<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClustetXL Down in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203572#M38365</link>
    <description>&lt;P&gt;For future reference, I would always recommend troubleshooting the connectivity before going straight to resetting SIC. If SIC was established and you then have a connectivity problem, resetting SIC only results in both a connectivity problem and also no SIC.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 02:11:36 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2024-01-19T02:11:36Z</dc:date>
    <item>
      <title>ClusterXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203507#M38346</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I currently have a 3 member ClusterXL HA.&lt;BR /&gt;1 of the members that was in "Standby" status, since a few days ago, has gone to "DOWN" status.&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;[Expert@fw2:0]# cphaprob show_failover&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Last cluster failover event:&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Reason: Interface Mgmt is down (Cluster Control Protocol packets are not received)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Event time: Sat Jan 13 08:30:25 2024&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cluster failover count:&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Failover counter: 139&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Time of counter reset: Fri Jul 28 09:33:23 2023 (reboot)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Cluster failover history (last 20 failovers since reboot/reset on Fri Jul 28 09:33:50 2023):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;No. Time: Transition: CPU: Reason: &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;1 Sat Jan 13 08:30:25 2024 Member 1 -&amp;gt; Member 2 06 Interface Mgmt is down (Cluster Control Protocol packets are not received)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2 Thu Jan 11 21:23:41 2024 Member 3 -&amp;gt; Member 1 14 Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------------------------------------------------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;[Expert@fw2:0]# ethtool Mgmt&lt;BR /&gt;Settings for Mgmt:&lt;BR /&gt;Supported ports: [ TP ]&lt;BR /&gt;Supported link modes: 10baseT/Half 10baseT/Full &lt;BR /&gt;100baseT/Half 100baseT/Full &lt;BR /&gt;1000baseT/Full &lt;BR /&gt;Supported pause frame use: Symmetric&lt;BR /&gt;Supports auto-negotiation: Yes&lt;BR /&gt;Supported FEC modes: Not reported&lt;BR /&gt;Advertised link modes: 10baseT/Half 10baseT/Full &lt;BR /&gt;100baseT/Half 100baseT/Full &lt;BR /&gt;1000baseT/Full &lt;BR /&gt;Advertised pause frame use: No&lt;BR /&gt;Advertised auto-negotiation: Yes&lt;BR /&gt;Advertised FEC modes: Not reported&lt;BR /&gt;Speed: 1000Mb/s&lt;BR /&gt;Duplex: Full&lt;BR /&gt;Port: Twisted Pair&lt;BR /&gt;PHYAD: 1&lt;BR /&gt;Transceiver: internal&lt;BR /&gt;Auto-negotiation: on&lt;BR /&gt;MDI-X: on (auto)&lt;BR /&gt;Supports Wake-on: pumbg&lt;BR /&gt;Wake-on: g&lt;BR /&gt;Current message level: 0x00000007 (7)&lt;BR /&gt;drv probe link&lt;BR /&gt;&lt;STRONG&gt;Link detected: yes&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;-------------------------------------------------------------------------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;What I have found, is that the diagnostic commands, make reference to the "Mgmt" interface of the box being "Down", but the interface, physically and logically are normal (on and linking).&lt;/P&gt;
&lt;P&gt;The "ethtool Mgmt" also tells us that the box does detect the connected cable.&lt;/P&gt;
&lt;P&gt;Can this error be caused by the other equipment connected to the other side of the cable that is on the Mgmt port (either a SW, or other equipment)?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 08:37:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203507#M38346</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-22T08:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203508#M38347</link>
      <description>&lt;P&gt;Please send below from that member&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob -l list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 15:47:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203508#M38347</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T15:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203509#M38348</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I share the result of the diagnostic commands.&lt;BR /&gt;&lt;BR /&gt;Thank you for your comments.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 15:53:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203509#M38348</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-18T15:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203510#M38349</link>
      <description>&lt;P&gt;Yea, definitely something with Mgmt interface. Can you confirm you can get interface without topology in smart console cluster object and does not give any errors?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 15:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203510#M38349</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T15:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203513#M38350</link>
      <description>&lt;P&gt;I tried it, and I got the following error message.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CL1.png" style="width: 735px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24119iAEBF6EF258D9A94C/image-size/large?v=v2&amp;amp;px=999" role="button" title="CL1.png" alt="CL1.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Does this make the Firewall responsible for the error?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 16:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203513#M38350</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-18T16:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203514#M38351</link>
      <description>&lt;P&gt;What does SIC show?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 16:13:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203514#M38351</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T16:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203517#M38352</link>
      <description>&lt;P&gt;I note this, in the SIC communication.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CL2.png" style="width: 570px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24120i7D51103291A55EC0/image-size/large?v=v2&amp;amp;px=999" role="button" title="CL2.png" alt="CL2.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Unlike my other 2 GW's that work fine, where the "Test SIC Status" shows me a "Communicating".&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 16:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203517#M38352</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-18T16:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203524#M38353</link>
      <description>&lt;P&gt;Thats your issue then, so you can reset SIC without actually having to do cpstop; cpstart, which would load initial policy anyway if you do SIC reset&lt;/P&gt;
&lt;P&gt;&lt;A href="https://korkutozcan.com/how-to-reset-sic-without-restarting-check-point-gw/" target="_blank"&gt;https://korkutozcan.com/how-to-reset-sic-without-restarting-check-point-gw/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 16:53:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203524#M38353</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T16:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203531#M38354</link>
      <description>&lt;P&gt;Buddy,&lt;/P&gt;
&lt;P&gt;Isn't this type of alert due to a connectivity problem?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:24:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203531#M38354</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-18T18:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203532#M38355</link>
      <description>&lt;P&gt;yes sir&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:25:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203532#M38355</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T18:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203535#M38356</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I followed the steps in the URL, but I get the following error.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CL3.png" style="width: 660px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24127i0B09F0012344FC9C/image-size/large?v=v2&amp;amp;px=999" role="button" title="CL3.png" alt="CL3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Do you think I should validate something else?&lt;/P&gt;
&lt;P&gt;I already reset the SIC in the GW CLI, and I also did it in the FW object that is "corrupted" from the SmartConsole.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:44:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203535#M38356</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-18T18:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203536#M38357</link>
      <description>&lt;P&gt;You need to see why it fails...check routes, ping, traceroute, do some captures. It appears basic connectivity is not there, if even SIC cant be established, which is an absolute must for policy install to work.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:46:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203536#M38357</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T18:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203539#M38359</link>
      <description>&lt;P&gt;My ClusterXL HA has 3 members.&lt;/P&gt;
&lt;P&gt;I think it is a problem with the SW to which the management interfaces of each box are connected.&lt;BR /&gt;&lt;BR /&gt;Is it advisable, to check the other equipment, to which my failed box is connected?&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ACTIVE FW&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;[Expert@fw1:0]# ping 172.16.113.44&lt;BR /&gt;PING 172.16.113.44 (172.16.113.44) 56(84) bytes of data.&lt;BR /&gt;64 bytes from 172.16.113.44: icmp_seq=1 ttl=64 time=0.491 ms&lt;BR /&gt;64 bytes from 172.16.113.44: icmp_seq=2 ttl=64 time=0.176 ms&lt;/P&gt;
&lt;P&gt;[Expert@fw1:0]# ip r g 172.16.113.44&lt;BR /&gt;172.16.113.44 dev Mgmt src 172.16.113.2 &lt;BR /&gt;cache &lt;BR /&gt;[Expert@fw1:0]# &lt;BR /&gt;[Expert@fw1:0]# traceroute 172.16.113.44&lt;BR /&gt;traceroute to 172.16.113.44 (172.16.113.44), 30 hops max, 40 byte packets&lt;BR /&gt;1 172.16.113.44 (172.16.113.44) 0.634 ms 0.648 ms 0.731 ms&lt;BR /&gt;[Expert@fw1:0]#&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1st FW STANDBY&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;[Expert@fw3:0]# ping 172.16.113.44&lt;BR /&gt;PING 172.16.113.44 (172.16.113.44) 56(84) bytes of data.&lt;BR /&gt;64 bytes from 172.16.113.44: icmp_seq=2 ttl=64 time=0.970 ms&lt;BR /&gt;64 bytes from 172.16.113.44: icmp_seq=3 ttl=64 time=0.523 m&lt;/P&gt;
&lt;P&gt;[Expert@fw3:0]# ip r g 172.16.113.44&lt;BR /&gt;172.16.113.44 dev Mgmt src 172.16.113.4 &lt;BR /&gt;cache &lt;BR /&gt;[Expert@fw3:0]# &lt;BR /&gt;[Expert@fw3:0]# ip r g 172.16.113.44&lt;BR /&gt;172.16.113.44 dev Mgmt src 172.16.113.4 &lt;BR /&gt;cache &lt;BR /&gt;[Expert@fw3:0]#&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2nd FW STANDBY (This is the one that is failing)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;[Expert@fw2:0]# ping 172.16.113.44&lt;BR /&gt;PING 172.16.113.44 (172.16.113.44) 56(84) bytes of data.&lt;BR /&gt;From 172.16.113.3 icmp_seq=20 Destination Host Unreachable&lt;BR /&gt;From 172.16.113.3 icmp_seq=21 Destination Host Unreachable&lt;/P&gt;
&lt;P&gt;[Expert@fw2:0]# ip r g 172.16.113.44&lt;BR /&gt;172.16.113.44 dev Mgmt src 172.16.113.3 &lt;BR /&gt;cache&lt;/P&gt;
&lt;P&gt;[Expert@fw2:0]# traceroute 172.16.113.44&lt;BR /&gt;traceroute to 172.16.113.44 (172.16.113.44), 30 hops max, 40 byte packets&lt;BR /&gt;1 * * *&lt;BR /&gt;2 * * *&lt;BR /&gt;3 * * *&lt;BR /&gt;4 * * *&lt;BR /&gt;5 * * *&lt;BR /&gt;6 * * *&lt;BR /&gt;7 * * *&lt;BR /&gt;8 * * *&lt;BR /&gt;9 * * *&lt;BR /&gt;10 * * *&lt;BR /&gt;11 * * *&lt;BR /&gt;12 * * *&lt;BR /&gt;13 * * *&lt;BR /&gt;14 * * *&lt;BR /&gt;15 * * *&lt;BR /&gt;16 * * *&lt;BR /&gt;&lt;BR /&gt;Thanks. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 19:08:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203539#M38359</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-18T19:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203545#M38361</link>
      <description>&lt;P&gt;Sort of goes without saying, you should go by process of elimination, ie check whatever equipment is "in the picture"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 21:01:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203545#M38361</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T21:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203572#M38365</link>
      <description>&lt;P&gt;For future reference, I would always recommend troubleshooting the connectivity before going straight to resetting SIC. If SIC was established and you then have a connectivity problem, resetting SIC only results in both a connectivity problem and also no SIC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 02:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203572#M38365</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-01-19T02:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: ClustetXL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203574#M38367</link>
      <description>&lt;P&gt;For sure, 100%. Personally, thats what I always do when people have such an issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 02:16:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Down/m-p/203574#M38367</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-19T02:16:39Z</dc:date>
    </item>
  </channel>
</rss>

