<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sync Bond issue during VSX upgrade in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71324#M9602</link>
    <description>First thing to check is what the cluster sync is set to on both members, multicast, broadcast, unicast or auto, just make sure they are both set to the same.&lt;BR /&gt;As long as this is not production I would make member 2 the only active, by cpstop on member 1 and continue the upgrade there.&lt;BR /&gt;I have seen similar issues with clusterXL on VSX before where I had a clean install that during the vsxt_util reconfigure took over from the active member.&lt;BR /&gt;</description>
    <pubDate>Sun, 29 Dec 2019 18:34:08 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-12-29T18:34:08Z</dc:date>
    <item>
      <title>Sync Bond issue during VSX upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71319#M9601</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm currently trying to upgrade our (fortunately not yet productive) VSX environment from 80.20 to 80.30 via "Connectivity Upgrade".&lt;/P&gt;&lt;P&gt;Unfortunately I ran into an issue, that causes me some pain and I don't know how to proceed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following situation:&lt;/P&gt;&lt;P&gt;The both VSX Gateways are connected via Sync-Bond (bond2 - two direct cables running between them, no switches involved).&lt;/P&gt;&lt;P&gt;After I followed the instructions from "Installation an Upgrade Guide R80.30" for "Connectivity Upgrade of a VSX Cluster" until step 4, where I upgraded the standby member to R80.30 via clish CPUSE. At that moment, I realised that the status of the members is not as expected.&lt;/P&gt;&lt;P&gt;As far as I understood, the primary member should stay "ACTIVE", whereas the upgraded one should go in a "READY" state.&lt;/P&gt;&lt;P&gt;In my case, they seem to have lost the sync between them, so both sides are now active:&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Member 1 (not upgraded):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Member 2 (upgraded):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I check the "cphaprob -a if" on the members, I see some strange behavior. Member 1 is constantly transitioning from up to down:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you repeat the command in short intervals, you see the timer going up to 5 seconds, then suddenly the status changes to following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the next iteration is "DOWN" again.&lt;/P&gt;&lt;P&gt;On the other member (upgraded) the status is constantly at "Inbound: UP&amp;nbsp; - Outbound: DOWN"&lt;/P&gt;&lt;P&gt;The cabling was left untouched, the bond config seems OK on both sides.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure how to proceed further. I considered this as a connectivity-upgrade test before everything goes into production, but in that case it failed completely...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 12:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71319#M9601</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2020-06-29T12:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Bond issue during VSX upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71324#M9602</link>
      <description>First thing to check is what the cluster sync is set to on both members, multicast, broadcast, unicast or auto, just make sure they are both set to the same.&lt;BR /&gt;As long as this is not production I would make member 2 the only active, by cpstop on member 1 and continue the upgrade there.&lt;BR /&gt;I have seen similar issues with clusterXL on VSX before where I had a clean install that during the vsxt_util reconfigure took over from the active member.&lt;BR /&gt;</description>
      <pubDate>Sun, 29 Dec 2019 18:34:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71324#M9602</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-12-29T18:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Bond issue during VSX upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71326#M9603</link>
      <description>&lt;P&gt;Thanks Maarten,&lt;/P&gt;&lt;P&gt;I've checked that on both sides and configured both of them to broadcast, but that didn't resolve the issue.&lt;/P&gt;&lt;P&gt;I then rebooted member1 just out of frustration.&lt;/P&gt;&lt;P&gt;Now the status on member2 is "READY" and "cphaprob -a if" shows bond2 constantly UP,&amp;nbsp; but on member1 it is constantly "Inbound UP - Outbound DOWN".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then found sk65560 describing all the possible causes and solutions, but none of them seems plausible:&lt;/P&gt;&lt;DIV class="solutionFieldDiv cp_h2_black"&gt;&lt;EM&gt;Cause&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV class="solutionEditableField cp_text"&gt;&lt;P&gt;&lt;EM&gt;Physical/Logical connectivity issue due to one of the following:&lt;/EM&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRIKE&gt;&lt;EM&gt;Bad switch configuration (factors such as: Speed, Duplex, Flow Control, etc).&lt;/EM&gt;&lt;/STRIKE&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRIKE&gt;&lt;EM&gt;Bad network cable.&lt;/EM&gt;&lt;/STRIKE&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRIKE&gt;&lt;EM&gt;Bad switch port (if it is a copper port, verify that that are no bent or missing pins&amp;nbsp;in the socket).&lt;/EM&gt;&lt;/STRIKE&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRIKE&gt;&lt;EM&gt;High latency on switch (switch might be under heavy load or have poor connection).&amp;nbsp;&lt;/EM&gt;&lt;/STRIKE&gt; -&amp;gt; &lt;FONT color="#FF9900"&gt;No switches involved&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Bad port on appliance (if it is a copper port, verify that there are no bent or missing pins in the socket). -&amp;gt; &lt;FONT color="#FF9900"&gt;not likely, before starting the upgrade everything was fine.&amp;nbsp;&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Subnet mis-match between cluster members on the interface shown to have the issue. -&amp;gt; &lt;FONT color="#FF9900"&gt;No, both are in the same subnet:192.168.191.1/2&amp;nbsp;&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Mismatch in monitor mode - monitor mode is not supported in ClusterXL -&amp;gt; &lt;FONT color="#FF9900"&gt;monitor mode not in use&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Anti-Spoofing is not configured correctly. -&amp;gt; &lt;FONT color="#FF9900"&gt;For Sync interface Anti-Spoofing isn't configurable (at least from SC)&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;IGMP Membership issues (often occurs with Nexus switches) -&amp;gt; &lt;FONT color="#FF9900"&gt;no switches used, direct connection&amp;nbsp;&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Network Adapter LAN segment (when working with Virtual Machines) are mismatched between cluster members. -&amp;gt; &lt;FONT color="#FF9900"&gt;physical appliances&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Cluster ID is already in use -&amp;gt; &lt;FONT color="#FF9900"&gt;only CP firewalls that we have in use, directly connected, they can't see another cluster, even if one was there...&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I've also checked the logging our logging, there's something suspicious there:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I'm not sure what that means.&amp;nbsp;&lt;BR /&gt;It's originating from member1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding your suggestion to go on:&amp;nbsp;&lt;BR /&gt;This will be a future 24/7 productive environment, that's why the CU feature is very important for me. I would like to find the cause of this issue, otherwise we may run into the same issue at the next update. Currently I can take the time to troubleshoot, which later won't be possible that easy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 29 Jun 2020 12:33:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71326#M9603</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2020-06-29T12:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Bond issue during VSX upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71331#M9604</link>
      <description>Setting CCP to broadcast is the worst of them all, always try to use unicast if possible.&lt;BR /&gt;&lt;BR /&gt;What I would do is start all over again, if I was trying to really find the issue, start with a clean install of R80.20 with the latest jumbo and do a vsx_util reconfigure. Then start the migration again and see what happens</description>
      <pubDate>Mon, 30 Dec 2019 06:11:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Bond-issue-during-VSX-upgrade/m-p/71331#M9604</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-12-30T06:11:15Z</dc:date>
    </item>
  </channel>
</rss>

