<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reason for Firewall Failover in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250363#M48947</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@firewall-01:0]# cphaprob show_failover&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: ADMIN_DOWN PNOTE&lt;BR /&gt;Event time: Fri May 30 13:26:03 2025&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 15&lt;BR /&gt;Time of counter reset: Thu Dec 26 17:03:43 2024 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cluster failover history (last 20 failovers since reboot/reset on Thu Dec 26 17:03:43 2024):&lt;/P&gt;&lt;P&gt;No. Time: Transition: CPU: Reason:&lt;BR /&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;BR /&gt;1 Fri May 30 13:26:03 2025 Member 1 -&amp;gt; Member 2 11 ADMIN_DOWN PNOTE&lt;BR /&gt;2 Wed Jan 8 11:59:48 2025 Member 1 -&amp;gt; Member 2 47 USER DEFINED PNOTE&lt;BR /&gt;3 Fri Dec 27 12:44:02 2024 Member 2 -&amp;gt; Member 1 52 ADMIN_DOWN PNOTE&lt;BR /&gt;4 Fri Dec 27 12:40:27 2024 Member 1 -&amp;gt; Member 2 12 ADMIN_DOWN PNOTE&lt;BR /&gt;5 Fri Dec 27 12:32:35 2024 Member 2 -&amp;gt; Member 1 21 ADMIN_DOWN PNOTE&lt;BR /&gt;6 Fri Dec 27 12:21:59 2024 Member 2 -&amp;gt; Member 1 22 ADMIN_DOWN PNOTE&lt;BR /&gt;7 Fri Dec 27 12:20:01 2024 Member 1 -&amp;gt; Member 2 18 ADMIN_DOWN PNOTE&lt;BR /&gt;8 Fri Dec 27 12:19:36 2024 Member 2 -&amp;gt; Member 1 27 ADMIN_DOWN PNOTE&lt;BR /&gt;9 Fri Dec 27 12:18:34 2024 Member 1 -&amp;gt; Member 2 13 ADMIN_DOWN PNOTE&lt;BR /&gt;10 Fri Dec 27 12:18:05 2024 Member 2 -&amp;gt; Member 1 13 ADMIN_DOWN PNOTE&lt;BR /&gt;11 Fri Dec 27 12:02:26 2024 Member 1 -&amp;gt; Member 2 26 ADMIN_DOWN PNOTE&lt;BR /&gt;12 Fri Dec 27 12:00:22 2024 Member 2 -&amp;gt; Member 1 49 ADMIN_DOWN PNOTE&lt;BR /&gt;13 Thu Dec 26 19:26:39 2024 Member 1 -&amp;gt; Member 2 00 Reboot&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@firewall-01:0]# cphaprob -l list | more&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 5212 sec&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 5209.7 sec&lt;/P&gt;&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 243335 sec&lt;/P&gt;&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92311e+06 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92311e+06 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92308e+06 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: Init&lt;BR /&gt;Registration number: 6&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92308e+06 sec&lt;/P&gt;&lt;P&gt;Device Name: ted&lt;BR /&gt;Registration number: 7&lt;BR /&gt;Timeout: 600 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 1.9 sec&lt;/P&gt;&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 1.20708e+06 sec&lt;/P&gt;&lt;P&gt;Device Name: DSD&lt;BR /&gt;Registration number: 9&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 5190.4 sec&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jun 2025 13:37:17 GMT</pubDate>
    <dc:creator>cassiolima</dc:creator>
    <dc:date>2025-06-02T13:37:17Z</dc:date>
    <item>
      <title>Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250342#M48931</link>
      <description>&lt;P&gt;For some reason my firewall failed over, I wanted to know why. Using the command shows this:&lt;/P&gt;&lt;P&gt;ADMIN_DOWN PNOTE&lt;/P&gt;&lt;P&gt;What does this mean?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@firewall-01:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 3.3.3.1 0% STANDBY fw-01&lt;BR /&gt;2 3.3.3.2 100% ACTIVE fw-02&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114802&lt;BR /&gt;State change: DOWN -&amp;gt; STANDBY&lt;BR /&gt;Reason for state change: There is already an ACTIVE member in the cluster (member 2)&lt;BR /&gt;Event time: Fri May 30 14:34:29 2025&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: &lt;STRONG&gt;ADMIN_DOWN PNOTE&lt;/STRONG&gt;&lt;BR /&gt;Event time: Fri May 30 13:26:03 2025&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 15&lt;BR /&gt;Time of counter reset: Thu Dec 26 17:03:43 2024 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@firewall-01:0]# cphaprob show_failover&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: &lt;STRONG&gt;ADMIN_DOWN PNOTE&lt;/STRONG&gt;&lt;BR /&gt;Event time: Fri May 30 13:26:03 2025&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 15&lt;BR /&gt;Time of counter reset: Thu Dec 26 17:03:43 2024 (reboot)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 12:01:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250342#M48931</guid>
      <dc:creator>cassiolima</dc:creator>
      <dc:date>2025-06-02T12:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250343#M48932</link>
      <description>&lt;P&gt;Actually, if I read your output correctly, there was no failover. At some point, your Standby member was down, and it came back up and assumed Standby role. Your Active GW never changed its role.&lt;BR /&gt;&lt;BR /&gt;The admin_down pnote can be triggered on standby member by many different reasons: policy installation, reboot, or a manual operation. In most of those cases, if the Active role does not move to another GW, it is perfectly normal.&lt;BR /&gt;&lt;BR /&gt;I suggest you look for more information in the following SKs:&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk125152" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk125152&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk169359" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk169359&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 12:34:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250343#M48932</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-06-02T12:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250353#M48938</link>
      <description>&lt;P&gt;&amp;nbsp;Tks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the logs :&lt;/P&gt;&lt;P&gt;May 30 13:35:58 2025 firewall-01 kernel:[fw4_1];CLUS-120200-1: Starting CUL mode because CPU-06 usage (81%) on the local member increased above the configured threshold (80%).&lt;BR /&gt;May 30 13:36:08 2025 firewall-01 kernel:[fw4_1];CLUS-120202-1: Stopping CUL mode after 10 sec (short CUL timeout), because no member reported CPU usage above the configured threshold (80%) during the last 10 sec.&lt;BR /&gt;May 30 13:37:30 2025 firewall-01 kernel:[fw4_1];CLUS-120102-1: admin_down PNOTE ON&lt;BR /&gt;May 30 13:37:30 2025 firewall-01 kernel:[fw4_1];CLUS-111400-1: State change: ACTIVE -&amp;gt; DOWN | Reason: ADMIN_DOWN PNOTE&lt;BR /&gt;May 30 13:37:30 2025 firewall-01 kernel:[fw4_1];CLUS-214704-1: Remote member 2 (state STANDBY -&amp;gt; ACTIVE) | Reason: No other ACTIVE members have been found in the cluster&lt;BR /&gt;May 30 13:37:30 2025 firewall-01 kernel:[fw4_1];CLUS-100102-1: Failover member 1 -&amp;gt; member 2 | Reason: ADMIN_DOWN PNOTE&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:06:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250353#M48938</guid>
      <dc:creator>cassiolima</dc:creator>
      <dc:date>2025-06-02T13:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250354#M48939</link>
      <description>&lt;P&gt;Please run below command and send what it shows.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob show_failover&lt;/P&gt;
&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 0&lt;BR /&gt;Time of counter reset: Sun Jun 1 18:16:45 2025 (reboot)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cluster failover history (last 20 failovers since reboot/reset on Sun Jun 1 18:16:45 2025):&lt;/P&gt;
&lt;P&gt;No. Time: Transition: CPU: Reason:&lt;BR /&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;/P&gt;
&lt;P&gt;No failover was detected since last reboot/reset&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]#&lt;/P&gt;
&lt;P&gt;As Val said, that message can mean it was triggered by any of below:&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob -l list | more&lt;/P&gt;
&lt;P&gt;Built-in Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Registered Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 50675.8 sec&lt;/P&gt;
&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 50673.9 sec&lt;/P&gt;
&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 53264 sec&lt;/P&gt;
&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 53316.1 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 53315.5 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: 30 sec&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:08:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250354#M48939</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T13:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250363#M48947</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@firewall-01:0]# cphaprob show_failover&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: ADMIN_DOWN PNOTE&lt;BR /&gt;Event time: Fri May 30 13:26:03 2025&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 15&lt;BR /&gt;Time of counter reset: Thu Dec 26 17:03:43 2024 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cluster failover history (last 20 failovers since reboot/reset on Thu Dec 26 17:03:43 2024):&lt;/P&gt;&lt;P&gt;No. Time: Transition: CPU: Reason:&lt;BR /&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;BR /&gt;1 Fri May 30 13:26:03 2025 Member 1 -&amp;gt; Member 2 11 ADMIN_DOWN PNOTE&lt;BR /&gt;2 Wed Jan 8 11:59:48 2025 Member 1 -&amp;gt; Member 2 47 USER DEFINED PNOTE&lt;BR /&gt;3 Fri Dec 27 12:44:02 2024 Member 2 -&amp;gt; Member 1 52 ADMIN_DOWN PNOTE&lt;BR /&gt;4 Fri Dec 27 12:40:27 2024 Member 1 -&amp;gt; Member 2 12 ADMIN_DOWN PNOTE&lt;BR /&gt;5 Fri Dec 27 12:32:35 2024 Member 2 -&amp;gt; Member 1 21 ADMIN_DOWN PNOTE&lt;BR /&gt;6 Fri Dec 27 12:21:59 2024 Member 2 -&amp;gt; Member 1 22 ADMIN_DOWN PNOTE&lt;BR /&gt;7 Fri Dec 27 12:20:01 2024 Member 1 -&amp;gt; Member 2 18 ADMIN_DOWN PNOTE&lt;BR /&gt;8 Fri Dec 27 12:19:36 2024 Member 2 -&amp;gt; Member 1 27 ADMIN_DOWN PNOTE&lt;BR /&gt;9 Fri Dec 27 12:18:34 2024 Member 1 -&amp;gt; Member 2 13 ADMIN_DOWN PNOTE&lt;BR /&gt;10 Fri Dec 27 12:18:05 2024 Member 2 -&amp;gt; Member 1 13 ADMIN_DOWN PNOTE&lt;BR /&gt;11 Fri Dec 27 12:02:26 2024 Member 1 -&amp;gt; Member 2 26 ADMIN_DOWN PNOTE&lt;BR /&gt;12 Fri Dec 27 12:00:22 2024 Member 2 -&amp;gt; Member 1 49 ADMIN_DOWN PNOTE&lt;BR /&gt;13 Thu Dec 26 19:26:39 2024 Member 1 -&amp;gt; Member 2 00 Reboot&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@firewall-01:0]# cphaprob -l list | more&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 5212 sec&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 5209.7 sec&lt;/P&gt;&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 243335 sec&lt;/P&gt;&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92311e+06 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92311e+06 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92308e+06 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: Init&lt;BR /&gt;Registration number: 6&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 3.92308e+06 sec&lt;/P&gt;&lt;P&gt;Device Name: ted&lt;BR /&gt;Registration number: 7&lt;BR /&gt;Timeout: 600 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 1.9 sec&lt;/P&gt;&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 1.20708e+06 sec&lt;/P&gt;&lt;P&gt;Device Name: DSD&lt;BR /&gt;Registration number: 9&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 5190.4 sec&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:37:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250363#M48947</guid>
      <dc:creator>cassiolima</dc:creator>
      <dc:date>2025-06-02T13:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250384#M48953</link>
      <description>&lt;P&gt;Seems like whatever was down recovered very quick.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 20:03:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/250384#M48953</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T20:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/269855#M53422</link>
      <description>&lt;P&gt;Seeing a gateway report as "down" would normally tell me it is incapable of becoming active.&amp;nbsp; Is there a simple way to make this gateway go from "down" to "standby"?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 04:52:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/269855#M53422</guid>
      <dc:creator>jimm</dc:creator>
      <dc:date>2026-02-06T04:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/269889#M53425</link>
      <description>&lt;P&gt;You will need to resolve whatever pnote / condition that is causing it be down. If you can share the common cluster outputs (perhaps in a new thread)&amp;nbsp; we can guide accordingly.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 12:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/269889#M53425</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-02-06T12:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Reason for Firewall Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/269890#M53426</link>
      <description>&lt;P&gt;Put it this way. Simplest way could be reboot of that firewall, but even that is not guarantee it would work. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;said, you need to check what pnote is causing the issue.&lt;/P&gt;
&lt;P&gt;Please send output from below commands from expert mode:&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob -l list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 12:33:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reason-for-Firewall-Failover/m-p/269890#M53426</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-06T12:33:25Z</dc:date>
    </item>
  </channel>
</rss>

