<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sync interface on 80.30 never comes up in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153820#M25888</link>
    <description>&lt;P&gt;Thank you. When browsing the SKs and forum, I didn't stumble upon this. I verified and most of the 3 settings were rejected. I have reconfigured the sync interface with a port group that has these settings enabled. Immediately, the interfaces came up, the cluster formed and I have a working active/standby setup on 80.30. I was hoping it was not CP related.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;That was fast! Thank you! Saves me at least some hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2022 08:07:18 GMT</pubDate>
    <dc:creator>woee</dc:creator>
    <dc:date>2022-07-26T08:07:18Z</dc:date>
    <item>
      <title>Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153814#M25884</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have set up a HA cluster (2 gw + 1 mgmt) running 81.10 and everything is working fine. This is running on an ESXi server. When I set up the same cluster but in version 80.30, the sync interface never comes up. The HA cluster actually runs in split brain, as they cannot communicate since the sync interface never comes up. I&amp;nbsp;have tested different configuration settings, but the ClusterXL is always failing to be established.&lt;/P&gt;&lt;P&gt;- I have a /30 subnet on the sync interface, making it a unique sync network (and it is the lowest vlan).&lt;BR /&gt;- On Gaia all interfaces are up, I can ping between them just fine to any interface, also the sync interface.&lt;BR /&gt;&lt;SPAN&gt;- Access policy contains just 1 rule to allow anything.&lt;BR /&gt;- I have the all-in-one evaluation license on all servers.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- In the logs I cannot see anything but the fact that the sync interface is down on both sides.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Via cpconfig I removed each member (option 6) and joined again after reboot.&lt;BR /&gt;- I recreated the sic trust, changed every possible setting for anti-spoofing.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- I removed the cluster object and recreated it again, no effect.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- I used vmxnet3 and E1000 interfaces on the virtual machines.&lt;BR /&gt;- I used different subnets and IP addresses, but same result.&lt;BR /&gt;- Changed CCP mode to broadcast, unicast, auto, all same result (now it is again auto/unicast).&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- ClusterXL is installed on the gateways.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- I used the wizard to create the cluster.&lt;BR /&gt;- I reinstalled the servers to be sure but the same result is noticed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The only way to get the interfaces in an UP state, is when I set the first mgmt interface to cluster+sync. When I do this the interfaces come up (sometimes), but there is still no traffic between them to establish a proper HA cluster.&lt;/P&gt;&lt;P&gt;I am new to Checkpoint and cannot find any other info to troubleshoot further. I've taken a look at the log files, but cannot find a log file about the sync interface and the HA mechanism (not in fwd.elg or messages or any other file). Is there a log file where you can see the servers trying to establish the cluster or why the sync interfaces don't come up for HA? These interfaces are up and working, they just don't do HA.&lt;/P&gt;&lt;P&gt;Is there something obvious I am missing on the 80.30 that is different from the 81.10?&lt;/P&gt;&lt;P&gt;Thank you!&lt;BR /&gt;Wouter&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 07:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153814#M25884</guid>
      <dc:creator>woee</dc:creator>
      <dc:date>2022-07-26T07:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153815#M25885</link>
      <description>&lt;P&gt;Double check that your clusterID on R80.30 is set to the same number on both cluster members.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 07:18:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153815#M25885</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-26T07:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153816#M25886</link>
      <description>&lt;P&gt;R80.40 and above is less strict on the requirements...&lt;/P&gt;
&lt;P&gt;Do you have all the following in place:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101214" target="_self"&gt;sk101214&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 07:48:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153816#M25886</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-26T07:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153819#M25887</link>
      <description>&lt;P&gt;Thanks, great pointing out the clusterid, makes sense if there is a mismatch 2 different clusters will be formed. I don't know how to get this id. Do you know an easy way to verify this on 80.30?&lt;/P&gt;&lt;P&gt;[Expert@FW1:0]# cphaconf cluster_id get&lt;BR /&gt;cphaconf cluster_id set\get is not supported in this version.&lt;BR /&gt;For more details, please refer to sk25977.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153819#M25887</guid>
      <dc:creator>woee</dc:creator>
      <dc:date>2022-07-26T08:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153820#M25888</link>
      <description>&lt;P&gt;Thank you. When browsing the SKs and forum, I didn't stumble upon this. I verified and most of the 3 settings were rejected. I have reconfigured the sync interface with a port group that has these settings enabled. Immediately, the interfaces came up, the cluster formed and I have a working active/standby setup on 80.30. I was hoping it was not CP related.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;That was fast! Thank you! Saves me at least some hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153820#M25888</guid>
      <dc:creator>woee</dc:creator>
      <dc:date>2022-07-26T08:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153824#M25889</link>
      <description>&lt;P&gt;from clish:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE class="monospace"&gt;show cluster mmagic&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:29:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153824#M25889</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-26T08:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153825#M25890</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/78320"&gt;@woee&lt;/a&gt;&amp;nbsp;great to hear. you can ignore ClusterID then &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153825#M25890</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-26T08:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153826#M25891</link>
      <description>&lt;P&gt;So what is the clusterID in there?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;FW1&amp;gt; show cluster mmagic&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Configuration mode: Automatic&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Configuration phase: Stable&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;MAC magic: 1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;MAC forward magic: 254&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Used MAC magic values: None.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153826#M25891</guid>
      <dc:creator>woee</dc:creator>
      <dc:date>2022-07-26T08:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface on 80.30 never comes up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153827#M25892</link>
      <description>&lt;P&gt;Yes, but now I need to know. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:33:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-interface-on-80-30-never-comes-up/m-p/153827#M25892</guid>
      <dc:creator>woee</dc:creator>
      <dc:date>2022-07-26T08:33:28Z</dc:date>
    </item>
  </channel>
</rss>

