<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Gateway in red  on smartconsole in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212025#M40211</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;We have two gateway in cluster.&lt;/P&gt;&lt;P&gt;the first gateway is in red.&lt;/P&gt;&lt;P&gt;I think I can't add or modify existing rule...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don"t understand why there is a gateway in red, there is no modification...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have only the admin account, to access to smartconsole R80.30 and webpage gaia portal R80.30.&lt;/P&gt;&lt;P&gt;and expert password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don"t have password cli to access to Gateway directly in cli.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How I can resolve this gateway in green ?&lt;/P&gt;&lt;P&gt;without break the other gateway or block access completly the compagny on rules on outside...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks you very Much&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 08:22:09 GMT</pubDate>
    <dc:creator>EricB84</dc:creator>
    <dc:date>2024-04-23T08:22:09Z</dc:date>
    <item>
      <title>Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212025#M40211</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;We have two gateway in cluster.&lt;/P&gt;&lt;P&gt;the first gateway is in red.&lt;/P&gt;&lt;P&gt;I think I can't add or modify existing rule...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don"t understand why there is a gateway in red, there is no modification...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have only the admin account, to access to smartconsole R80.30 and webpage gaia portal R80.30.&lt;/P&gt;&lt;P&gt;and expert password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don"t have password cli to access to Gateway directly in cli.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How I can resolve this gateway in green ?&lt;/P&gt;&lt;P&gt;without break the other gateway or block access completly the compagny on rules on outside...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks you very Much&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 08:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212025#M40211</guid>
      <dc:creator>EricB84</dc:creator>
      <dc:date>2024-04-23T08:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212028#M40212</link>
      <description>&lt;P&gt;R80.30 is out of support for a while now.&lt;BR /&gt;&lt;BR /&gt;As the error show, you have an issue with ClusterXL on one of the gateways. You need GW access to troubleshoot. If you can access GW WebUI, use the same credentials to access it via SSH or console&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 08:33:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212028#M40212</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-04-23T08:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212029#M40213</link>
      <description>&lt;P&gt;Beside of the unsupported release:&lt;BR /&gt;&lt;BR /&gt;The red cross icon can have many reasons. What tells the little popup when moving the mouse over it?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 08:39:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212029#M40213</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-23T08:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212032#M40216</link>
      <description>&lt;P&gt;hi vincent&lt;/P&gt;&lt;P&gt;thanks for your help&lt;/P&gt;&lt;P&gt;it's in attached files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don"t know how to connect directly to gateway&lt;/P&gt;&lt;P&gt;it's ok by management console only but not more&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 09:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212032#M40216</guid>
      <dc:creator>EricB84</dc:creator>
      <dc:date>2024-04-23T09:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212035#M40218</link>
      <description>&lt;P&gt;hi val&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have this message to connect to the first gateway&lt;BR /&gt;I have find the password for the second gateway and it's ok !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the first I have this message :&amp;nbsp;&lt;/P&gt;&lt;P&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;BR /&gt;@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @&lt;BR /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;BR /&gt;IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!&lt;BR /&gt;Someone could be eavesdropping on you right now (man-in-the-middle attack)!&lt;BR /&gt;It is also possible that the RSA host key has just been changed.&lt;BR /&gt;The fingerprint for the RSA key sent by the remote host is&lt;BR /&gt;XX:XX:XX:XX.......&amp;nbsp;&lt;BR /&gt;Please contact your system administrator.&lt;BR /&gt;Add correct host key in /home/admin/.ssh/known_hosts to get rid of this message.&lt;BR /&gt;Offending key in /home/admin/.ssh/known_hosts:2&lt;BR /&gt;RSA host key for 10.38.204.24 has changed and you have requested strict checking.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 09:26:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212035#M40218</guid>
      <dc:creator>EricB84</dc:creator>
      <dc:date>2024-04-23T09:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212038#M40219</link>
      <description>&lt;P&gt;Ignore this warning for now. Connect to the first GW via SSH and run "cphaprob stat" command&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 09:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212038#M40219</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-04-23T09:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212046#M40222</link>
      <description>&lt;P&gt;Cluster Mode: High Availability (Primary Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 1.1.1.1 0% DOWN fw1-CKP&lt;BR /&gt;2 1.1.1.2 100% ACTIVE fw2-CKP&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: IAC&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-110800&lt;BR /&gt;State change: INIT -&amp;gt; DOWN&lt;BR /&gt;Reason for state change: Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)&lt;BR /&gt;Event time: Tue Apr 9 09:59:29 2024&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: Interface eth3 is down (Cluster Control Protocol packets are not received)&lt;BR /&gt;Event time: Thu Apr 4 13:23:37 2024&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 13&lt;BR /&gt;Time of counter reset: Mon Aug 23 07:42:39 2021 (reboot)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have find this topic to remove the fw to cluster, and add again&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk88360" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk88360&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's possible ?&lt;/P&gt;&lt;P&gt;it's dont block all the lan, if there is only one fw active in the cluster ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 11:15:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212046#M40222</guid>
      <dc:creator>EricB84</dc:creator>
      <dc:date>2024-04-23T11:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212054#M40225</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;Reason for state change: Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)"&lt;BR /&gt;&lt;BR /&gt;So the interface configurations should be checked and compared between both nodes.&lt;BR /&gt;Seems like there is an interface configured in SmartConsole objects topology and on one of the nodes but not on the other.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:14:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212054#M40225</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-23T12:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212055#M40226</link>
      <description>&lt;P&gt;You may use as well commands like&lt;BR /&gt;&lt;BR /&gt;cphaprob -a if&lt;BR /&gt;fw getifs&lt;BR /&gt;&lt;BR /&gt;and see output.&lt;BR /&gt;Or at least, connect to the Gaia Web Interface and Check / Compare Interface Configs of both nodes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:18:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212055#M40226</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-23T12:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212061#M40229</link>
      <description>&lt;P&gt;Just try this from smart console, as per my screenshot and see what it shows you. And yes, send output of cphaprob -a if from both members, as well as output from cpconfig&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25374iFC5FC62BC665BCF6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:32:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212061#M40229</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T12:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212064#M40230</link>
      <description>&lt;P&gt;I have the solution !&lt;/P&gt;&lt;P&gt;in fact the interface in our backbone was shut&lt;/P&gt;&lt;P&gt;Im connect to cisco 4500, and shut, no shut and it's work now&lt;/P&gt;&lt;P&gt;all is green&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I don"t understand our configuration.&lt;/P&gt;&lt;P&gt;we have a cable rj45 between two gateway type sync&lt;/P&gt;&lt;P&gt;two cables directly in backbone cisco, with an interco vlan&lt;/P&gt;&lt;P&gt;and two other cables for the stack switch in another vlan, (same as the vlan for the smart console)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don"t understand why there is an interco with backbone, and a cable between two gw.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:46:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212064#M40230</guid>
      <dc:creator>EricB84</dc:creator>
      <dc:date>2024-04-23T12:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212065#M40231</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110595"&gt;@EricB84&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I have the solution !&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Congrats! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110595"&gt;@EricB84&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I don"t understand why there is an interco with backbone, and a cable between two gw.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Kindly explain what exactly you mean with interco with backbone&lt;BR /&gt;&lt;BR /&gt;brV&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:50:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212065#M40231</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-23T12:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212070#M40235</link>
      <description>&lt;P&gt;we have a&amp;nbsp;&lt;/P&gt;&lt;P&gt;cisco 4500 *2 : backbone of the compagny (who are connected all other switch by fiber)&lt;/P&gt;&lt;P&gt;and a stack of 5 switch in it room&lt;/P&gt;&lt;P&gt;and two checkpoint&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is a link between two checkpoint for the SYNC =&amp;gt; I think it's for HA&lt;/P&gt;&lt;P&gt;but there is a cable between checkpoint checkpoint and each backbone cisco on vlan interco 100 : vlan not routed (just to isolate of other vlan)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and two others cables in another vlan (the same of smartconsole vm) goes to each backbone cisco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don"t understand the configuration.&lt;/P&gt;&lt;P&gt;why there is a link between two gw type sync&lt;/P&gt;&lt;P&gt;and interco with backbone of the company&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:01:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212070#M40235</guid>
      <dc:creator>EricB84</dc:creator>
      <dc:date>2024-04-23T13:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212075#M40237</link>
      <description>&lt;P&gt;First of all i would identity the interfaces on the Checkpoint devices connected to each other and those connected to your interco.&lt;BR /&gt;Then i would have a look at the topology of the object in SmartConsole.&lt;BR /&gt;I guess, somebody has configured two interfaces as sync interfaces. What should work in theory i guess but officially it's not a supported setup afaik.&lt;BR /&gt;Supported sync redundancy is to do that using bond interfaces.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:16:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212075#M40237</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-04-23T13:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway in red  on smartconsole</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212077#M40239</link>
      <description>&lt;P&gt;I agree with everything&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16383"&gt;@Vincent_Bacher&lt;/a&gt;&amp;nbsp;said. Just for the context, would you mind run below commands on both members and send as text file attachments.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cpconfig&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob -l list&lt;/P&gt;
&lt;P&gt;cphaprob show_failover&lt;/P&gt;
&lt;P&gt;cphaprob mvc&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:34:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-in-red-on-smartconsole/m-p/212077#M40239</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-23T13:34:14Z</dc:date>
    </item>
  </channel>
</rss>

