P&gt;What other changes were made if any during/post upgrade? e.g.&lt;/P&gt;
&lt;P&gt;- CoreXL&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- HT / SMT&lt;/P&gt;
&lt;P&gt;- Dynamic Dispatcher&lt;/P&gt;
&lt;P&gt;- Multi-queue&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 00:28:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134115#M20052</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-11-16T00:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134121#M20056</link>
      <description>&lt;P&gt;- You have done full fresh install + vsx_util_reconfigure on both nodes?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- This does not affect active box - only rebooted node shows various VS states?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- The state on the active box goes into a DOWN state and the rebooted member always goes into READY&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- What does cphaprob stat and cphaprob -a if say on particular VSes, what problem they report?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- 'cphaprob' reflects the actual status, so on the active node, it reports DOWN during the reboot of other node and the reason for that is IAC. It reports that multiple interfaces are down. The gest of it is, Inbound is UP but outbound is DOWN.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- You are not observing packet loss between boxes on sync traffic?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- We are not observing packet loss between anything.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Do you use virtual switches or routers?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- Yes we use virtual switches&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 07:07:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134121#M20056</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-16T07:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134122#M20057</link>
      <description>&lt;P&gt;- CoreXL&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- Has been modified: moved a non MQ interface (MGMT) to a different core&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- HT / SMT&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- Hasn't been modified.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Dynamic Dispatcher&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- In R80.10 VSX, we didn't have DP. In R80.30, this is defaultly activated. So coming from R80.10 to R80.30, this now active.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Multi-queue&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-- Hasn't been modified.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 07:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134122#M20057</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-16T07:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134125#M20059</link>
      <description>&lt;P&gt;Please open a TAC case for this.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 07:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134125#M20059</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-16T07:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134133#M20063</link>
      <description>&lt;P&gt;I would comb through fwk.elg files (both VS0 and other VSes) as they have full history of clustering state changes and possible causes. TAC case as suggested by Val sounds reasonable if you are stuck &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 09:02:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134133#M20063</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-16T09:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134138#M20065</link>
      <description>&lt;P&gt;TAC case was already logged but little to no progress was made as to the rootcause of this problem. Just wanted to hear if anyone on CheckMates had any similar experiences.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 10:05:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134138#M20065</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-16T10:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134214#M20087</link>
      <description>&lt;P&gt;did you read this SK?&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43872&amp;amp;partition=Advanced&amp;amp;product=ClusterXL" target="_self"&gt;sk43872&lt;/A&gt;&amp;nbsp;quite a bit of info regarding kernel parameters you changed&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 07:13:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134214#M20087</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-17T07:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134258#M20100</link>
      <description>&lt;P&gt;The SK doesn't explain why we needed those parameters in R80.30, whilst the cluster just worked fine on version R80.10. If there is a valid technical reason as to why these are needed, we are happy to hear it.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 13:28:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134258#M20100</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-17T13:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134269#M20104</link>
      <description>&lt;P&gt;ClusterXL (and also SecureXL &amp;amp; CoreXL) have been changed drastically between these two versions, which could be a "valid technical reason" that clustering parameters would be changed between the versions.&lt;BR /&gt;&lt;BR /&gt;However, a remaining cluster member should not go from Active to Down during reboot of the second member. I would ask TAC to concentrate on this&amp;nbsp; symptom.&lt;/P&gt;
&lt;P&gt;The second cluster member coming up as Ready is normal, in my view. It cannot be anything else before full sync is completed, and there is no Active member to request it from. Crack why the other guys is Down, and you solve the problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 14:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134269#M20104</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-17T14:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134271#M20105</link>
      <description>&lt;P&gt;I agree with this statement. Still, two weeks in and not much has progressed.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 14:37:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134271#M20105</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-17T14:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134329#M20120</link>
      <description>&lt;P&gt;Not to ruffle feathers Val, but I never seen in normal circumstances cluster member entering READY state apart from upgrade when members are running different versions (HW and/or SW). As far as I have seen it it does DOWN &amp;gt; INIT &amp;gt; STANDBY (or ACTIVE if it's a higher priority member with corresponding cluster setting)&lt;/P&gt;
&lt;P&gt;There is a fairly set list of cases that will trigger READY state on VSX: (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42096&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_self"&gt;sk42096&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;&lt;EM&gt;There are cluster members with a lower software version on this subnet / VLAN&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;[member with higher software version will go into state 'Ready'].&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;&lt;EM&gt;The number of CoreXL FireWall instances on cluster members is different&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;[member with greater number of CoreXL FW instances will go into state 'Ready'].&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Note: This applies only to R80.10 and lower versions.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;&lt;EM&gt;The ID numbers of CoreXL FireWall instances and handling CPU core numbers on cluster members are different.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;&lt;EM&gt;On Gaia OS - Linux kernels on cluster members are different (32-bit vs 64-bit)&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;[member with higher kernel edition will go into state 'Ready'].&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;&lt;EM&gt;On Gaia OS - Cluster member runs in VSX mode, while other members run in Gateway mode&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;[member in VSX mode will go into state 'Ready'].&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Also checked fwk.elg history on my VSX and did not see a single READY state there apart from upgrade &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;grep CLUS $FWDIR/log/fwk.elg* | grep "State change"|grep READY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[3 Jul 17:09:11][fw4_0];[vs_0];CLUS-115303-1: State change: DOWN -&amp;gt; READY | Reason: Member with older software release has been detected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[3 Jul 17:15:54][fw4_0];[vs_0];CLUS-115303-1: State change: INIT -&amp;gt; READY | Reason: Member with older software release has been detected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[3 Jul 17:36:37][fw4_0];[vs_0];CLUS-115303-1: State change: INIT -&amp;gt; READY | Reason: Member with older software release has been detected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[3 Jul 17:55:28][fw4_0];[vs_0];CLUS-112100-1: State change: READY -&amp;gt; DOWN | Reason: FULLSYNC PNOTE&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2903"&gt;@Vincent_Croes&lt;/a&gt;&amp;nbsp;- I hope you have verified CoreXL allocations on both members and they are identical and also looked at fwk.elg logs, they might give a hint for member entering READY state?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 06:49:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134329#M20120</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-18T06:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134330#M20121</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2903"&gt;@Vincent_Croes&lt;/a&gt;&amp;nbsp;if you needed the command &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; this will show any VS1-9, not VS0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;grep CLUS /var/log/opt/CPsuite-R80.30/fw1/CTX/CTX0000?/fwk.elg*|grep "State change"&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 07:27:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134330#M20121</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-18T07:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134333#M20122</link>
      <description>&lt;P&gt;I haven't seen the READY state except for upgrade scenario's.&lt;/P&gt;&lt;P&gt;None of the fwk.elg files mention the READY state and as for the DOWN state, it mentions interfaces being down (same output as cphaprob -a if) because his buddy is being rebooted. However IMO that is not a reason to go DOWN, that is a reason to go ACTIVE ATTENTION.&lt;/P&gt;&lt;P&gt;It kinda looks like when he is not able to receive CCP packets from his buddy, he switches to the DOWN state for his VS'es.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 08:03:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134333#M20122</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-18T08:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134335#M20123</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 08:04:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134335#M20123</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-11-18T08:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade from R80.10 to R80.30 - Virtual Systems go into DOWN-READY state if one members re</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134340#M20125</link>
      <description>&lt;P&gt;We are both correct.&lt;BR /&gt;&lt;BR /&gt;Ready means cluster cannot initialise delta sync. The reasons are: different versions, unmatched CoreXL, and as I mentioned, full sync is not yet done.&lt;BR /&gt;&lt;BR /&gt;You actually can see it in your own log, the last line:&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;[3 Jul 17:55:28][fw4_0];[vs_0];CLUS-112100-1: State change: READY -&amp;gt; DOWN | Reason: FULLSYNC PNOTE&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;In a fully operational cluster that READY state is too short to notice. READY -&amp;gt; full sync request -&amp;gt; DOWN -&amp;gt; sync complete -&amp;gt; STANDBY, this is how the normal cycle looks. But if there is no ACTIVE member, the booting cluster member remains READY, as there is nowhere to send full sync request.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 08:15:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-upgrade-from-R80-10-to-R80-30-Virtual-Systems-go-into-DOWN/m-p/134340#M20125</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-18T08:15:48Z</dc:date>
    </item>
  </channel>
</rss>

