<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failover behavior in VSX environment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failover-behavior-in-VSX-environment/m-p/73519#M9370</link>
    <description>&lt;P&gt;Dear CheckMates Community,&lt;/P&gt;&lt;P&gt;coud someone of you explain how failover works in a VSX environment. As far as I know, in a non VSX default setup the first and the last VLAN on a trunk interface will be monitored. If on of this VLAN can't process CCP pakets a pnote will be genarated an failover to the other (standby) cluster member.&lt;/P&gt;&lt;P&gt;But how does it works in VSX?&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Please check below some outputs:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;vsid 5:&lt;BR /&gt;------&lt;BR /&gt;CCP mode: Manual (Broadcast)&lt;BR /&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), broadcast&lt;BR /&gt;wrp321 UP non sync(non secured), broadcast&lt;BR /&gt;wrp320 UP non sync(non secured), broadcast&lt;BR /&gt;bond3 UP non sync(non secured), broadcast, bond Load Sharing (bond3.1002)&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 9&lt;/P&gt;&lt;P&gt;wrp321 x.x.x.x&lt;BR /&gt;wrp320 192.168.x.1&lt;BR /&gt;bond2.2506 192.168.23x.46&lt;BR /&gt;bond2.1050 192.168.2x.164&lt;BR /&gt;bond2.2503 192.168.23x.22&lt;BR /&gt;bond3.1002 x.x.x.x&lt;BR /&gt;bond2.2509 192.168.23x.70&lt;BR /&gt;bond2.2505 192.168.23x.38&lt;BR /&gt;bond2.2504 192.168.23x.30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;cphaprob stat&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Cluster Mode: VSX High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 192.168.x.25 0% STANDBY fw1&lt;BR /&gt;2 (local) 192.168.x.26 100% ACTIVE fw2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-115704&lt;BR /&gt;State change: STANDBY -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: Member state has been changed due to issue in Virtual System 0&lt;BR /&gt;Event time: Tue Jan 21 11:04:26 2020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2020 08:29:49 GMT</pubDate>
    <dc:creator>Patrick150781</dc:creator>
    <dc:date>2020-01-28T08:29:49Z</dc:date>
    <item>
      <title>Failover behavior in VSX environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failover-behavior-in-VSX-environment/m-p/73519#M9370</link>
      <description>&lt;P&gt;Dear CheckMates Community,&lt;/P&gt;&lt;P&gt;coud someone of you explain how failover works in a VSX environment. As far as I know, in a non VSX default setup the first and the last VLAN on a trunk interface will be monitored. If on of this VLAN can't process CCP pakets a pnote will be genarated an failover to the other (standby) cluster member.&lt;/P&gt;&lt;P&gt;But how does it works in VSX?&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Please check below some outputs:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;vsid 5:&lt;BR /&gt;------&lt;BR /&gt;CCP mode: Manual (Broadcast)&lt;BR /&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), broadcast&lt;BR /&gt;wrp321 UP non sync(non secured), broadcast&lt;BR /&gt;wrp320 UP non sync(non secured), broadcast&lt;BR /&gt;bond3 UP non sync(non secured), broadcast, bond Load Sharing (bond3.1002)&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 9&lt;/P&gt;&lt;P&gt;wrp321 x.x.x.x&lt;BR /&gt;wrp320 192.168.x.1&lt;BR /&gt;bond2.2506 192.168.23x.46&lt;BR /&gt;bond2.1050 192.168.2x.164&lt;BR /&gt;bond2.2503 192.168.23x.22&lt;BR /&gt;bond3.1002 x.x.x.x&lt;BR /&gt;bond2.2509 192.168.23x.70&lt;BR /&gt;bond2.2505 192.168.23x.38&lt;BR /&gt;bond2.2504 192.168.23x.30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;cphaprob stat&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Cluster Mode: VSX High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 192.168.x.25 0% STANDBY fw1&lt;BR /&gt;2 (local) 192.168.x.26 100% ACTIVE fw2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-115704&lt;BR /&gt;State change: STANDBY -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: Member state has been changed due to issue in Virtual System 0&lt;BR /&gt;Event time: Tue Jan 21 11:04:26 2020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 08:29:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failover-behavior-in-VSX-environment/m-p/73519#M9370</guid>
      <dc:creator>Patrick150781</dc:creator>
      <dc:date>2020-01-28T08:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Failover behavior in VSX environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failover-behavior-in-VSX-environment/m-p/73787#M9371</link>
      <description>&lt;P&gt;Hi Patrick, I can see that you are running VSX in HA mode and not VSLS.&lt;/P&gt;
&lt;P&gt;If HA, the interface probing stays the same, cluster fails over with all VSs from one physical member to another. With VSLS, the failover happens on per VS basis, unless one of your machines is completely dead. All VLANs are probed on per VS basis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, in your case I can also see that there was an issue on VS0, meaning on the physical entity. It does not seem to be an interface failure related to VLANs, as VS0 only operates MGMT IF and Sync IF.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 16:57:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failover-behavior-in-VSX-environment/m-p/73787#M9371</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-01-30T16:57:05Z</dc:date>
    </item>
  </channel>
</rss>

