<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10019#M91477</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks , it was VLAN issue on switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Dec 2018 09:25:42 GMT</pubDate>
    <dc:creator>Ashish_Raval</dc:creator>
    <dc:date>2018-12-07T09:25:42Z</dc:date>
    <item>
      <title>HA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10014#M91472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On issuing command cphaprob stat on firewall cluster its showing toggle status Active/Standby and Active/Down.&lt;/P&gt;&lt;P&gt;also wrp interface showing down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSECFWAESCDT301:0&amp;gt; cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: VSX High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 (local) 172.31.255.253 100% Active&lt;BR /&gt;2 172.31.255.254&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0%&amp;nbsp; &lt;STRONG&gt;Down&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;and&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSECFWAESCDT301:0&amp;gt; cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: VSX High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;Number Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 (local) 172.31.255.253 100% Active&lt;BR /&gt;2 172.31.255.254&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0%&amp;nbsp; &lt;STRONG&gt;Standby&amp;nbsp; &amp;nbsp;&amp;gt;&amp;gt; This status changing&amp;nbsp;on every&amp;nbsp;hit of command&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; cphaprob -a if&lt;/P&gt;&lt;P&gt;vsid 0:&lt;BR /&gt;------&lt;BR /&gt;Required interfaces: 11&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), broadcast&lt;BR /&gt;Mgmt UP non sync(non secured), multicast&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 1&lt;/P&gt;&lt;P&gt;Mgmt 10.34.17.169&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;vsid 1:&lt;BR /&gt;------&lt;BR /&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), broadcast&lt;BR /&gt;&lt;STRONG&gt;wrp64 Inbound: DOWN (3.1 secs) Outbound: DOWN (67706.2 secs) non sync(n on secured), multicast&lt;/STRONG&gt;&lt;BR /&gt;eth2 UP non sync(non secured), multicast (eth2.101 )&lt;BR /&gt;eth1 UP non sync(non secured), multicast (eth1.100 )&lt;BR /&gt;eth6 UP non sync(non secured), multicast (eth6.1502 )&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 16&lt;/P&gt;&lt;P&gt;wrp64 10.34.17.81&lt;BR /&gt;eth2.101 10.34.17.113&lt;BR /&gt;eth2.1530 10.34.17.129&lt;BR /&gt;eth2.1915 10.34.17.57&lt;BR /&gt;eth2.1102 10.34.17.225&lt;BR /&gt;eth2.1914 10.34.17.49&lt;BR /&gt;eth2.1550 10.34.17.145&lt;BR /&gt;eth2.1911 10.34.17.33&lt;BR /&gt;eth2.1910 10.34.17.25&lt;BR /&gt;eth2.1913 10.34.17.41&lt;BR /&gt;eth2.1250 10.34.17.193&lt;BR /&gt;eth1.100 10.34.54.1&lt;BR /&gt;eth6.1502 10.34.17.74&lt;BR /&gt;eth2.1106 10.34.17.17&lt;BR /&gt;eth2.402 10.34.17.9&lt;BR /&gt;eth2.1570 10.34.17.177&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;vsid 2:&lt;BR /&gt;------&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), broadcast&lt;BR /&gt;&lt;STRONG&gt;wrp128 Inbound: DOWN (2950 secs) Outbound: DOWN (66556.4 secs) non sync(n on secured), multicast&lt;/STRONG&gt;&lt;BR /&gt;eth3 UP non sync(non secured), multicast (eth3.1240 )&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 4&lt;/P&gt;&lt;P&gt;wrp128 10.34.17.82&lt;BR /&gt;eth3.1411 10.34.54.193&lt;BR /&gt;eth3.1240 10.34.55.1&lt;BR /&gt;eth3.1921 10.34.55.193&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;vsid 3:&lt;BR /&gt;------&lt;BR /&gt;Required interfaces: 3&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;eth5 UP non sync(non secured), multicast&lt;BR /&gt;eth4 UP non sync(non secured), multicast&lt;BR /&gt;Sync UP sync(secured), broadcast&lt;BR /&gt;wrp192 Inbound: DOWN (22816.1 secs) Outbound: DOWN (67520.4 secs) non sync(n on secured), multicast&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 3&lt;/P&gt;&lt;P&gt;eth5 10.34.17.89&lt;BR /&gt;eth4 10.34.55.217&lt;BR /&gt;wrp192 10.34.17.83&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;vsid 4:&lt;BR /&gt;------&lt;BR /&gt;VS is working as a Virtual Switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 12:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10014#M91472</guid>
      <dc:creator>Ashish_Raval</dc:creator>
      <dc:date>2018-10-25T12:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: HA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10015#M91473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any VLAN or Interface flapping occurring upstream of the Gateway with whatever network is connected to that Virtual Switch? My guess is the Cluster State is flapping because of whatever is going on in that Virtual Switch.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 13:44:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10015#M91473</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-10-25T13:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: HA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10016#M91474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like connectivity is missing between boxes on the interface that is outside of your virtual switch. I'm just guessing but all your three VSes are connected to Vswitch on this subnet&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;10.34.17.x so make sure that on physical interface you have trunk with all required VLANs configured so both boxes can see each other.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;you can add output ifconfig from VS4&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 13:49:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10016#M91474</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-10-25T13:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: HA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10017#M91475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ccp mode is broadcast for Sync but multicast for the rest? try to set CCP mode to broadcast/multicast only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2018 20:00:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10017#M91475</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-10-26T20:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: HA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10018#M91476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the same issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;once i put change the ccp to broadcast, it works like a charm.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="background-color: #ffffff; color: blue;"&gt;#cphaconf set_ccp broadcast&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2018 15:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10018#M91476</guid>
      <dc:creator>Alex_Lam1</dc:creator>
      <dc:date>2018-11-12T15:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: HA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10019#M91477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks , it was VLAN issue on switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 09:25:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-issue/m-p/10019#M91477</guid>
      <dc:creator>Ashish_Raval</dc:creator>
      <dc:date>2018-12-07T09:25:42Z</dc:date>
    </item>
  </channel>
</rss>

