<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.40 5400 Cluster - HA module not started in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97084#M7526</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thanks for your information, I am opening a TAC case.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mladen&lt;/P&gt;</description>
    <pubDate>Sun, 20 Sep 2020 13:57:03 GMT</pubDate>
    <dc:creator>MladenAntesevic</dc:creator>
    <dc:date>2020-09-20T13:57:03Z</dc:date>
    <item>
      <title>R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97018#M7514</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We've configured 5400 cluster (HA) with two gateways and we have several VLAN subinterfaces both on a bond and on the physical interfaces. After rebooting the gateways the cluster is not started and we are getting following error message:&lt;/P&gt;&lt;P&gt;[Expert@CP-2:0]# cphaprob state&lt;/P&gt;&lt;P&gt;HA module not started.&lt;/P&gt;&lt;P&gt;(The same error message on both gateways)&lt;/P&gt;&lt;P&gt;We had to manualy start cluster with the command: cphastart on both gateways after each reboot.&lt;/P&gt;&lt;P&gt;We found following sk165073 saying that it could be a problem if there is a lot of non-monitored interfaces in a cluster. (by default not all VLAN subinterfaces are monitored)&lt;BR /&gt;We configured following fw kernel parameter in order to monitor all VLAN interfaces also:&lt;/P&gt;&lt;P&gt;[Expert@CP-1:0]# cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;fwha_monitor_all_vlan = 1&lt;/P&gt;&lt;P&gt;on both our gateways bu the same issue remains, the cluster is not automatically started after the reboot and has to be manually started on both gateways.&lt;BR /&gt;Please if you have some idea how to resolve this cluster issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Here is the detail command output:&lt;/P&gt;&lt;P&gt;[Expert@CP-2:0]# fw ctl get int fwha_monitor_all_vlan&lt;BR /&gt;fwha_monitor_all_vlan = 1&lt;BR /&gt;[Expert@CP-2:0]# cphaprob state&lt;/P&gt;&lt;P&gt;HA module not started.&lt;/P&gt;&lt;P&gt;[Expert@CP-2:0]# cphastart&lt;BR /&gt;[Expert@CP-2:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 10.255.253.1 100% ACTIVE CP1&lt;BR /&gt;2 (local) 10.255.253.2 0% STANDBY CP2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114802&lt;BR /&gt;State change: DOWN -&amp;gt; STANDBY&lt;BR /&gt;Reason for state change: There is already an ACTIVE member in the cluster (member 1)&lt;BR /&gt;Event time: Fri Sep 18 13:27:35 2020&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 0&lt;BR /&gt;Time of counter reset: Fri Sep 18 13:21:46 2020 (reboot)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@CP-2:0]# cphaprob -a -m if&lt;/P&gt;&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 11&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;&lt;P&gt;eth5 UP&lt;BR /&gt;bond1 (LS) UP&lt;BR /&gt;bond5 (S-LS) UP&lt;BR /&gt;bond4.172 (LS) UP&lt;BR /&gt;bond4.20 (LS) UP&lt;BR /&gt;bond4.60 (LS) UP&lt;BR /&gt;eth6.164 UP&lt;BR /&gt;eth6.166 UP&lt;BR /&gt;bond4.113 (LS) UP&lt;BR /&gt;eth6.165 UP&lt;BR /&gt;bond4.10 (LS) UP&lt;/P&gt;&lt;P&gt;S - sync, LM - link monitor, HA/LS - bond type&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 10&lt;/P&gt;&lt;P&gt;eth5&lt;BR /&gt;bond1&lt;BR /&gt;bond4.172&lt;BR /&gt;bond4.20&lt;BR /&gt;bond4.60&lt;BR /&gt;eth6.164&lt;BR /&gt;eth6.166&lt;BR /&gt;bond4.113&lt;BR /&gt;eth6.165&lt;BR /&gt;bond4.10&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Monitoring mode is "Monitor all VLANs": All VLANs are monitored&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 12:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97018#M7514</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-09-18T12:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97037#M7517</link>
      <description>&lt;P&gt;Did you check the state of the cluster in cpconfig?&lt;/P&gt;
&lt;P&gt;When the first time wizard on these systems was run before they were to be a cluster member and the membership question was answered with No, then cluster membership is not turned on in cpconfig.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 21:13:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97037#M7517</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-09-18T21:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97038#M7518</link>
      <description>&lt;P&gt;Hi Maarten,&lt;BR /&gt;yes, I was very careful about declaring my gateways as cluster members during the first setup wizard. I am pretty sure I have enabled Cluster membership. Anyway, my cluster is working if I manualy start cphastart after the gateway reboot. I believe my cluster setup is fine, since I have done several cluster setups recently.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 21:20:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97038#M7518</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-09-18T21:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97052#M7520</link>
      <description>&lt;P&gt;Maybe the issue from&amp;nbsp;&lt;SPAN&gt;sk98977 ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Sep 2020 14:18:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97052#M7520</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-09-19T14:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97065#M7521</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I see it now, I did not have matching hostnames in the SmartConsole and on the corresponding gateways. Now I have changed hostnames on the gateways so they are identical to gateways hostnames in the SmartConsole, but the problem still remains, I still have&amp;nbsp;&lt;SPAN&gt;HA module not started after the gateways reboot, still have to manually start the cphastart.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Sep 2020 22:53:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97065#M7521</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-09-19T22:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97073#M7523</link>
      <description>&lt;P&gt;I can confirm exactly the same issue on R80.30&amp;nbsp; 3.10 kernel on 16000 appliances with latest HFA.&lt;/P&gt;
&lt;P&gt;After reboot/cprestart, following services are not started (based on "cpwd_admin list" output):&lt;/P&gt;
&lt;P&gt;cphamset -d&lt;/P&gt;
&lt;P&gt;rtmd&lt;/P&gt;
&lt;P&gt;CPUSE agent (DAservices)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you try to install policy once you get "HA not started" ?&lt;/P&gt;
&lt;P&gt;Did you try to disable CCP encryption on both gateways ?&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 06:13:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97073#M7523</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2020-09-20T06:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97081#M7524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/45729"&gt;@MladenAntesevic&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;same issue with 6000 and 3.10 kernel.&lt;/P&gt;&lt;P&gt;Open a TAC case.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 13:19:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97081#M7524</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-09-20T13:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97083#M7525</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Jozko Mrkvicka,&lt;/P&gt;&lt;P&gt;CCP encryption is disabled by default I have not changed it, so it is already disabled on both my gateways:&lt;/P&gt;&lt;P&gt;cphaprob ccp_encrypt&lt;/P&gt;&lt;P&gt;OFF&lt;/P&gt;&lt;P&gt;I also compared outputs from&amp;nbsp;&lt;SPAN&gt;cpwd_admin list before and after a reboot and I see cphamset -d service is missing in my case after a reboot. So, probably there is some issue why cphamset is not starting after a reboot.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One funny thing, I also tried a policy install after reboot and it is working, even my cluster is established if I do policy install, it has the same effect as if I do manual cphastart on my gateways.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Mladen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 13:52:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97083#M7525</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-09-20T13:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97084#M7526</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thanks for your information, I am opening a TAC case.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mladen&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 13:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97084#M7526</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-09-20T13:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97100#M7534</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/45729"&gt;@MladenAntesevic&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another idea!&lt;/P&gt;
&lt;P&gt;Have a look if the following parameter is set:&lt;/P&gt;
&lt;P&gt;/etc/fw.boot/ha_boot.conf&lt;BR /&gt;ha_installed 1&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 18:12:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97100#M7534</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-09-20T18:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97111#M7544</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, this option is set on my both gateways, this is the complete output:&lt;/P&gt;&lt;P&gt;cat /etc/fw.boot/ha_boot.conf&lt;BR /&gt;ha_installed 1&lt;BR /&gt;fw1_build 994000685&lt;BR /&gt;release R80.40&lt;BR /&gt;take 294&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything looks fine. Please, explain to me what is your idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mladen&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 21:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97111#M7544</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-09-20T21:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 5400 Cluster - HA module not started</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97169#M7547</link>
      <description>&lt;P&gt;I am very sory for inconvenience,&amp;nbsp; seems that last hotfix solves this problem. I just have installed&amp;nbsp; HOTFIX_R80_40_JUMBO_HF_MAIN Take: 78&lt;/P&gt;&lt;P&gt;and my cluster now works fine, it is normally UP after the reboot.&lt;/P&gt;&lt;P&gt;Thank you all for supporting me.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 09:56:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-5400-Cluster-HA-module-not-started/m-p/97169#M7547</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-09-21T09:56:07Z</dc:date>
    </item>
  </channel>
</rss>

