<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster XL - Failover due to  Fullsync PNOTE ON in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249568#M48748</link>
    <description>&lt;P&gt;No, the CLI output is reliable. Your Sync interface is having issues that need investigating.&lt;/P&gt;</description>
    <pubDate>Thu, 22 May 2025 04:47:26 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2025-05-22T04:47:26Z</dc:date>
    <item>
      <title>Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113499#M15833</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;We faced an unexpected failover due to&amp;nbsp;Fullsync PNOTE ON&amp;nbsp; error&amp;nbsp;CLUS-120108.&lt;/P&gt;&lt;P&gt;According to SK125152&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" cellspacing="4" cellpadding="5"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;CLUS- 120108&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Fullsync PNOTE &amp;lt;ON | OFF&amp;gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;ON - problem&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the failover, I had verified that sync communication is ok and this member is in standby mode in the cluster.&lt;/P&gt;&lt;P&gt;In addition see below syncstat statistics.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="syncstat" style="width: 615px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10970i106CA84703B5BE2E/image-dimensions/615x509?v=v2" width="615" height="509" role="button" title="syncstat.png" alt="syncstat" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;syncstat&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Does anyone face the same issue? Do you know what trigger this behavior?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 09:02:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113499#M15833</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2021-03-15T09:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113800#M15881</link>
      <description>&lt;P&gt;Full sync only happens when the second member is coming from boot/initialization, and before it becomes the fully operational cluster member (usually in standby mode). Check the uptime, it seems to me one of your boxes rebooted itself.&lt;BR /&gt;&lt;BR /&gt;Also, fullsync PNOTE should not cause a failover. Please post the logs you got and full message&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 11:50:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113800#M15881</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-03-17T11:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113802#M15882</link>
      <description>&lt;P&gt;Hello Val ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Uptime is 160 days for all members of the cluster. The failover occurs on&amp;nbsp;Sun Mar 14 18:44:26 2021.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find attached&amp;nbsp;cpwd_admin list &amp;amp; messages.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 11:57:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113802#M15882</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2021-03-17T11:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113805#M15883</link>
      <description>&lt;P&gt;You did something with SNMP settings, which then called for cpstop/cpstart, which in it turn, caused Active member to go down.&lt;BR /&gt;&lt;BR /&gt;It says it right there in your messages:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs bp-is-scrollable" tabindex="0"&gt;&lt;CODE class="bp-text-code txt"&gt;Mar 14 18:44:24 2021 HQ pm[16877]: Disabled snmpd
Mar 14 18:44:24 2021 HQ xpand[16895]: Configuration changed from localhost by user admin by the service /usr/sbin/snmpd
Mar 14 18:44:24 2021 HQ snmpd: Destroying the lists of sensors
Mar 14 18:44:24 2021 HQ pm[16877]: Reaped:  snmpd[8268]
Mar 14 18:44:26 2021 HQ kernel: [fw4_1];CLUS-120108-2: Fullsync PNOTE ON
Mar 14 18:44:26 2021 HQ kernel: [fw4_1];CLUS-120130-2: cpstop
Mar 14 18:44:26 2021 HQ kernel: [fw4_1];CLUS-113500-2: State change: ACTIVE -&amp;gt; DOWN | Reason: FULLSYNC PNOTE - cpstop&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 17 Mar 2021 12:14:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113805#M15883</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-03-17T12:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113813#M15884</link>
      <description>&lt;P&gt;We did not change something manually on the SNMP configuration. I already had open a case with support and I will update the post accordingly.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 13:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113813#M15884</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2021-03-17T13:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113817#M15885</link>
      <description>&lt;P&gt;Sure, please keep us posted.&lt;BR /&gt;&lt;BR /&gt;This line, however suggests something has been done:&amp;nbsp;&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs bp-is-scrollable" tabindex="0"&gt;&lt;CODE class="bp-text-code txt"&gt;Mar 14 18:44:24 2021 HQ xpand[16895]: Configuration changed from localhost by user admin&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 17 Mar 2021 13:27:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/113817#M15885</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-03-17T13:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/114870#M16103</link>
      <description>&lt;P&gt;Hello all ,&lt;/P&gt;&lt;P&gt;The support cannot find the root cause of the issue.&lt;/P&gt;&lt;P&gt;The only suggestion that provided since the issue occurs once is to update to the latest jumbo take (we are on 78) because resolves many performance and stability issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 11:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/114870#M16103</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2021-03-29T11:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/114871#M16104</link>
      <description>&lt;P&gt;Val is definitely correct...based on that message in the logs you sent, seems that someone manually changed something in the config. Maybe try below command...cd /var/log and then run grep -i PNOTE messages.*&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 12:35:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/114871#M16104</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-29T12:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/114873#M16106</link>
      <description>&lt;P&gt;Mar 14 18:44:26 2021 HQ kernel: [fw4_1];CLUS-120108-2: Fullsync PNOTE ON&lt;BR /&gt;Mar 14 18:44:26 2021 HQ kernel: [fw4_1];CLUS-113500-2: State change: ACTIVE -&amp;gt; DOWN | Reason: FULLSYNC PNOTE - cpstop&lt;BR /&gt;Mar 14 18:44:28 2021 HQ kernel: [fw4_0];fwhak_drv_report_process_state: no running process, reporting pnote fwd&lt;BR /&gt;Mar 14 18:44:30 2021 HQ kernel: [fw4_1];CLUS-120105-2: routed PNOTE ON&lt;BR /&gt;Mar 14 18:44:31 2021 HQ kernel: [fw4_0];fwhak_drv_report_process_state: no running process, reporting pnote cphad&lt;BR /&gt;Mar 14 18:45:34 2021 HQ kernel: [fw4_1];CLUS-113601-2: State remains: INIT | Reason: FULLSYNC PNOTE - cpstart&lt;BR /&gt;Mar 14 18:45:36 2021 HQ kernel: [fw4_1];CLUS-100201-2: Failover member 2 -&amp;gt; member 1 | Reason: FULLSYNC PNOTE - cpstop&lt;BR /&gt;Mar 14 18:46:22 2021 HQ kernel: [fw4_1];CLUS-120207-2: LPRB PNOTE : local probing has started on interface bond1.399&lt;BR /&gt;Mar 14 18:46:51 2021 HQ kernel: [fw4_1];CLUS-120207-2: LPRB PNOTE : local probing has started on interface bond2&lt;BR /&gt;Mar 14 18:46:52 2021 HQ kernel: [fw4_1];CLUS-120207-2: LPRB PNOTE : local probing had stopped on interface bond2&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 13:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/114873#M16106</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2021-03-29T13:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249534#M48737</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I have an error that has to do with a VSX Cluster, which fails to "form", as apparently there is an error with the configuration, or at least is what I understand according to the following message that I have filtered.&lt;BR /&gt;It is an environment that is on VMWARE, but the interfaces of both members that make the VSX Cluster, are using the Eth2 interface as SYNC interface.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VSXLAB1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30562i474DAE2B01AA0E04/image-size/large?v=v2&amp;amp;px=999" role="button" title="VSXLAB1.jpg" alt="VSXLAB1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VSXLAB2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30561i7FA33153CE6BD463/image-size/large?v=v2&amp;amp;px=999" role="button" title="VSXLAB2.jpg" alt="VSXLAB2.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Could someone guide me on how to correct this problem?&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 17:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249534#M48737</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-05-21T17:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249559#M48746</link>
      <description>&lt;P&gt;You may need to enable promiscuous mode or like that in your VMWare environment for that virtual network segment. Something is preventing the CCP packets.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 03:02:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249559#M48746</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-05-22T03:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249566#M48747</link>
      <description>&lt;P&gt;Can the alert that one “sees” in the CLI of the VSX Cluster be a &lt;STRONG&gt;“false positive”&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;At the SmartConsole level, everything looks fine, in “green”, and the main thing, is that the VSX Cluster, does not appear “alarmed”.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VSXLAB3.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30570i0B5DA2CADE769CE0/image-size/large?v=v2&amp;amp;px=999" role="button" title="VSXLAB3.jpg" alt="VSXLAB3.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VSXLAB4.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30568i7D827C4BF2017BE2/image-size/large?v=v2&amp;amp;px=999" role="button" title="VSXLAB4.jpg" alt="VSXLAB4.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VSXLAB5.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30569iF0DD940953C9E0D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="VSXLAB5.jpg" alt="VSXLAB5.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I can install policies without errors on every 1 of my VS's that I have created, however at the CLI level, it looks like the cluster is broken.&lt;/P&gt;
&lt;P&gt;At times I see that the Eth2 interface, which is the SYNC interface, is “DOWN”, and at other times, I see what I am sharing in this update.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VSXLAB6.jpg" style="width: 512px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30571iFBFCC2291918364B/image-size/large?v=v2&amp;amp;px=999" role="button" title="VSXLAB6.jpg" alt="VSXLAB6.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 03:21:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249566#M48747</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-05-22T03:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - Failover due to  Fullsync PNOTE ON</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249568#M48748</link>
      <description>&lt;P&gt;No, the CLI output is reliable. Your Sync interface is having issues that need investigating.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 04:47:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-XL-Failover-due-to-Fullsync-PNOTE-ON/m-p/249568#M48748</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-05-22T04:47:26Z</dc:date>
    </item>
  </channel>
</rss>

