<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unexpected Failover in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196446#M36664</link>
    <description>&lt;P&gt;Please always remember to specify Version and JHF&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you find other information in /var/log/messages ?&lt;/P&gt;</description>
    <pubDate>Fri, 27 Oct 2023 20:45:26 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2023-10-27T20:45:26Z</dc:date>
    <item>
      <title>Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196422#M36656</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I would like your opnions about my problem.&lt;/P&gt;&lt;P&gt;I search for a long days and try to solved my problem, but uncessfull.&lt;/P&gt;&lt;P&gt;I opened a ticket for my business partner and they told me, "This problem is in your infraestruture", but I`m unconfortable with this answer.&lt;/P&gt;&lt;P&gt;I checked and ccp are runing in manual mode and unicast mode. In our switch we don´t have any log about interface down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oct 26 19:15:30.470983 cpcl_master_init(6353): entering&lt;BR /&gt;Oct 26 19:15:30.470983 entering cpcl_master_init()&lt;BR /&gt;Oct 26 19:15:30.470983 cpcl_master_init(6415): sockpath is /tmp/sockvrf0&lt;BR /&gt;Oct 26 19:15:30.470983 leaving cpcl_master_init()&lt;BR /&gt;Oct 26 19:15:30.470983 cpcl_master_init(6491): leaving&lt;/P&gt;&lt;P&gt;Oct 26 19:15:30&amp;nbsp; BGP State Sync&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; PIM State Sync&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; System Initialization&amp;nbsp;&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; OSPF3 Graceful Restart&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; OSPF2 Graceful Restart&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; OSPF State Sync&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; Cluster Sync&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; Cluster Notification&amp;nbsp;&amp;nbsp;&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; BGP Graceful Restart&amp;nbsp;&amp;nbsp;&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;BR /&gt;Oct 26 19:15:30&amp;nbsp; BFD Monitored Sessions&amp;nbsp; OK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Became master&lt;/P&gt;&lt;P&gt;CCP mode: Manual (Unicast)&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Transition to new ACTIVE:&amp;nbsp;&amp;nbsp; Member 1 -&amp;gt; Member 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Reason:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface ethX-XX.XXXX is down (disconnected / link down)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Event time:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thu Oct 26 19:15:30 2023&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:34:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196422#M36656</guid>
      <dc:creator>freakness</dc:creator>
      <dc:date>2023-10-27T15:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196446#M36664</link>
      <description>&lt;P&gt;Please always remember to specify Version and JHF&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you find other information in /var/log/messages ?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 20:45:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196446#M36664</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-10-27T20:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196464#M36666</link>
      <description>&lt;P&gt;We're there any configuration changes in the infrastructure at this time, is port-fast configured on the interfaces connecting the firewall?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2023 09:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196464#M36666</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-28T09:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196467#M36667</link>
      <description>&lt;P&gt;I would feel the same about that sort of answer you got, very generic and not overly helpful, sadly. But, you came to the right place, Im sure we can help you more. Here are few commands I would run if I were you.&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob mvc&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob -l list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;grep -i DOWN /var/log/messages*&lt;/P&gt;
&lt;P&gt;Just look for the date/time and interface affected in the grep command.&lt;/P&gt;
&lt;P&gt;If you need more help, I have very good cluster lab, so we can do any test needed.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2023 14:20:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196467#M36667</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-28T14:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196470#M36668</link>
      <description>&lt;P&gt;If you run &lt;STRONG&gt;ifconfig&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;ethX-XX&lt;/STRONG&gt; from expert mode for the relevant interface, is the "carrier" counter nonzero?&amp;nbsp; If so the interface went through a state transition (which is what that message is saying) which&amp;nbsp;could indicate a loose cable or the attached switch crashed or otherwise brought the port down.&amp;nbsp; Possibly a bad firewall NIC but not likely.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2023 14:41:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196470#M36668</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-10-28T14:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196483#M36672</link>
      <description>&lt;P&gt;Thanks for you answer.&lt;/P&gt;&lt;P&gt;Version R81.10&amp;nbsp; - build 883 and no hotfix installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;did you find other information in /var/log/messages ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Nothing. And the Fortigates working properly in our infraestructure.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2023 14:06:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196483#M36672</guid>
      <dc:creator>freakness</dc:creator>
      <dc:date>2023-10-29T14:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196484#M36673</link>
      <description>&lt;P&gt;Nothing.&lt;/P&gt;&lt;P&gt;I worked with Cisco in the past... and I didn't see any problem with this point and the same settings was used with other firewalls in the same infrastructure. I`m in the new job and I have 30 days here.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2023 14:09:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196484#M36673</guid>
      <dc:creator>freakness</dc:creator>
      <dc:date>2023-10-29T14:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196485#M36674</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;ifconfig eth1-XX&lt;BR /&gt;eth1-XX&amp;nbsp; &amp;nbsp; &amp;nbsp;Link encap:Ethernet&amp;nbsp; HWaddr XX:XX:7F:XX:F1:XX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UP BROADCAST RUNNING MULTICAST&amp;nbsp; MTU:1500&amp;nbsp; Metric:1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets:22543550903 errors:18709 dropped:0 overruns:0 frame:18614&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets:29795676550 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; collisions:0 txqueuelen:1000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:5785044122914 (5.2 TiB)&amp;nbsp; TX bytes:39969706629061 (36.3 TiB)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;This firewall has been working since january. This counter nerver been cleared.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2023 14:25:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196485#M36674</guid>
      <dc:creator>freakness</dc:creator>
      <dc:date>2023-10-29T14:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196487#M36675</link>
      <description>&lt;P&gt;cphaprob -a if, this command have a lot of information... It´s a problem for me sharing this. I don`t know, but in the specifical interface I aways have a problem&amp;nbsp; and the logs show me a specifical vlan, it isn´t the lowest and isn´t highest in this interface.&lt;BR /&gt;Ex:&lt;/P&gt;&lt;P&gt;Eth1.10&lt;BR /&gt;vlan 100&lt;BR /&gt;vlan 200&lt;BR /&gt;vlan 220 # Problem&lt;BR /&gt;vlan 400&lt;BR /&gt;vlan 700&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2023 14:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196487#M36675</guid>
      <dc:creator>freakness</dc:creator>
      <dc:date>2023-10-29T14:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196488#M36676</link>
      <description>&lt;P&gt;Running without a JHF applied is not recommended.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC will almost certainly ask you to update if there are no other obvious contributing factors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In general regarding portfast:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/r81.20/webadminguides/en/cp_r81.20_clusterxl_adminguide/content/topics-cxlg/troubleshooting-issues-with-bonds.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/r81.20/webadminguides/en/cp_r81.20_clusterxl_adminguide/content/topics-cxlg/troubleshooting-issues-with-bonds.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2023 14:46:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196488#M36676</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-29T14:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196490#M36677</link>
      <description>&lt;P&gt;The reason why you only see lowest and highest vlan in that command my friend is due to kernal parameter fwha_monitor_all_vlan being 0, which is by default. I would not bother changing it, as we had customer and many TAC cases about failover (usually routed issue) and we thought that parameter was the problem, but turns out it was not.&lt;/P&gt;
&lt;P&gt;If I were you, below is what I would give to TAC:&lt;/P&gt;
&lt;P&gt;cpinfo from both members&lt;/P&gt;
&lt;P&gt;all var/log/messages files&lt;/P&gt;
&lt;P&gt;all /var/log routed files&lt;/P&gt;
&lt;P&gt;cpview -s export&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2023 15:43:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196490#M36677</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-29T15:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196526#M36696</link>
      <description>&lt;P&gt;I'm sorry, I believe I caused a problem in your interpretation.&lt;/P&gt;&lt;P&gt;When I asked to our partner, He told me CCP just monitoring the highest and the lowest vlan in the same interface.&lt;/P&gt;&lt;P&gt;In any case, after some insistence on my part, a case was opened with checkpoint.&lt;BR /&gt;I hope the problem is identified and I continue to follow this forum here.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 09:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196526#M36696</guid>
      <dc:creator>freakness</dc:creator>
      <dc:date>2023-10-30T09:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196527#M36697</link>
      <description>&lt;P&gt;OK,&lt;/P&gt;&lt;P&gt;I understand your point about update as recomendation.&lt;/P&gt;&lt;P&gt;But I need to be sure that this will solve my specific problem.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 09:42:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196527#M36697</guid>
      <dc:creator>freakness</dc:creator>
      <dc:date>2023-10-30T09:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196538#M36700</link>
      <description>&lt;P&gt;That is A LOT of errors on the receiving side, you need to look into it ASAP&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 12:19:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unexpected-Failover/m-p/196538#M36700</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-30T12:19:39Z</dc:date>
    </item>
  </channel>
</rss>

