<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Sync Address flapping in a cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35801#M2906</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are multiple steps in the SK.&lt;/P&gt;&lt;P&gt;Which ones did you try and what results did you find?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Jul 2018 01:00:21 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-07-04T01:00:21Z</dc:date>
    <item>
      <title>HA Sync Address flapping in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35800#M2905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are facing a strange issue in one of our cluster. After adding a new interface in the cluster, the unique address of the other member showed in cphaprob state is flapping. the address is constantly changing if I'm watching cphaprob state between all the interfaces addresses (sync address too).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the cluster is working fine. (no failover)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On member 1 I have this type :&lt;/P&gt;&lt;P&gt;1 (local)&amp;nbsp; 'SYNC ADDRESS' &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;100%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active&lt;BR /&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'OTHER INTERFACE ADDRESS' &amp;nbsp;&amp;nbsp;&amp;nbsp; 0%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And on member 2 :&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'OTHER INTERFACE ADDRESS' &amp;nbsp; 100%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active&lt;BR /&gt;2 (local)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;'SYNC ADDRESS' &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The cphaprob -a if is good (all interfaces UP), I'm in Broadcast CCP due to TP switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;netstat -in shows no error at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The strange thing is that if I remove the new interface from topology, the cluster is back to normal. I already contacted Checkpoint regarding this issue and they gave me the sk43984 but it's not helping me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2018 16:20:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35800#M2905</guid>
      <dc:creator>Romaric_DUCLOUX</dc:creator>
      <dc:date>2018-07-02T16:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: HA Sync Address flapping in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35801#M2906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are multiple steps in the SK.&lt;/P&gt;&lt;P&gt;Which ones did you try and what results did you find?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 01:00:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35801#M2906</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-04T01:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: HA Sync Address flapping in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35802#M2907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please make sure sync network is completely isolated from the production networks. It seems you are receiving a "wrong" CCP frame on sync interface from time to time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;&amp;nbsp;the issue so far is cosmetic, so the regular ClusterXL troubleshooting might not&amp;nbsp;yield a result here, unless there is a fail-over situation.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would advise an extensive ClusterXL debug, but that is for a Support Engineer on the case to decide&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 09:39:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35802#M2907</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-07-04T09:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: HA Sync Address flapping in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35803#M2908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Valeri and Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all, thanks for your time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Daemon, on the SK I did the folllowing :&lt;/P&gt;&lt;P&gt;Step 1 : 0% loss and less than 1ms latency&lt;/P&gt;&lt;P&gt;Step 2 : already did&lt;/P&gt;&lt;P&gt;Step 3 : Two Pingable hosts&lt;/P&gt;&lt;P&gt;Step 4&amp;nbsp; : In R77.30, it's already configured&lt;/P&gt;&lt;P&gt;Step 5 : Same as step 4&lt;/P&gt;&lt;P&gt;Step 6 is not relevant for me&lt;/P&gt;&lt;P&gt;Step 7 : CPU is stable&lt;/P&gt;&lt;P&gt;Step 8 : I prefer to do this in mainteance window,&lt;/P&gt;&lt;P&gt;Step 9 : same as step 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Valeri,&lt;/P&gt;&lt;P&gt;Unfortunately, I don't have the hand on the network equipement on site, but they assure that all the interfaces are isolated properly.&lt;/P&gt;&lt;P&gt;I'm in discussion with a Checkpoint Engineer actually, I'm trying to negotiate a maintenance window with the TP, he wants to debug by himself on the gateways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 12:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35803#M2908</guid>
      <dc:creator>Romaric_DUCLOUX</dc:creator>
      <dc:date>2018-07-04T12:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: HA Sync Address flapping in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35804#M2909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We finally solved the issue today.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue was quite simple in fact. As the checkpoint is on a TP site, we do not have the hand on the switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They finally found that the new interface recently added to the topology were in the same VLAN as the sync interface. So the broadcast domains were the same which causes all the troubles in the display and some failover too !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help guys.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2018 15:36:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35804#M2909</guid>
      <dc:creator>Romaric_DUCLOUX</dc:creator>
      <dc:date>2018-07-26T15:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: HA Sync Address flapping in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35805#M2910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That will definitely do it.&lt;/P&gt;&lt;P&gt;Thanks for updating us.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2018 18:57:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Sync-Address-flapping-in-a-cluster/m-p/35805#M2910</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-26T18:57:04Z</dc:date>
    </item>
  </channel>
</rss>

