<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cluster xl start time after reboot in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cluster-xl-start-time-after-reboot/m-p/8767#M471</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upon the recovery of a cluster member, there is an extended handshake between the two cluster members that may take awhile and includes a full sync.&amp;nbsp; After a reboot and while the recovered member is still showing "Down", what do these commands show:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cphaprob -a if&lt;/P&gt;&lt;P&gt;cphaprob -ia list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are likely to see something called a "Recovery Delay" in the output of the second command, which is more or less equivalent to a VRRP Cold Start Delay.&amp;nbsp; It is also possible the first command will show one or more interfaces as "Down" due to STP delays in your switchports, but that shouldn't last anywhere close to 5 minutes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the following for more info:&amp;nbsp; &lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92353&amp;amp;partition=Advanced&amp;amp;product=VSX," style="max-width: 840px;"&gt;sk92353: Output of 'cphaprob -ia list' on &lt;STRONG&gt;ClusterXL&lt;/STRONG&gt; shows a Critical Device called 'Recovery Delay'&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Nov 2017 12:08:24 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2017-11-03T12:08:24Z</dc:date>
    <item>
      <title>cluster xl start time after reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cluster-xl-start-time-after-reboot/m-p/8765#M469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently testing a new R80.10 ClusterXL based firewall cluster and notice the following:&lt;/P&gt;&lt;P&gt;When rebooting one of the cluster member&amp;nbsp;the Cluster XL status&amp;nbsp; of that member is around 5 minutes in down before it moves over to Standby state:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cphaprob state&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 192.168.1.2 100% Active&lt;BR /&gt;2 (local) 192.168.1.3 0% Down&lt;/P&gt;&lt;P&gt;Local member is in current state since Thu Nov 2 21:22:55 2017&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 192.168.1.2 100% Active&lt;BR /&gt;2 (local) 192.168.1.3 0% Standby&lt;/P&gt;&lt;P&gt;Local member is in current state since Thu Nov 2 21:28:26 2017&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this normal behavior ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards, Rob.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 20:56:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cluster-xl-start-time-after-reboot/m-p/8765#M469</guid>
      <dc:creator>Rob_Gaal</dc:creator>
      <dc:date>2017-11-02T20:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl start time after reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cluster-xl-start-time-after-reboot/m-p/8766#M470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the surface, that seems reasonable.&lt;/P&gt;&lt;P&gt;Before a cluster member is actually up and ready to accept traffic, the various processes have to be started, the security policy loaded, and connections from the other active system synced.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Nov 2017 06:18:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cluster-xl-start-time-after-reboot/m-p/8766#M470</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-03T06:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl start time after reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cluster-xl-start-time-after-reboot/m-p/8767#M471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upon the recovery of a cluster member, there is an extended handshake between the two cluster members that may take awhile and includes a full sync.&amp;nbsp; After a reboot and while the recovered member is still showing "Down", what do these commands show:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cphaprob -a if&lt;/P&gt;&lt;P&gt;cphaprob -ia list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are likely to see something called a "Recovery Delay" in the output of the second command, which is more or less equivalent to a VRRP Cold Start Delay.&amp;nbsp; It is also possible the first command will show one or more interfaces as "Down" due to STP delays in your switchports, but that shouldn't last anywhere close to 5 minutes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the following for more info:&amp;nbsp; &lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92353&amp;amp;partition=Advanced&amp;amp;product=VSX," style="max-width: 840px;"&gt;sk92353: Output of 'cphaprob -ia list' on &lt;STRONG&gt;ClusterXL&lt;/STRONG&gt; shows a Critical Device called 'Recovery Delay'&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Nov 2017 12:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/cluster-xl-start-time-after-reboot/m-p/8767#M471</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-03T12:08:24Z</dc:date>
    </item>
  </channel>
</rss>

