<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster dead timeout SK93454 - 3 or 30? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134745#M20239</link>
    <description>&lt;P&gt;Answering the original question,&lt;BR /&gt;&lt;BR /&gt;The mentioned SK is describing the recommended change, and not the default settings for the mentioned parameter. The way I read it, it should say two things: default parameter (which is 3 HTUs) and recommended one (which is 30).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;By default, CCP sends 3 hello per second, and losing one causes cluster to check connectivity and go into failover. 3 seconds equal to 9 to 10 CCP frames lost, and may affect production traffic by delaying it on the failed previously active cluster member.&lt;BR /&gt;&lt;BR /&gt;That said, I am checking with SK owners what they tried to say &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Nov 2021 15:35:27 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-11-23T15:35:27Z</dc:date>
    <item>
      <title>Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134714#M20228</link>
      <description>&lt;P&gt;Hi! Just wondered if you could check your gateways and see the value of this kernel parameter from&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93454&amp;amp;partition=Advanced&amp;amp;product=ClusterXL" target="_self"&gt;sk93454&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2" color="#3366FF"&gt;fw ctl get int fwha_dead_timeout_multiplier&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2" color="#3366FF"&gt;fwha_dead_timeout_multiplier = 3&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;The reason I'm asking is that SK article says it should be &lt;U&gt;&lt;STRONG&gt;30&lt;/STRONG&gt; &lt;/U&gt;whereas we see &lt;U&gt;&lt;STRONG&gt;3&lt;/STRONG&gt;&lt;/U&gt; and we have seen very strange cluster failovers - for example rebooting standby cluster member resulted in full failover as active cluster member was reporting lost CCP packets. I start to suspect that this kernel parameter is set too low (by mistake /typo) so instead of having 3sec cluster dead timeout we actually have 300ms!&lt;/P&gt;
&lt;P&gt;We are running R80.40 T120&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 10:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134714#M20228</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-23T10:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134728#M20230</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;checked on different systems all shows "3"&lt;/P&gt;
&lt;P&gt;R80.10, R80.40, R81, R81.10 and VSX R80.10, R80.40&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 11:55:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134728#M20230</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-11-23T11:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134738#M20234</link>
      <description>&lt;P&gt;Im so glad you actually brought this up...as soon as I read it, I recall once working with customer on R80.20 cluster and escalation guy in TAC said to change this value to 30 and when we pressed him why, as we saw value 3 on different versions, he really could not explain it, said would open R&amp;amp;D task and absolutely nothing came out of it. I mean, I like to think of myself as pretty open minded person and willing to try things when stuff is broken, but definitely not someone who wants to blindly change things without any logical reasoning. Maybe someone from CP can chime in and give us a reason.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 14:32:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134738#M20234</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-23T14:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134740#M20236</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;- do you think you could ask internally pls? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 15:04:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134740#M20236</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-23T15:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134741#M20237</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;What is the actual question you want me to ask?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 15:11:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134741#M20237</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-23T15:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134745#M20239</link>
      <description>&lt;P&gt;Answering the original question,&lt;BR /&gt;&lt;BR /&gt;The mentioned SK is describing the recommended change, and not the default settings for the mentioned parameter. The way I read it, it should say two things: default parameter (which is 3 HTUs) and recommended one (which is 30).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;By default, CCP sends 3 hello per second, and losing one causes cluster to check connectivity and go into failover. 3 seconds equal to 9 to 10 CCP frames lost, and may affect production traffic by delaying it on the failed previously active cluster member.&lt;BR /&gt;&lt;BR /&gt;That said, I am checking with SK owners what they tried to say &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 15:35:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134745#M20239</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-23T15:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134749#M20240</link>
      <description>&lt;P&gt;# fw ctl get int fwha_dead_timeout_multiplier&lt;BR /&gt;fwha_dead_timeout_multiplier = 3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Running JHFA 125 on the device I ran the command on.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 16:50:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134749#M20240</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-11-23T16:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134781#M20244</link>
      <description>&lt;P&gt;Thanks Val!&lt;/P&gt;
&lt;P&gt;Are we looking at the same SK? I see it very clearly stated as 3secs by default&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 316px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14361iA17C2B85E450705C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's set to 3 (=300ms) and CCP hello interval is 333ms (1/3s) then there's a high probability that Hello will get missed. To allow one CCP Hello to be missed the timer should be just under (2 x 1/3s) or 599ms.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's if I understood the logic correctly. Or there are some other CCP timers. And this is where it gets tricky as there are bunch of very old articles and many kernel adjustable timers do not exist in R80.40. So it would be nice to have an updated SK regarding CCP timer functionality &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 06:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134781#M20244</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-24T06:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134793#M20247</link>
      <description>&lt;P&gt;Yes we do, hence I said, it is badly worded at the beginning, and I am already taking it with the owners. It should say, AFAIK, "&lt;EM&gt;Cluster dead interval is 0.3 second, by default&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Now, see the rest of my explanation, all clicks into place &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 08:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134793#M20247</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-24T08:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134795#M20248</link>
      <description>&lt;P&gt;Great! Thanks Val!&lt;/P&gt;
&lt;P&gt;But then it begs the same question: if timeout is 300ms and interval between CCP hello is 333ms - then timeout is too short as it can start counting exactly after one Hello is sent and will expire before next Hello arrives&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 08:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134795#M20248</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-24T08:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134796#M20249</link>
      <description>&lt;P&gt;No, it is .3 seconds of additional wait for the missing packet.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 08:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/134796#M20249</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-24T08:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster dead timeout SK93454 - 3 or 30?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/179009#M32802</link>
      <description>&lt;P&gt;I know this is an old thread, but this may be helpful for future readers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The SK says the recommended value is 30 &lt;U&gt;&lt;STRONG&gt;"HTU"&lt;/STRONG&gt;&lt;/U&gt;, while the value we configure for&amp;nbsp;&lt;STRONG&gt;&lt;CODE&gt;fwha_dead_timeout_multiplier&lt;/CODE&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;is just a multiplier (not HTUs).&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How this parameter works is it uses the value we configure (3 or any other value) and multiplies it by 10 HTUs (each HTU is 100ms). So the timeout in this case becomes 3 x 10 (HTUs) = 3 seconds. This is the default AND recommended value. You can also find more information about this parameter in&amp;nbsp;sk92723.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both lines written in the SK are correct:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Cluster dead interval is 3 &lt;U&gt;&lt;STRONG&gt;seconds&lt;/STRONG&gt;&lt;/U&gt;, by default.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Recommended value&amp;nbsp;for both&amp;nbsp;kernel parameters is&amp;nbsp;30 (&lt;U&gt;&lt;STRONG&gt;HTU&lt;/STRONG&gt;&lt;/U&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That is just to understand the inner logic about what is written in the SK. Bottom line is that whatever value we configure for this parameter will end up being the number of '&lt;U&gt;&lt;STRONG&gt;seconds&lt;/STRONG&gt;&lt;/U&gt;' for this timeout (because of how this value is anyway multiplied by 10 HTUs in the background).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hope this helps and makes sense.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 05:04:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-dead-timeout-SK93454-3-or-30/m-p/179009#M32802</guid>
      <dc:creator>Pablo_Munoz</dc:creator>
      <dc:date>2023-04-25T05:04:24Z</dc:date>
    </item>
  </channel>
</rss>

