<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ClusterXL Alert (!) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202508#M38107</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a ClusterXL R81.10 with an alert.&lt;/P&gt;
&lt;P&gt;The problem is that according to the "&lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt;" command, the interface Eth1.19 ... is up, however, I still see the Cluster "alerted" when I query with the "&lt;STRONG&gt;cphaprob state&lt;/STRONG&gt;", I see the member 2 with the symbol &lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The fact of having the Cluster alerted, gives me the impression, that it is causing that from the SmartConsole, I see the alert related to a problem by the "AntiBot", but checking the AntiBot, I observe that everything is fine.&lt;/P&gt;
&lt;P&gt;The GW has Internet connectivity and DNS resolution.&lt;/P&gt;
&lt;P&gt;Is there a way to correct this?&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2024 18:57:46 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2024-01-08T18:57:46Z</dc:date>
    <item>
      <title>ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202508#M38107</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a ClusterXL R81.10 with an alert.&lt;/P&gt;
&lt;P&gt;The problem is that according to the "&lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt;" command, the interface Eth1.19 ... is up, however, I still see the Cluster "alerted" when I query with the "&lt;STRONG&gt;cphaprob state&lt;/STRONG&gt;", I see the member 2 with the symbol &lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The fact of having the Cluster alerted, gives me the impression, that it is causing that from the SmartConsole, I see the alert related to a problem by the "AntiBot", but checking the AntiBot, I observe that everything is fine.&lt;/P&gt;
&lt;P&gt;The GW has Internet connectivity and DNS resolution.&lt;/P&gt;
&lt;P&gt;Is there a way to correct this?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:57:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202508#M38107</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-08T18:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202511#M38108</link>
      <description>&lt;P&gt;Can you check your trunking to ensure L2 vlans are seen by both sides.&amp;nbsp; Also provide the output from SG1.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:02:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202511#M38108</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2024-01-08T19:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202512#M38109</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Have you tried cphastop; cphastart on the cluster member with the issue?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:03:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202512#M38109</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T19:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202513#M38110</link>
      <description>&lt;P&gt;Did you address the two problems mentioned here?&lt;BR /&gt;Neither of these issues are with Anti-Bot.&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs bp-is-scrollable" tabindex="0"&gt;&lt;CODE class="bp-text-code txt"&gt;Last member state change event:
   Event Code:                 CLUS-110305
   State change:               ACTIVE -&amp;gt; ACTIVE(!)
   Reason for state change:    Interface eth1.19 is down (Cluster Control Protocol packets are not received)
   Event time:                 Mon Dec 18 16:34:17 2023

Last cluster failover event:
   Transition to new ACTIVE:   Member 1 -&amp;gt; Member 2
   Reason:                     Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)
   Event time:                 Thu Dec 14 11:29:25 2023
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:03:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202513#M38110</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-08T19:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202515#M38111</link>
      <description>&lt;P&gt;Those things Phoneboy mentioned are 100% relevant, for sure, but just wondering, as they show mid December date, was it fixed since then?&lt;/P&gt;
&lt;P&gt;Please verify by running below&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaorrob -l list&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202515#M38111</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T19:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202523#M38112</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I provide the output of SG1 and SG2.&lt;/P&gt;
&lt;P&gt;I suspect that by having this "alert" in the Cluster (!), it may be causing the alert related to my AntiBot.&lt;/P&gt;
&lt;P&gt;I have done basic tests, such as making sure that there is internet connectivity from the 2 GWs and that both resolve DNS, and everything is fine.&lt;/P&gt;
&lt;P&gt;The problem is that from the SmartConsole, I have the alert both at ClusterXL and AntiBot level.&lt;/P&gt;
&lt;P&gt;I think, that both problems are related.&lt;/P&gt;
&lt;P&gt;I have applied the validation command "&lt;STRONG&gt;cpstat antimalware -f update_status&lt;/STRONG&gt;" on the member that is "&lt;STRONG&gt;ACTIVE(!)&lt;/STRONG&gt;" and I get the following result.&lt;/P&gt;
&lt;P&gt;Attached is the result of several commands applied on both GWs.&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:47:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202523#M38112</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-08T19:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202524#M38113</link>
      <description>&lt;P&gt;Can you send cphaprob -a if of cpfw02?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202524#M38113</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T19:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202525#M38114</link>
      <description>&lt;P&gt;Nm, got it. Okay, so on fw01, shows required interfaces 5 and other one shows 6, so something is not matching. Can you confirm topology is correct as far as cluster config for those interfaces?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202525#M38114</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T19:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202528#M38115</link>
      <description>&lt;P&gt;I'm observing the difference.&lt;/P&gt;
&lt;P&gt;Indeed, I see that my SG2, has 6 "Required Interfaces" and the SG1, only 5.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;---------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;[Expert@SG2:0]# cphaprob -a if&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;CCP mode: Manual (Unicast)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Required interfaces: 6&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Required secured interfaces: 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;[Expert@SG1:0]# cphaprob -a if&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;CCP mode: Manual (Unicast)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Required interfaces: 5&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Required secured interfaces: 1&lt;BR /&gt;&lt;BR /&gt;---------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;These values must be identical in both members, right?&lt;/P&gt;
&lt;P&gt;How can I fix this error?&lt;BR /&gt;Because according to my client, there should be 6 "Required Interfaces", not 5.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 20:31:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202528#M38115</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-08T20:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202532#M38116</link>
      <description>&lt;P&gt;If they dont match, cluster will never work properly. So, have them check smart console topology and observe those 6 interfaces to confirm topology is indeed set as cluster for them.&lt;/P&gt;
&lt;P&gt;I attached example from my lab&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24007i80ABAD2A0D4CF469/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24008i27D0D4FC71E27BBF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 20:35:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202532#M38116</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T20:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202535#M38117</link>
      <description>&lt;P&gt;It validates it.&lt;/P&gt;
&lt;P&gt;Indeed, there should only be &lt;STRONG&gt;5 Required Interfaces&lt;/STRONG&gt; (I made a mistake in the # I said in the previous post).&lt;/P&gt;
&lt;P&gt;The interfaces are in the SmartConsole topology, under "&lt;STRONG&gt;type -&amp;gt; Cluster&lt;/STRONG&gt;" except for the Sync interface, which is under "&lt;STRONG&gt;type -&amp;gt; Sync&lt;/STRONG&gt;".&lt;/P&gt;
&lt;P&gt;It occurs to me then, that from the SmartConsole I should give a "&lt;STRONG&gt;Get Interfaces Without Topology&lt;/STRONG&gt;", to "refresh" maybe the console, and mitigate the ClusterXL alert?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 20:54:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202535#M38117</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-08T20:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Alert (!)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202536#M38118</link>
      <description>&lt;P&gt;As long as you are positive its correct, yes, do that and install the policy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 20:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Alert/m-p/202536#M38118</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T20:55:42Z</dc:date>
    </item>
  </channel>
</rss>

