<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failure in the implementation of ClusterXL in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185333#M34092</link>
    <description>&lt;P&gt;Appears there is sync issue. If I were you, I would issue cphastop; cphastart on both members and test again.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 15:27:29 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-06-30T15:27:29Z</dc:date>
    <item>
      <title>Failure in the implementation of ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185325#M34089</link>
      <description>&lt;P&gt;Good afternoon everyone,&lt;/P&gt;
&lt;P&gt;I'm facing a problem with the ClusterXL implementation. When completing the implementation, one of the cluster members, in this case, FW_01, is in DOWN status. I'm not sure if this was before or after the access rules were created.&lt;/P&gt;
&lt;P&gt;Has anyone experienced this before?&lt;/P&gt;
&lt;P&gt;Attached is a screenshot of the command output for each of the members.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 21:25:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185325#M34089</guid>
      <dc:creator>Luciano_Cirino</dc:creator>
      <dc:date>2023-06-30T21:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Failure in the implementation of ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185326#M34090</link>
      <description>&lt;P&gt;Please send below from both members.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 15:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185326#M34090</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-30T15:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Failure in the implementation of ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185332#M34091</link>
      <description>&lt;P&gt;Member 1 - FW_01&lt;/P&gt;&lt;P&gt;FW_01&amp;gt; cphaprob roles&lt;/P&gt;&lt;P&gt;ID Role&lt;/P&gt;&lt;P&gt;1 (local) Non-Master&lt;BR /&gt;2 Master&lt;/P&gt;&lt;P&gt;FW_01&amp;gt; cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 172.16.0.1 0% DOWN FW_01&lt;BR /&gt;2 172.16.0.2 100% ACTIVE(!) FW_02&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: LPRB, IAC&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-112000&lt;BR /&gt;State change: INIT -&amp;gt; DOWN&lt;BR /&gt;Reason for state change: USER DEFINED PNOTE&lt;BR /&gt;Event time: Mon Jun 19 15:00:24 2023&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: FULLSYNC PNOTE - cpstop&lt;BR /&gt;Event time: Mon Jun 19 15:00:06 2023&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 1&lt;BR /&gt;Time of counter reset: Wed Jun 14 13:08:01 2023 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW_01&amp;gt; cphaprob -a if&lt;/P&gt;&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;&lt;P&gt;eth1 UP&lt;BR /&gt;Sync (S) UP&lt;BR /&gt;Mgmt (P) DOWN (940275 secs)&lt;/P&gt;&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 2&lt;/P&gt;&lt;P&gt;eth1 10.24.3.254&lt;BR /&gt;Mgmt 192.168.1.3&lt;/P&gt;&lt;P&gt;FW_01&amp;gt; cphaprob list&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 940291 sec&lt;/P&gt;&lt;P&gt;FW_01&amp;gt; cphaprob syncstat&lt;/P&gt;&lt;P&gt;Delta Sync Statistics&lt;/P&gt;&lt;P&gt;Sync status: OK&lt;/P&gt;&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 1142352&lt;BR /&gt;Sent retransmission requests................. 2&lt;BR /&gt;Sent retransmission updates.................. 0&lt;BR /&gt;Peak fragments per update.................... 1&lt;/P&gt;&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 13704124&lt;BR /&gt;Received retransmission requests............. 0&lt;/P&gt;&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... Sync&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 78480 [Bps]&lt;BR /&gt;Peak rate.................................... 78480 [Bps]&lt;BR /&gt;Link usage................................... 0%&lt;BR /&gt;Total........................................ 65614 [MB]&lt;/P&gt;&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;&lt;P&gt;Reset on Mon Jun 19 15:00:30 2023 (triggered by fullsync).&lt;/P&gt;&lt;P&gt;============================================================================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Member 2 - FW_02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW_02&amp;gt; cphaprob roles&lt;/P&gt;&lt;P&gt;ID Role&lt;/P&gt;&lt;P&gt;1 Non-Master&lt;BR /&gt;2 (local) Master&lt;/P&gt;&lt;P&gt;FW_02&amp;gt; cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 172.16.0.1 0% DOWN FW_01&lt;BR /&gt;2 (local) 172.16.0.2 100% ACTIVE(!) FW_02&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: LPRB, IAC&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-116505&lt;BR /&gt;State change: DOWN -&amp;gt; ACTIVE(!)&lt;BR /&gt;Reason for state change: All other machines are dead (timeout), Interface Sync is down (disconnected / link down)&lt;BR /&gt;Event time: Mon Jun 19 15:00:06 2023&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: Available on member 1&lt;BR /&gt;Event time: Mon Jun 19 15:00:06 2023&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 1&lt;BR /&gt;Time of counter reset: Wed Jun 14 13:08:01 2023 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW_02&amp;gt; cphaprob -a if&lt;/P&gt;&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;&lt;P&gt;eth1 UP&lt;BR /&gt;Sync (S) UP&lt;BR /&gt;Mgmt (P) DOWN (940895 secs)&lt;/P&gt;&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 2&lt;/P&gt;&lt;P&gt;eth1 10.24.3.254&lt;BR /&gt;Mgmt 192.168.1.3&lt;/P&gt;&lt;P&gt;FW_02&amp;gt; cphaprob list&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem (non-blocking)&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 940907 sec&lt;/P&gt;&lt;P&gt;FW_02&amp;gt; cphaprob syncstat&lt;/P&gt;&lt;P&gt;Delta Sync Statistics&lt;/P&gt;&lt;P&gt;Sync status: OK&lt;/P&gt;&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 13940522&lt;BR /&gt;Sent retransmission requests................. 1&lt;BR /&gt;Sent retransmission updates.................. 35&lt;BR /&gt;Peak fragments per update.................... 1&lt;/P&gt;&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 972144&lt;BR /&gt;Received retransmission requests............. 1&lt;/P&gt;&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... Sync&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 78470 [Bps]&lt;BR /&gt;Peak rate.................................... 78470 [Bps]&lt;BR /&gt;Link usage................................... 0%&lt;BR /&gt;Total........................................ 65644 [MB]&lt;/P&gt;&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;&lt;P&gt;Reset on Mon Jun 19 14:54:13 2023 (triggered by fullsync).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;A detail,
member 1 and 2, talk to each other and to the management, but do not go out to the internet. Manages, talks to everyone and goes out to the internet.&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 30 Jun 2023 15:25:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185332#M34091</guid>
      <dc:creator>Luciano_Cirino</dc:creator>
      <dc:date>2023-06-30T15:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Failure in the implementation of ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185333#M34092</link>
      <description>&lt;P&gt;Appears there is sync issue. If I were you, I would issue cphastop; cphastart on both members and test again.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 15:27:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185333#M34092</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-30T15:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Failure in the implementation of ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185366#M34093</link>
      <description>&lt;P&gt;Edited the original post for clarity and moved it to the correct space&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 21:26:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failure-in-the-implementation-of-ClusterXL/m-p/185366#M34093</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-30T21:26:18Z</dc:date>
    </item>
  </channel>
</rss>

