<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: local probing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154815#M26461</link>
    <description>&lt;P&gt;Did you look into&amp;nbsp;&lt;SPAN&gt;sk93454 yet?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Aug 2022 07:08:08 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-08-10T07:08:08Z</dc:date>
    <item>
      <title>local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154801#M26457</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;after upgrading to r81.10, all our clusters are showing:&lt;/P&gt;
&lt;P&gt;Local Probing PNOTE ON&lt;/P&gt;
&lt;P&gt;then within the same second we get:&lt;/P&gt;
&lt;P&gt;Local Probing PNOTE OFF&lt;/P&gt;
&lt;P&gt;its happening across multiple interfaces and all all our r81 clusters (about 12 times per day per cluster). We never had that error on R80.20.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cluster members are split across multiple datacenters, and if my understanding is correct the default timer is 10ms, well doing a ping I can see ping times getting up to 8ms so I suspect that may be the case we are exceeding 10ms at times.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Although we never needed to tweak the value on the old version, I think this could have been resolved by changing&amp;nbsp;fwha_timer_cpha_res from 1 to 2 (meaning a 20ms timeout) however this is no longer chanegable in R81.10. I tried&amp;nbsp;changing&amp;nbsp;fwha_timer_sync_res but it didnt help the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas on what we can change?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 03:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154801#M26457</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2022-08-10T03:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154804#M26458</link>
      <description>&lt;P&gt;Are you able to share some more about the clusters? e.g.&lt;/P&gt;
&lt;P&gt;* Are they physical appliances or VMs&lt;/P&gt;
&lt;P&gt;* Which JHF takes are used/installed&lt;/P&gt;
&lt;P&gt;* Are they all running with Unicast CCP&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 04:51:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154804#M26458</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-10T04:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154805#M26459</link>
      <description>&lt;P&gt;They are all VM's we are running take 45, they al have:&amp;nbsp;CCP mode: Manual (Unicast), vmac is enabled on them all too&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 05:01:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154805#M26459</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2022-08-10T05:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154806#M26460</link>
      <description>&lt;P&gt;Thanks - Vmware/ESX&amp;nbsp; or&amp;nbsp; Hyper-V and with multiple vCPUs assigned to each instance not single?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you provide the output of the following:&lt;/P&gt;
&lt;P&gt;fw ctl get int fwha_dead_timeout_multiplier&lt;BR /&gt;fw ctl get int fwha_if_problem_tolerance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 07:33:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154806#M26460</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-10T07:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154815#M26461</link>
      <description>&lt;P&gt;Did you look into&amp;nbsp;&lt;SPAN&gt;sk93454 yet?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 07:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154815#M26461</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-08-10T07:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154862#M26462</link>
      <description>&lt;P&gt;its vmware, we have at least 2x CPUs in each instance. dynamic dispatcher is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fwha_dead_timeout_multiplier = 3&lt;/P&gt;
&lt;P&gt;fwha_if_problem_tolerance = 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 21:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154862#M26462</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2022-08-10T21:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154863#M26463</link>
      <description>&lt;P&gt;I hadn't found that no, it does look good but I can confirm I don't see "&lt;SPAN&gt;cluster_info" events happening, the cluster routed info history log doesn't&amp;nbsp;show any clusterxl events happening either, I believe we are only losing 1 or 2 of the 3 ccp packets and therefore never actually&amp;nbsp;getting&amp;nbsp;marked as dead, just probing starts, we get a response&amp;nbsp;and its back&amp;nbsp;to normal.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 21:57:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154863#M26463</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2022-08-10T21:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: local probing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154894#M26464</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try follow&amp;nbsp;sk171844.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yair&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 14:50:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/local-probing/m-p/154894#M26464</guid>
      <dc:creator>Yair_Shahar</dc:creator>
      <dc:date>2022-08-11T14:50:42Z</dc:date>
    </item>
  </channel>
</rss>

