<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191774#M35503</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to share with our ongoing issue which i cannot solved and so far have not received interesting feedback from TAC. So maybe you had something similar and you did manage to solve it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus my cluser is &lt;STRONG&gt;cp 6600 in VRRP mode , sync only. gaia 81.10&amp;nbsp; , take 110&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem started from failed policy installation and we got following meesage :&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Policy instllation failed on gateway. Cluster policy instllation failed (see sk125152)&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;After that we noticed higher cpu than normally and some cores had peaks up to 100%. Normally it was arround 20-30%. So in my view there is correlation between policy instllation failure and high cpu. Some acion could even prove it = i installed latest hotfix take 110 and after reboot all looked really good but again tried to install policy what ends with failure and high cpu re-occur.&lt;/P&gt;&lt;P&gt;So i was digging deeper and sk indicates that it could be a problem with HA/ClusterXL. I found out that i cannot ping 2nd Sync node ip address.&amp;nbsp; weird thing is that i checked the switches where ports from firewalls are directly connected ( access vlan , both in a same,) and in both access switch t&lt;STRONG&gt;here is no mac on direct port leading to sync interface.&lt;/STRONG&gt;.. output from firewall just prove that in arp table ip which i am trying to ping has "incomplete" mac&amp;lt;-&amp;gt;ip resolution.. Same on both ends on different access switch..&lt;/P&gt;&lt;P&gt;so topology is like below :&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw node1 Sync port ---&amp;gt; access switch dc1 vlan 1000 ---&amp;gt; fiber between dc --&amp;gt; access switch dc2 vlan 1000 --&amp;gt;fw node2 Sync port&lt;/P&gt;&lt;P&gt;do you know what i could check further??&amp;nbsp;&lt;/P&gt;&lt;P&gt;i shut/unshut ports on fw/switches without any success. Is it possibile that some HA processes hanged, crushed and its not sending any traffic and switch cannot put mac on particular port ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you in advance for any hints&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2023 20:33:19 GMT</pubDate>
    <dc:creator>KamilZet</dc:creator>
    <dc:date>2023-09-06T20:33:19Z</dc:date>
    <item>
      <title>Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191774#M35503</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to share with our ongoing issue which i cannot solved and so far have not received interesting feedback from TAC. So maybe you had something similar and you did manage to solve it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus my cluser is &lt;STRONG&gt;cp 6600 in VRRP mode , sync only. gaia 81.10&amp;nbsp; , take 110&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem started from failed policy installation and we got following meesage :&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Policy instllation failed on gateway. Cluster policy instllation failed (see sk125152)&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;After that we noticed higher cpu than normally and some cores had peaks up to 100%. Normally it was arround 20-30%. So in my view there is correlation between policy instllation failure and high cpu. Some acion could even prove it = i installed latest hotfix take 110 and after reboot all looked really good but again tried to install policy what ends with failure and high cpu re-occur.&lt;/P&gt;&lt;P&gt;So i was digging deeper and sk indicates that it could be a problem with HA/ClusterXL. I found out that i cannot ping 2nd Sync node ip address.&amp;nbsp; weird thing is that i checked the switches where ports from firewalls are directly connected ( access vlan , both in a same,) and in both access switch t&lt;STRONG&gt;here is no mac on direct port leading to sync interface.&lt;/STRONG&gt;.. output from firewall just prove that in arp table ip which i am trying to ping has "incomplete" mac&amp;lt;-&amp;gt;ip resolution.. Same on both ends on different access switch..&lt;/P&gt;&lt;P&gt;so topology is like below :&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw node1 Sync port ---&amp;gt; access switch dc1 vlan 1000 ---&amp;gt; fiber between dc --&amp;gt; access switch dc2 vlan 1000 --&amp;gt;fw node2 Sync port&lt;/P&gt;&lt;P&gt;do you know what i could check further??&amp;nbsp;&lt;/P&gt;&lt;P&gt;i shut/unshut ports on fw/switches without any success. Is it possibile that some HA processes hanged, crushed and its not sending any traffic and switch cannot put mac on particular port ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you in advance for any hints&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 20:33:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191774#M35503</guid>
      <dc:creator>KamilZet</dc:creator>
      <dc:date>2023-09-06T20:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191776#M35504</link>
      <description>&lt;P&gt;This "&lt;STRONG&gt;Cluster policy &lt;/STRONG&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;installation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&amp;nbsp;failed"&amp;nbsp;&lt;/STRONG&gt;message no longer only means that the atomic load/commit failed or timed out on one of the cluster members, in R81+ it can also indicate that some kind of cluster sanity check failed during policy installation.&amp;nbsp; You'll need to look in&amp;nbsp;&lt;SPAN&gt;$FWDIR/log/cphaconf.elg on both members for clues about what is wrong.&amp;nbsp; So far I've seen this message indicate:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) One of the cluster members is set for MVC and one is not (&lt;/SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179969" target="_self"&gt;sk179969:&amp;nbsp;Policy&amp;nbsp;installation&amp;nbsp;fails&amp;nbsp;with error "Policy&amp;nbsp;installation&amp;nbsp;failed&amp;nbsp;on gateway.&amp;nbsp;Clusterpolicy&amp;nbsp;installation&amp;nbsp;failed&lt;/A&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179969" target="_self"&gt;"&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) The state of cluster enablement in &lt;STRONG&gt;cpconfig&lt;/STRONG&gt; is incorrect (enabled for a non-cluster object, or disabled for a gateway that is part of a cluster object -&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180980" target="_blank" rel="noopener"&gt;sk180980:&amp;nbsp;Policy&amp;nbsp;installation failure with error message "Policy&amp;nbsp;installation&amp;nbsp;failed&amp;nbsp;on gateway.&amp;nbsp;Cluster&amp;nbsp;policy&amp;nbsp;installation&amp;nbsp;failed&amp;nbsp;(see sk125152)"&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There are probably some other sanity checks I haven't run into yet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The fact that you can't ARP on the sync network is a definite problem, and may be another one of the new sanity checks that are performed; namely making sure that the sync network is working, assuming state sync is enabled on the cluster object.&amp;nbsp; ARP is never denied by a security policy or antispoofing so I'd look there.&amp;nbsp; The high CPU is probably a symptom of the problem rather than the cause, unless it is so extreme it is causing a commit timeout on one of the gateways.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 22:55:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191776#M35504</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-09-06T22:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191787#M35505</link>
      <description>&lt;P&gt;Just to be sure of cluster state, can you send below from both members?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob list&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 23:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191787#M35505</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-06T23:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191848#M35506</link>
      <description>&lt;P&gt;here you are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw1:&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-01:0]# cphaprob roles&lt;/P&gt;&lt;P&gt;ID Role&lt;/P&gt;&lt;P&gt;1 (local) Master&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-01:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: Sync only (OPSEC) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Firewall State (*)&lt;/P&gt;&lt;P&gt;1 (local) 192.168.10.226 Active&lt;/P&gt;&lt;P&gt;(*) FW-1 monitors only the sync operation and the security policy&lt;BR /&gt;Use OPSEC's monitoring tool to get the cluster status&lt;BR /&gt;[Expert@fw-de-niest-01:0]# cphaprob list&lt;/P&gt;&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-01:0]# cphaprob -a if&lt;/P&gt;&lt;P&gt;CCP mode: Manual (Multicast)&lt;BR /&gt;Sync sync(secured), multicast&lt;BR /&gt;Mgmt non sync(non secured)&lt;BR /&gt;eth1-04 non sync(non secured)&lt;BR /&gt;eth1-02 non sync(non secured)&lt;BR /&gt;eth1-03 non sync(non secured)&lt;BR /&gt;eth1-01 non sync(non secured)&lt;BR /&gt;eth1-02 non sync(non secured)&lt;/P&gt;&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 19&lt;/P&gt;&lt;P&gt;eth1-04 xxxxx ( x just to hide in use ip addresses )&amp;nbsp;&lt;BR /&gt;eth1-02.2001 xxxxx&lt;BR /&gt;eth1-02.3507 xxxxxx&lt;BR /&gt;eth1-02.3503 xxxxx&lt;BR /&gt;eth1-02.3524 xxxxx&lt;BR /&gt;eth1-02.2100 xxxxx&lt;BR /&gt;eth1-02.3505 xxxxx&lt;BR /&gt;eth1-02.2030 xxxxx&lt;BR /&gt;eth1-03.2032 xxxxx&lt;BR /&gt;eth1-02.3504 xxxxx&lt;BR /&gt;eth1-01.2086 xxxxx&lt;BR /&gt;eth1-02.3508 xxxxx&lt;BR /&gt;eth1-02.2031 xxxxx&lt;BR /&gt;eth1-02.3529 xxxxx&lt;BR /&gt;eth1-02.3587 xxxxx&lt;BR /&gt;eth1-02.3588 xxxxx&lt;BR /&gt;eth1-02.3523 xxxxx&lt;BR /&gt;eth1-02.2084 xxxxx&lt;BR /&gt;eth1-02.3510 xxxxx&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-01:0]# cphaprob syncstat&lt;/P&gt;&lt;P&gt;Delta Sync Statistics&lt;/P&gt;&lt;P&gt;Sync status: OK&lt;/P&gt;&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 45951141&lt;BR /&gt;Sent retransmission requests................. 0&lt;BR /&gt;Sent retransmission updates.................. 0&lt;BR /&gt;Peak fragments per update.................... 2&lt;/P&gt;&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 0&lt;BR /&gt;Received retransmission requests............. 0&lt;/P&gt;&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... Sync&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 5178 [KBps]&lt;BR /&gt;Peak rate.................................... 7906 [KBps]&lt;BR /&gt;Link usage................................... 4%&lt;BR /&gt;Total........................................ 655036[MB]&lt;/P&gt;&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;&lt;P&gt;Reset on Tue Sep 5 22:14:50 2023 (triggered by fullsync).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@fw-de-niest-02:0]# cphaprob roles&lt;/P&gt;&lt;P&gt;ID Role&lt;/P&gt;&lt;P&gt;2 (local) Non-Master&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-02:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: Sync only (OPSEC) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Firewall State (*)&lt;/P&gt;&lt;P&gt;2 (local) 192.168.10.227 Active&lt;/P&gt;&lt;P&gt;(*) FW-1 monitors only the sync operation and the security policy&lt;BR /&gt;Use OPSEC's monitoring tool to get the cluster status&lt;BR /&gt;[Expert@fw-de-niest-02:0]# cphaprob list&lt;/P&gt;&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-02:0]# cphaprob -a if&lt;/P&gt;&lt;P&gt;CCP mode: Manual (Multicast)&lt;BR /&gt;Sync sync(secured), multicast&lt;BR /&gt;Mgmt non sync(non secured)&lt;BR /&gt;eth1-04 non sync(non secured)&lt;BR /&gt;eth1-02 non sync(non secured)&lt;BR /&gt;eth1-03 non sync(non secured)&lt;BR /&gt;eth1-01 non sync(non secured)&lt;BR /&gt;eth1-02 non sync(non secured)&lt;/P&gt;&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 19&lt;/P&gt;&lt;P&gt;eth1-04 xxxxxxx&lt;BR /&gt;eth1-02.2001 xxxxxxx&lt;BR /&gt;eth1-02.3507 xxxxxxx&lt;BR /&gt;eth1-02.3503 xxxxxxx&lt;BR /&gt;eth1-02.3524 xxxxxxx&lt;BR /&gt;eth1-02.2100 xxxxxxx&lt;BR /&gt;eth1-02.3505 xxxxxxx&lt;BR /&gt;eth1-02.2030 xxxxxxx&lt;BR /&gt;eth1-03.2032 xxxxxxx&lt;BR /&gt;eth1-02.3504 xxxxxxx&lt;BR /&gt;eth1-01.2086 xxxxxxx&lt;BR /&gt;eth1-02.3508 xxxxxxx&lt;BR /&gt;eth1-02.2031 xxxxxxx&lt;BR /&gt;eth1-02.3529 xxxxxxx&lt;BR /&gt;eth1-02.3587 xxxxxxx&lt;BR /&gt;eth1-02.3588 xxxxxxx&lt;BR /&gt;eth1-02.3523 xxxxxxx&lt;BR /&gt;eth1-02.2084 xxxxxxx&lt;BR /&gt;eth1-02.3510 xxxxxxx&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-02:0]# cphaprob syncstat&lt;/P&gt;&lt;P&gt;Delta Sync Statistics&lt;/P&gt;&lt;P&gt;Sync status: OK&lt;/P&gt;&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 3349848&lt;BR /&gt;Sent retransmission requests................. 0&lt;BR /&gt;Sent retransmission updates.................. 0&lt;BR /&gt;Peak fragments per update.................... 2&lt;/P&gt;&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 0&lt;BR /&gt;Received retransmission requests............. 0&lt;/P&gt;&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... Sync&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 16620 [Bps]&lt;BR /&gt;Peak rate.................................... 4815 [KBps]&lt;BR /&gt;Link usage................................... 0%&lt;BR /&gt;Total........................................ 4976 [MB]&lt;/P&gt;&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;&lt;P&gt;Reset on Tue Sep 5 21:30:04 2023 (triggered by fullsync).&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 06:27:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191848#M35506</guid>
      <dc:creator>KamilZet</dc:creator>
      <dc:date>2023-09-07T06:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191858#M35507</link>
      <description>&lt;P&gt;Thx for joining to conversation. I will review mentioned logs by you :&amp;nbsp;&lt;SPAN&gt;cphaconf.elg. Regarding SK which you shared both are not related to me :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[Expert@fw-de-niest-01:0]# cphaprob mvc&lt;/P&gt;&lt;P&gt;OFF&lt;BR /&gt;&lt;BR /&gt;[Expert@fw-de-niest-02:0]# cphaprob mvc&lt;/P&gt;&lt;P&gt;OFF&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. i have clusterxl sync only with vrrp and it is configured on mgmt&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in addition to a problem we captured a packets on switch with direct connection to Sync port on FW where i am not seeing mac and there is only traffic like this :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-09-07 09_35_22-Window.png" style="width: 845px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22373i2478631F13055CFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-09-07 09_35_22-Window.png" alt="2023-09-07 09_35_22-Window.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 07:37:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191858#M35507</guid>
      <dc:creator>KamilZet</dc:creator>
      <dc:date>2023-09-07T07:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191877#M35508</link>
      <description>&lt;P&gt;This is your issue...BOTH members "think" they are active, as neither shows as backup. Can you verify in topology that you have configured all those interfaces as clustered AND you can also get interfaces without topology option?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 10:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191877#M35508</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-07T10:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191878#M35509</link>
      <description>&lt;P&gt;Just managed to solve it.. it was absolutelly our fault as vlan was removed due to migration ( by mistake ) on vtp server what cause removing it also from all clients. So access vlan was configured on port etc but in fact there was no such vlan anymore &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; and noone was looking in the easiest part but&amp;nbsp; digging in logs/changes etc ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;So recovering communication on a sync link solved high cpu ( quite interesting why , maybe due to having vrrp still in proper state but clusterXl sync had troubles ?? ) , installation of policy etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you all for you suggestion and help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 10:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191878#M35509</guid>
      <dc:creator>KamilZet</dc:creator>
      <dc:date>2023-09-07T10:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Installation failed on GW | sk125152 | High Cpu | Problem wih sync link</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191883#M35510</link>
      <description>&lt;P&gt;Yep, thats exactly it. Its important to remember, unlike most other major vendors, changes in CP cluster do NOT replicate automatically from master to backup, like they do in Cisco, FGT, PAN.&lt;/P&gt;
&lt;P&gt;Great job btw &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;✔&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 11:16:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Installation-failed-on-GW-sk125152-High-Cpu-Problem-wih/m-p/191883#M35510</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-07T11:16:58Z</dc:date>
    </item>
  </channel>
</rss>

