<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint 26000 Cluster XL Down in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251712#M49272</link>
    <description>&lt;P&gt;Make sure as Chris said that cables are connected and you see green lit up. If thats the case and you still see the same, try cphastop; cphastart and see what happens. If no change, reboot and test. If even afer that no change, please send following:&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob -l list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;cphaconf mvc&lt;/P&gt;
&lt;P&gt;From both members please.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sat, 21 Jun 2025 13:00:25 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-06-21T13:00:25Z</dc:date>
    <item>
      <title>Checkpoint 26000 Cluster XL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251706#M49267</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are doing well&lt;/P&gt;&lt;P&gt;We are migrating from old hardware to new hardware and made the new hardware ready so during migration we just need to move cables.&lt;/P&gt;&lt;P&gt;At the moment, there is only cable on SYNC and MGMT interface and no cables on data port.&lt;/P&gt;&lt;P&gt;We are seeing one of the cluster is down:&lt;/P&gt;&lt;P&gt;FW2:&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 12.12.12.1 100% ACTIVE(!) XXX-XXX-FW1&lt;BR /&gt;2 (local) 12.12.12.2 0% DOWN XXX-XXX-FW2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: LPRB, IAC&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-110205&lt;BR /&gt;State change: ACTIVE(!) -&amp;gt; DOWN&lt;BR /&gt;Reason for state change: Interface eth3-01 is down (disconnected / link down)&lt;BR /&gt;Event time: Sat Jun 21 12:09:16 2025&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 2 -&amp;gt; Member 1&lt;BR /&gt;Reason: Interface eth3-01 is down (disconnected / link down)&lt;BR /&gt;Event time: Sat Jun 21 12:10:21 2025&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 4&lt;BR /&gt;Time of counter reset: Mon Jun 16 11:24:25 2025 (reboot)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW1:&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 12.12.12.1 100% ACTIVE(!) XXX-XXX-FW1&lt;BR /&gt;2 12.12.12.2 0% DOWN XXX-XXX-FW2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: LPRB, IAC&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-110205&lt;BR /&gt;State change: ACTIVE -&amp;gt; ACTIVE(!)&lt;BR /&gt;Reason for state change: Interface eth2-04.56 is down (disconnected / link down)&lt;BR /&gt;Event time: Sat Jun 21 12:10:21 2025&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 2 -&amp;gt; Member 1&lt;BR /&gt;Reason: Interface eth3-01 is down (disconnected / link down)&lt;BR /&gt;Event time: Sat Jun 21 12:10:21 2025&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 4&lt;BR /&gt;Time of counter reset: Mon Jun 16 11:24:25 2025 (reboot)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the eth03 module and eth02 module are fibre port and last time I got to know DC engineer didn't inserted SFP on eth03-01. I got to know from them they have inserted SFP but I am waiting for pictures from them.&lt;/P&gt;&lt;P&gt;Can cluster be down if the fibre port has no SFP installed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW2:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem&lt;/P&gt;&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 2171.2 sec&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 503 sec&lt;/P&gt;&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 2392.3 sec&lt;/P&gt;&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 64955.2 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 64954.5 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 64887.4 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: Init&lt;BR /&gt;Registration number: 6&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 64882.4 sec&lt;/P&gt;&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 7&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 2169.9 sec&lt;/P&gt;&lt;P&gt;Device Name: cvpnd&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 1.4 sec&lt;/P&gt;&lt;P&gt;Device Name: DSD&lt;BR /&gt;Registration number: 9&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 439.7 sec&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW-2&lt;BR /&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;&lt;P&gt;eth3-01 (P) DOWN (867.6 secs)&lt;BR /&gt;Mgmt UP&lt;BR /&gt;Sync (S) UP&lt;BR /&gt;eth2-04.56 (P) DOWN (2351 secs)&lt;BR /&gt;bond1.50 (LS) DOWN&lt;BR /&gt;eth1-03.100 (P) DOWN (2351 secs)&lt;BR /&gt;eth2-03.54 (P) DOWN (2351 secs)&lt;BR /&gt;bond1.53 (LS) DOWN&lt;BR /&gt;eth2-03.90 (P) DOWN (2351 secs)&lt;BR /&gt;eth1-01.172 (P) DOWN (2351 secs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;============================================================================&lt;/P&gt;&lt;P&gt;FW1:&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem (non-blocking)&lt;/P&gt;&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 2406.6 sec&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 707.8 sec&lt;/P&gt;&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 1486.2 sec&lt;/P&gt;&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 2781.7 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 2780.9 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 2699.6 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: Init&lt;BR /&gt;Registration number: 6&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 2694.5 sec&lt;/P&gt;&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 7&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 2401.9 sec&lt;/P&gt;&lt;P&gt;Device Name: cvpnd&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 0.3 sec&lt;/P&gt;&lt;P&gt;Device Name: DSD&lt;BR /&gt;Registration number: 9&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 642.2 sec&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW1:&lt;/P&gt;&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;&lt;P&gt;eth3-01 (P) DOWN (962.1 secs)&lt;BR /&gt;Mgmt UP&lt;BR /&gt;Sync (S) UP&lt;BR /&gt;eth2-04.56 (P) DOWN (2472.7 secs)&lt;BR /&gt;bond1.50 (LS) DOWN&lt;BR /&gt;eth2-03.54 (P) DOWN (2472.7 secs)&lt;BR /&gt;bond1.53 (LS) DOWN&lt;BR /&gt;eth2-03.90 (P) DOWN (2472.7 secs)&lt;BR /&gt;eth1-01.172 (P) DOWN (2472.7 secs)&lt;BR /&gt;eth1-03.100 (P) DOWN (2472.7 secs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jun 2025 07:05:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251706#M49267</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-06-21T07:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 26000 Cluster XL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251707#M49268</link>
      <description>&lt;P&gt;I got the picture from DC team and SFP is installed on eth3-01 port on both firewalls&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jun 2025 07:10:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251707#M49268</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-06-21T07:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 26000 Cluster XL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251710#M49270</link>
      <description>&lt;P&gt;You said there are no data port cables connected so the cluster cannot be up.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jun 2025 11:12:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251710#M49270</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-21T11:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 26000 Cluster XL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251712#M49272</link>
      <description>&lt;P&gt;Make sure as Chris said that cables are connected and you see green lit up. If thats the case and you still see the same, try cphastop; cphastart and see what happens. If no change, reboot and test. If even afer that no change, please send following:&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob -l list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;cphaconf mvc&lt;/P&gt;
&lt;P&gt;From both members please.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jun 2025 13:00:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251712#M49272</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-21T13:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 26000 Cluster XL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251748#M49276</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;When only Sync and Mgmt are connected (which is OK when getting ready before migration), I always ignore cluster state.&lt;BR /&gt;There are no production interfaces connected, so cluster down seems to be the correct state.&lt;BR /&gt;&lt;BR /&gt;When you have migrated and all interfaces (Sync, Mgmt and production) are connected and switch ports are configured correctly cluster state should be OK. If not, then it is time to investigate.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 08:50:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251748#M49276</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-06-23T08:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 26000 Cluster XL Down</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251760#M49278</link>
      <description>&lt;P&gt;Valid points&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 10:00:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-26000-Cluster-XL-Down/m-p/251760#M49278</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-23T10:00:56Z</dc:date>
    </item>
  </channel>
</rss>

