<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Delay when standby member to came up in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230079#M44275</link>
    <description>&lt;P&gt;HI Checkmates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Today i have seen new issue on cluster XL.&lt;/P&gt;&lt;P&gt;Environment: Distribution architecture&lt;/P&gt;&lt;P&gt;Version : R81.20&lt;/P&gt;&lt;P&gt;Hotfix : 84&lt;/P&gt;&lt;P&gt;Cluster members : 2 checkpoint appliances&lt;/P&gt;&lt;P&gt;When i do a cluster failover, secondary member takes at least 10 minutes to process the traffic. That time our all the services are goes down, after 10 minutes everything works fine. i did not observe any drops on log (smart console).&lt;/P&gt;&lt;P&gt;but the cluster state show active/standby states correctly. no delay on this part.&lt;/P&gt;&lt;P&gt;Kindly help me to sort out the new problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rajkumar T&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 19:57:22 GMT</pubDate>
    <dc:creator>TRajkumar</dc:creator>
    <dc:date>2024-10-17T19:57:22Z</dc:date>
    <item>
      <title>Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230079#M44275</link>
      <description>&lt;P&gt;HI Checkmates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Today i have seen new issue on cluster XL.&lt;/P&gt;&lt;P&gt;Environment: Distribution architecture&lt;/P&gt;&lt;P&gt;Version : R81.20&lt;/P&gt;&lt;P&gt;Hotfix : 84&lt;/P&gt;&lt;P&gt;Cluster members : 2 checkpoint appliances&lt;/P&gt;&lt;P&gt;When i do a cluster failover, secondary member takes at least 10 minutes to process the traffic. That time our all the services are goes down, after 10 minutes everything works fine. i did not observe any drops on log (smart console).&lt;/P&gt;&lt;P&gt;but the cluster state show active/standby states correctly. no delay on this part.&lt;/P&gt;&lt;P&gt;Kindly help me to sort out the new problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rajkumar T&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 19:57:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230079#M44275</guid>
      <dc:creator>TRajkumar</dc:creator>
      <dc:date>2024-10-17T19:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230080#M44276</link>
      <description>&lt;P&gt;Can you please send outputs of below when this happens?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;**********************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob -l list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;********************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, never seen such an issue myself, even back in R55.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 20:06:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230080#M44276</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-17T20:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230087#M44279</link>
      <description>&lt;P&gt;Is there any dynamic routing involved or are there issues with stale ARP entries?&lt;/P&gt;
&lt;P&gt;Do the issue occur regardless of which member is active or standby?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 22:38:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230087#M44279</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-10-17T22:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230089#M44280</link>
      <description>&lt;P&gt;Have you run any tcpdumps and/or traffic captures to see if the packets are reaching the gateway during the outage period?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 01:58:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230089#M44280</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-10-18T01:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230161#M44294</link>
      <description>&lt;P&gt;Sounds like a Gratuitous ARP issue (which is the default setting), do you have VMAC set on the cluster object?&amp;nbsp; That should help but if you still experience a 10-12 second delay upon failover even after setting VMAC you'll need to set portfast (NOT disable STP) on the switch ports the firewalls are connected to.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If everything is working properly, upon failover you should see the following traffic behavior:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Catastrophic Failover (active completely dies/crashes): Outage of up to 2.5 seconds&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Non-Catastrophic Failover (active interface failure, clusterXL_admin down, etc.): Outage of up to 300 milliseconds&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 15:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230161#M44294</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-10-18T15:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230164#M44295</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/84623"&gt;@TRajkumar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;makes super valid point. Can you see if below is enabled or not?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28118iAAB09199AD2394EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 15:43:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230164#M44295</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-18T15:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230169#M44296</link>
      <description>&lt;P&gt;share fw tab -t connections -s from both members at the same time.&lt;/P&gt;
&lt;P&gt;This will show if the connections are synced.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 17:41:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230169#M44296</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-10-18T17:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230196#M44301</link>
      <description>&lt;P&gt;HI Chris&lt;/P&gt;&lt;P&gt;&amp;nbsp;There is no dynamic routing.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 04:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230196#M44301</guid>
      <dc:creator>TRajkumar</dc:creator>
      <dc:date>2024-10-19T04:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230197#M44302</link>
      <description>&lt;P&gt;Dear Timothy&lt;/P&gt;&lt;P&gt;Thanks i will try this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rajkumar T&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 04:51:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230197#M44302</guid>
      <dc:creator>TRajkumar</dc:creator>
      <dc:date>2024-10-19T04:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Delay when standby member to came up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230200#M44304</link>
      <description>&lt;P&gt;Try to toggle that option and install policy and then do a failover test and see what happens. If no change, naybe open TAC case to further investigate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 13:01:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Delay-when-standby-member-to-came-up/m-p/230200#M44304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-19T13:01:39Z</dc:date>
    </item>
  </channel>
</rss>

