<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R82 ElasticXL &amp;amp; VSNext Issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252210#M49385</link>
    <description>&lt;P&gt;Not entirely sure why, but I did a policy push just to see what it would do to the status, and it actually fixed the status issue:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1 (local) 192.0.2.1 100% ACTIVE(P) VWGCOREFW-s01-01&lt;BR /&gt;15 192.0.2.15 100% ACTIVE VWGCOREFW-s02-01&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114904&lt;BR /&gt;State change: ACTIVE(!) -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: Reason for ACTIVE! alert has been resolved&lt;BR /&gt;Event time: Sun Jun 29 20:46:06 2025&lt;BR /&gt;&lt;BR /&gt;The interface counts on both nodes remains the same though.&amp;nbsp; I believe the status of "Active(P)" is normal indicating this is the pivot node.&lt;/P&gt;</description>
    <pubDate>Sun, 29 Jun 2025 19:51:20 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2025-06-29T19:51:20Z</dc:date>
    <item>
      <title>R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251796#M49285</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Built a R82 ElasticXL &amp;amp; VSNext Lab in Proxmox, JHFA installed is Take 25&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- I managed to delete ID0/VS0 which I should never be able to do.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- reassign magg1 from vs500 so in affect knocking at management, again should not be able to do this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you have had similar issues please post and hopefully Checkpoint can review and respond.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I had one other issue where I created a virtual gateway through gclish however for some reason I could not connect to the management interface on the VG. So attempted to delete via GUI and then the system crashed.&amp;nbsp; I've logged a TAC case to investigate the crash logs.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 17:01:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251796#M49285</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-23T17:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251797#M49286</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I assume this is related to R82 jumbo 25 thread?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 17:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251797#M49286</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-23T17:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251832#M49294</link>
      <description>&lt;P data-start="0" data-end="194"&gt;Hey,&lt;BR data-start="61" data-end="64" /&gt;You're right, we haven't blocked deletion from the WebUI.&lt;BR data-start="125" data-end="128" /&gt;magg1 can be reassigned under the customer's responsibility.&lt;/P&gt;
&lt;P data-start="196" data-end="402"&gt;I'd like to check the logs for your issue, as we didn’t observe it on our end.&lt;BR data-start="278" data-end="281" /&gt;Also, Take 25 is not recommended for VSNext, as we've encountered issues establishing SIC with the management server.&lt;/P&gt;
&lt;P data-start="196" data-end="402"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="196" data-end="402"&gt;Thanks,&lt;/P&gt;
&lt;P data-start="196" data-end="402"&gt;Matan&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 05:05:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251832#M49294</guid>
      <dc:creator>matanbe_chkpcp</dc:creator>
      <dc:date>2025-06-24T05:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251846#M49297</link>
      <description>&lt;P&gt;Hi Matan,&lt;/P&gt;
&lt;P&gt;Happy to jump on a webex with you if you like.&amp;nbsp; I have snapshots so at least I've got to the point I don't need to do a complete rebuild.&lt;/P&gt;
&lt;P&gt;Yesterday re-created a virtual gateway and lost connectivity again.&amp;nbsp;&lt;BR /&gt;In my mind some of these issues must be to do with setting this up in Proxmox, but thats only a guess.&amp;nbsp; It would be really good to get Checkpoint to actually confirm how we should actually lab this in VMWare Workstation or Proxmox as I think it will help allot of people out with learning and adoption.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 08:29:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251846#M49297</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-24T08:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251849#M49298</link>
      <description>&lt;P&gt;Yes Mate.&lt;/P&gt;
&lt;P&gt;As advised by Chris just thought I would create a separate thread so it can be used by us all.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 08:45:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251849#M49298</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-24T08:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251855#M49301</link>
      <description>&lt;P&gt;Got it. Let us know if you end up doing remote with Matan and how it goes.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 10:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251855#M49301</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-24T10:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251859#M49304</link>
      <description>&lt;P data-start="0" data-end="63"&gt;Hey,&lt;/P&gt;
&lt;P data-start="65" data-end="283"&gt;Currently, we don't support Proxmox as a VM platform — we only support VMware.&lt;BR data-start="147" data-end="150" /&gt;I'll send you a private message to schedule a meeting, understand the requirements, and see if we can find a workable solution.&lt;/P&gt;
&lt;P data-start="285" data-end="308"&gt;Thanks,&lt;BR data-start="296" data-end="299" /&gt;Matan&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 10:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251859#M49304</guid>
      <dc:creator>matanbe_chkpcp</dc:creator>
      <dc:date>2025-06-24T10:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251860#M49305</link>
      <description>&lt;P&gt;Thanks Matan&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 10:50:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251860#M49305</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-24T10:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251862#M49307</link>
      <description>&lt;P&gt;Hey Matan,&lt;/P&gt;
&lt;P&gt;I suppose same applies to eve-ng as well?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 11:10:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251862#M49307</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-24T11:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251894#M49326</link>
      <description>&lt;P&gt;We don't do any internal testing on eve-ng that I'm aware of.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251894#M49326</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-24T15:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251897#M49327</link>
      <description>&lt;P&gt;It's also not supported as outlined in sk181128.&lt;/P&gt;
&lt;P&gt;PMTR-107075 ElasticXL ElasticXL Cluster supports only physical Check Point appliances (Virtual Machines or Open Servers are not supported).&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:12:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251897#M49327</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-24T15:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251898#M49328</link>
      <description>&lt;P&gt;Thanks Chris. I somehow missed that in the sk.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:13:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251898#M49328</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-24T15:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251971#M49351</link>
      <description>&lt;P&gt;Thanks for jumping on with me Matan.&amp;nbsp; I've pinged over some more observations to you, if they are valid happy to post here as well, if it helps.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 14:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251971#M49351</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-25T14:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251972#M49352</link>
      <description>&lt;P&gt;Observation - which is not an issue but something I'm not sure is documented anywhere:&lt;BR /&gt;tp_dummy_5 Link encap:Ethernet HWaddr xx:xx:xx:BD:90:7E&lt;BR /&gt;inet addr:99.81.112.231 Bcast:0.0.0.0 Mask:255.255.255.255&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The above interface appears when turning on TP (I've not turned off the blades to check to see which one actually creates this).&amp;nbsp; The same interface and IP is present on different VSs.&amp;nbsp; Why is this there (especially with a public IP) and what is its function?&amp;nbsp; How is this secured (its not seen in the topology) and what communications requirements does it have to Checkpoint?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 14:41:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/251972#M49352</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-25T14:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252076#M49366</link>
      <description>&lt;P&gt;Found another issue (not really sure if it is), when clustering, JHFA applied to active node is replicated to standby node, however in the cluster management section the standby device does not show the JHFA is installed, even if it becomes the active device.&lt;BR /&gt;&lt;BR /&gt;That may be more of a known issue, but thought I would mention it.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 16:46:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252076#M49366</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-26T16:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252197#M49378</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;We are aware of this issue and it will be addressed in the upcoming Jumbos.&lt;/P&gt;
&lt;P&gt;I'll review your private messages.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2025 11:33:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252197#M49378</guid>
      <dc:creator>matanbe_chkpcp</dc:creator>
      <dc:date>2025-06-29T11:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252198#M49379</link>
      <description>&lt;P&gt;Great thanks Matan.&lt;/P&gt;
&lt;P&gt;Issue I have now is cphaprob reports (Active!P) status, however not entirely sure how I check the interface status on the standby member as you can't access it once its in a cluster?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2025 11:39:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252198#M49379</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-29T11:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252199#M49380</link>
      <description>&lt;P&gt;You can always move between members using "m &amp;lt;site_id&amp;gt;_&amp;lt;member_id&amp;gt;", for example - m 1_2.&lt;/P&gt;
&lt;P&gt;What is the error shown on cphaprob stat?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2025 11:46:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252199#M49380</guid>
      <dc:creator>matanbe_chkpcp</dc:creator>
      <dc:date>2025-06-29T11:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252200#M49381</link>
      <description>&lt;P&gt;Here what I see at the moment:&lt;/P&gt;
&lt;P&gt;# cphaprob stat&lt;/P&gt;
&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;
&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;
&lt;P&gt;1 (local) 192.0.2.1 100% ACTIVE(!P) FW-s01-01&lt;BR /&gt;15 192.0.2.15 100% ACTIVE FW-s02-01&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: IAC&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-110805&lt;BR /&gt;State change: ACTIVE -&amp;gt; ACTIVE(!)&lt;BR /&gt;Reason for state change: Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)&lt;BR /&gt;Event time: Sun Jun 29 15:10:06 2025&lt;BR /&gt;&lt;BR /&gt;I switched between the two nodes now and checked cphaprob -a if on the different VS's, can't really see any issue.&lt;/P&gt;
&lt;P&gt;When issuing m &amp;lt;1_1&amp;gt; or &amp;lt;2_1&amp;gt; is this connect going over the Sync network.&amp;nbsp; I believe it is, so just wanted confirm this is the transport between the two nodes and not the management interfaces?&lt;BR /&gt;&lt;BR /&gt;Question:&lt;BR /&gt;How would be monitor both nodes using a NMS? Normally I would just point the NMS to the Mgmt IP of each node, so I assume there must be a way to monitor both nodes using SNMP v3?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2025 14:24:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252200#M49381</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-06-29T14:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: R82 ElasticXL &amp; VSNext Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252203#M49383</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5933"&gt;@genisis__&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;When issuing m &amp;lt;1_1&amp;gt; or &amp;lt;2_1&amp;gt; is this connect going over the Sync network.&amp;nbsp; I believe it is, so just wanted confirm this is the transport between the two nodes and not the management interfaces?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Yes, it goes over sync. It's a key-based SSH connection:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[Expert@DallasticXL-s01-01:0]# m 2
Moving to member 1_2

This system is for authorized use only.
Last login: Mon Jun  9 21:35:55 2025 from 192.0.2.1
[Expert@DallasticXL-s01-02:0]# who
admin    pts/1        Jun 29 17:28 (192.0.2.1)

[Expert@DallasticXL-s01-02:0]# netstat -anp | grep sshd
tcp        0      0 0.0.0.0:22                  0.0.0.0:*                   LISTEN      20160/sshd          
tcp        0      0 192.0.2.2:22                192.0.2.1:33556             ESTABLISHED 4843/sshd: admin [p 
unix  2      [ ]         DGRAM                    4266141855 4843/sshd: admin [p 
unix  3      [ ]         STREAM     CONNECTED     4266141861 4843/sshd: admin [p 
unix  2      [ ]         STREAM     CONNECTED     4266141839 4843/sshd: admin [p 

[Expert@DallasticXL-s01-02:0]# egrep "^$(date +"%b %e") " /var/log/secure
Jun 29 17:28:56 2025 DallasticXL-s01-02 sshd[4843]: Accepted publickey for admin from 192.0.2.1 port 33556 ssh2: RSA SHA256:+gbwzSST0ECeJLtwXYXcONnH//hQ32wOgoK82WjFekg
Jun 29 17:28:56 2025 DallasticXL-s01-02 sshd[4843]: pam_unix(sshd:session): session opened for user admin by (uid=0)
Jun 29 17:28:56 2025 DallasticXL-s01-02 sudo:    admin : TTY=pts/1 ; PWD=/home/admin ; USER=root ; COMMAND=validate&lt;/LI-CODE&gt;
&lt;P&gt;Incidentally, the private key which authenticates this connection is in /home/admin/.ssh/id_rsa, and it doesn't have a passphrase. Each member of the ElasticXL cluster appears to generate a new RSA key pair when it joins, and the public keys of all members go in /home/admin/.ssh/authorized_keys, which is synchronized to all members, so they all trust each other.&lt;/P&gt;
&lt;P&gt;All of this has some pretty significant security implications. For example, if someone has administrative access to an ElasticXL cluster member, they can exfiltrate one of these keys which will ensure they continue to have direct access to the shared user "admin". I'm not yet sure if the keys are used for anything else which could complicate rotating them when an admin leaves the company.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2025 17:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-ElasticXL-amp-VSNext-Issues/m-p/252203#M49383</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-06-29T17:55:32Z</dc:date>
    </item>
  </channel>
</rss>

