<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX - cphaprob -a if show different Required interface on different member cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/193424#M35935</link>
    <description>&lt;P&gt;Does the issue persists following a reboot?&lt;/P&gt;
&lt;P&gt;In the GAiA configuration for each member how many interfaces have 'state on' set?&lt;/P&gt;
&lt;P&gt;With reference to&amp;nbsp;&lt;SPAN&gt;sk94545 what is the status of your bonds and the relevant config file(s)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Sep 2023 00:42:54 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-09-24T00:42:54Z</dc:date>
    <item>
      <title>VSX - cphaprob -a if show different Required interface on different member cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/118048#M16707</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;we have a vsx clusterXL ,&lt;BR /&gt;&lt;BR /&gt;atm the status is "active/down"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;node 1 show MORE interfaces than normal using cphaprob -a if&amp;nbsp;&lt;BR /&gt;we have 31 interface ,and this value is correct on noode 2 ,down ATM.&lt;BR /&gt;&lt;BR /&gt;Node 1 report 47 Required interface. it's strange.&lt;BR /&gt;&lt;BR /&gt;All the interfaces are up ,&lt;/P&gt;&lt;P&gt;We can reach every next-hop&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;NODE1 : active&lt;/P&gt;&lt;P&gt;[Expert@MI-DM-VSX1AOFE1:7]# cphaprob -i list&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem (non-blocking)&lt;/P&gt;&lt;P&gt;NODE 2 : DOWN&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@MI-DM-VSX1AOFE2:7]# cphaprob -i list&lt;/P&gt;&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;&lt;P&gt;* Issue 'cphaprob -l list' to show full list of pnotes&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NODE 1 : Active&lt;/P&gt;&lt;P&gt;vsid 7:&lt;BR /&gt;------&lt;BR /&gt;Required interfaces: 9***&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;bond0 UP sync(secured), broadcast, bond Load Sharing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 6&lt;/P&gt;&lt;P&gt;eth1-02.156 100.97.12.225&lt;BR /&gt;eth1-02.1156 100.97.112.225&lt;BR /&gt;eth1-02.1106 100.97.110.81&lt;BR /&gt;eth1-01.206 100.97.20.81&lt;BR /&gt;eth1-03.306 100.97.30.81&lt;BR /&gt;eth1-02.106 100.97.10.81&lt;BR /&gt;&lt;BR /&gt;NODE 2 : DOWN&lt;/P&gt;&lt;P&gt;vsid 7:&lt;BR /&gt;------&lt;BR /&gt;Required interfaces: 1&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;bond0 UP sync(secured), broadcast, bond Load Sharing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 6&lt;/P&gt;&lt;P&gt;eth1-02.156 100.97.12.225&lt;BR /&gt;eth1-02.1156 100.97.112.225&lt;BR /&gt;eth1-02.1106 100.97.110.81&lt;BR /&gt;eth1-01.206 100.97.20.81&lt;BR /&gt;eth1-03.306 100.97.30.81&lt;BR /&gt;eth1-02.106 100.97.10.81&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[Expert@MI-DM-VSX1AOFE1:7]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: VSX High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 (local) 10.255.255.77 100% Active Attention&lt;BR /&gt;2 10.255.255.78 0% Down&lt;BR /&gt;&lt;BR /&gt;IT's strange because node 2 report the CORRECT number of interfaces ,but probably is down because node 1 "force" to see more interfaces.&lt;BR /&gt;&lt;BR /&gt;Any suggestion ?&lt;BR /&gt;&lt;BR /&gt;they are R77,30 with latest jumbo ;&lt;/P&gt;&lt;P&gt;don't suggest to udpate them : we tried to udpate to 80.40 ( with cpuse and update ,and with fresh install + vsx reconfigure but after the update all the vfw lost every ROUTE so we needed to rollback )&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;NODE 2 : down&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 09:33:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/118048#M16707</guid>
      <dc:creator>Supporto_Checkp</dc:creator>
      <dc:date>2021-05-10T09:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - cphaprob -a if show different Required interface on different member cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/118053#M16709</link>
      <description>&lt;P&gt;First, I would compare the&lt;BR /&gt;&lt;FONT color="#333399"&gt;fw ctl get int fwha_monitor_all_vlan&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#333399"&gt;fw ctl get int fwha_monitor_specific_vlan&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#333399"&gt;fw ctl get int fwha_monitor_low_high_vlans&lt;/FONT&gt;&lt;BR /&gt;and&lt;BR /&gt;&lt;FONT color="#333399"&gt;$FWDIR/boot/modules/fwkern.conf&lt;/FONT&gt;&lt;BR /&gt;and&lt;BR /&gt;&lt;FONT color="#333399"&gt;$FWDIR/conf/cpha_specific_vlan_data.conf&lt;/FONT&gt; (per VS)&lt;BR /&gt;of both cluster members.&lt;/P&gt;&lt;P&gt;Maybe there is a mismatch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 10:05:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/118053#M16709</guid>
      <dc:creator>Martin_Stolz</dc:creator>
      <dc:date>2021-05-10T10:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - cphaprob -a if show different Required interface on different member cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/118067#M16713</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;everything seems fine&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[Expert@MI-DM-VSX1AOFE1:0]# cat /var/opt/fw.boot/modules/fwkern.conf&lt;BR /&gt;fwha_active_standby_bridge_mode=1&lt;BR /&gt;fwha_monitor_if_link_state=1&lt;BR /&gt;fwha_mac_magic=130&lt;BR /&gt;fwha_mac_forward_magic=129&lt;BR /&gt;fwha_add_vsid_to_ccp_mac=1&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE1:0]# fw ctl get int fwha_monitor_all_vlan&lt;BR /&gt;fwha_monitor_all_vlan = 0&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE1:0]# fw ctl get int fwha_monitor_specific_vlan&lt;BR /&gt;fwha_monitor_specific_vlan = 0&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE1:0]# fw ctl get int fwha_monitor_low_high_vlans&lt;BR /&gt;fwha_monitor_low_high_vlans = 1&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE1:0]# cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;fwha_active_standby_bridge_mode=1&lt;BR /&gt;fwha_monitor_if_link_state=1&lt;BR /&gt;fwha_mac_magic=130&lt;BR /&gt;fwha_mac_forward_magic=129&lt;BR /&gt;fwha_add_vsid_to_ccp_mac=1&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE1:0]#&lt;/P&gt;&lt;P&gt;[Expert@MI-DM-VSX1AOFE2:0]# cat /var/opt/fw.boot/modules/fwkern.conf&lt;BR /&gt;fwha_active_standby_bridge_mode=1&lt;BR /&gt;fwha_monitor_if_link_state=1&lt;BR /&gt;fwha_mac_magic=130&lt;BR /&gt;fwha_mac_forward_magic=129&lt;BR /&gt;fwha_add_vsid_to_ccp_mac=1&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE2:0]# fw ctl get int fwha_monitor_all_vlan&lt;BR /&gt;fwha_monitor_all_vlan = 0&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE2:0]# fw ctl get int fwha_monitor_specific_vlan&lt;BR /&gt;fwha_monitor_specific_vlan = 0&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE2:0]# fw ctl get int fwha_monitor_low_high_vlans&lt;BR /&gt;fwha_monitor_low_high_vlans = 1&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE2:0]# cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;fwha_active_standby_bridge_mode=1&lt;BR /&gt;fwha_monitor_if_link_state=1&lt;BR /&gt;fwha_mac_magic=130&lt;BR /&gt;fwha_mac_forward_magic=129&lt;BR /&gt;fwha_add_vsid_to_ccp_mac=1&lt;BR /&gt;[Expert@MI-DM-VSX1AOFE2:0]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$FWDIR/conf/cpha_specific_vlan_data.conf exists only in vs0 and it's empty,all lines commented&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 12:55:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/118067#M16713</guid>
      <dc:creator>Supporto_Checkp</dc:creator>
      <dc:date>2021-05-10T12:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - cphaprob -a if show different Required interface on different member cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/165797#M29760</link>
      <description>&lt;P&gt;Did you figure it out? Seems like we are having the exact problem,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 14:29:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/165797#M29760</guid>
      <dc:creator>ycapps</dc:creator>
      <dc:date>2022-12-21T14:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - cphaprob -a if show different Required interface on different member cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/193387#M35928</link>
      <description>&lt;P&gt;Me to - we are having simmilar issues&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 20:12:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/193387#M35928</guid>
      <dc:creator>ftangen</dc:creator>
      <dc:date>2023-09-22T20:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - cphaprob -a if show different Required interface on different member cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/193424#M35935</link>
      <description>&lt;P&gt;Does the issue persists following a reboot?&lt;/P&gt;
&lt;P&gt;In the GAiA configuration for each member how many interfaces have 'state on' set?&lt;/P&gt;
&lt;P&gt;With reference to&amp;nbsp;&lt;SPAN&gt;sk94545 what is the status of your bonds and the relevant config file(s)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2023 00:42:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cphaprob-a-if-show-different-Required-interface-on-different/m-p/193424#M35935</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-09-24T00:42:54Z</dc:date>
    </item>
  </channel>
</rss>

