<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sync interface DOWN after reboot of Standby Member - any other TShoot options? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188864#M31662</link>
    <description>&lt;P&gt;Hi all, we have an issue with our VSX HA Cluster (Two gateways, Active/Standby), where after rebooting the Standby for whatever reason the Sync interface remains DOWN. In the past when this occurred, a physical power down of the standby restored the link, but a normal reboot does not (nor bouncing the link).&lt;/P&gt;&lt;P&gt;We're in the process of eliminating physical problems, particularly replacing the cable and SFP for this link. But I was wondering if there is any other troubleshooting steps I might be able to do in the mean time?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[ACTIVE] SYNC (eth3-04) &amp;lt;----&amp;gt; (eth3-04) SYNC [STANDBY]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Currently we have no HA resiliency, all VS are DOWN on the standby which isn't ideal.&lt;/P&gt;&lt;P&gt;Interface counters show no incrementing RX or TX on either side.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;cphaprob syncstat&lt;/EM&gt; does show incrementing SENT sync messages, but no received messages.&lt;/P&gt;&lt;P&gt;My theory is maybe the SFP/Transceiver is faulty, and perhaps in a normal reboot the SFP doesn't lose power, but in a full physical power down it does? Which maybe causes the link to come back up, I'm not sure..&lt;/P&gt;&lt;P&gt;I appreciate any thoughts!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 07:30:01 GMT</pubDate>
    <dc:creator>Parabol</dc:creator>
    <dc:date>2023-08-08T07:30:01Z</dc:date>
    <item>
      <title>Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188864#M31662</link>
      <description>&lt;P&gt;Hi all, we have an issue with our VSX HA Cluster (Two gateways, Active/Standby), where after rebooting the Standby for whatever reason the Sync interface remains DOWN. In the past when this occurred, a physical power down of the standby restored the link, but a normal reboot does not (nor bouncing the link).&lt;/P&gt;&lt;P&gt;We're in the process of eliminating physical problems, particularly replacing the cable and SFP for this link. But I was wondering if there is any other troubleshooting steps I might be able to do in the mean time?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[ACTIVE] SYNC (eth3-04) &amp;lt;----&amp;gt; (eth3-04) SYNC [STANDBY]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Currently we have no HA resiliency, all VS are DOWN on the standby which isn't ideal.&lt;/P&gt;&lt;P&gt;Interface counters show no incrementing RX or TX on either side.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;cphaprob syncstat&lt;/EM&gt; does show incrementing SENT sync messages, but no received messages.&lt;/P&gt;&lt;P&gt;My theory is maybe the SFP/Transceiver is faulty, and perhaps in a normal reboot the SFP doesn't lose power, but in a full physical power down it does? Which maybe causes the link to come back up, I'm not sure..&lt;/P&gt;&lt;P&gt;I appreciate any thoughts!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 07:30:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188864#M31662</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-08-08T07:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188867#M31663</link>
      <description>&lt;P&gt;Could you perform command below and share me result:&lt;/P&gt;&lt;P&gt;cphaprob stat&lt;/P&gt;&lt;P&gt;cphaprob -a if&lt;/P&gt;&lt;P&gt;tcpdump -nni &amp;lt;name interface sync&amp;gt; port 8116&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 07:34:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188867#M31663</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2023-08-08T07:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188872#M31665</link>
      <description>&lt;P&gt;Thanks for the reply Tron, please see below (I emitted some details like hostname/IP).&lt;/P&gt;&lt;P&gt;Even running tcpdump without port specified shows no packets at all on the interface.. so it seems the link is completely dead which makes me think it must be a physical issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Standby_Gateway:0&amp;gt; cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: Virtual System Load Sharing (Primary Up)&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 x.x.x.x 100% ACTIVE(!) Primary_Gateway&lt;BR /&gt;2 (local) x.x.x.x 0% DOWN Standby_Gateway&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: IAC&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-110205&lt;BR /&gt;State change: ACTIVE(!) -&amp;gt; DOWN&lt;BR /&gt;Reason for state change: Interface eth3-04 is down (disconnected / link down)&lt;BR /&gt;Event time: Mon Aug 7 13:39:34 2023&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: Available on member 1&lt;BR /&gt;Event time: Mon Aug 7 13:39:01 2023&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 7&lt;BR /&gt;Time of counter reset: Tue Sep 6 17:00:37 2022 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cluster name: Cluster&lt;/P&gt;&lt;P&gt;Virtual Devices Status on each Cluster Member&lt;BR /&gt;=============================================&lt;/P&gt;&lt;P&gt;ID | Weight| Primary | Standby&lt;BR /&gt;| | |&lt;BR /&gt;| | |&lt;BR /&gt;| | | [local]&lt;BR /&gt;-------+-------+-----------+-----------&lt;BR /&gt;2 | 10 | ACTIVE(!) | DOWN&lt;BR /&gt;3 | 10 | ACTIVE(!) | DOWN&lt;BR /&gt;---------------+-----------+-----------&lt;BR /&gt;Active | 2 | 0&lt;BR /&gt;Weight | 20 | 0&lt;BR /&gt;Weight (%) | 100 | 0&lt;/P&gt;&lt;P&gt;Legend: Init - Initializing, Active! - Active Attention&lt;BR /&gt;Down! - ClusterXL Inactive or Virtual System is Down&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Standby_Gateway:0&amp;gt; cphaprob -a if&lt;/P&gt;&lt;P&gt;vsid 0:&lt;BR /&gt;------&lt;BR /&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 1&lt;BR /&gt;Required secured interfaces: 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;&lt;P&gt;eth1-01 UP&lt;BR /&gt;eth3-04 (S) DOWN (72062 secs)&lt;/P&gt;&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 1&lt;/P&gt;&lt;P&gt;eth1-01 x.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@Standby_Gateway:0]# tcpdump -nni eth3-04 port 8116&lt;BR /&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on eth3-04, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;BR /&gt;^C&lt;BR /&gt;0 packets captured&lt;BR /&gt;0 packets received by filter&lt;BR /&gt;0 packets dropped by kernel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 07:44:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188872#M31665</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-08-08T07:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188874#M31666</link>
      <description>&lt;P&gt;Thanks for your respone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;As information your provide, we can see:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Interface eth3-04 is down (disconnected / link down)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This causes the HAstatus to Alert DOWN. Let's check what this interface is, where this physical interface is connected, is it through any switches device?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Are there any previous changes?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 07:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188874#M31666</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2023-08-08T07:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188877#M31667</link>
      <description>&lt;P&gt;How are the links cabled - are the gateways directly connected to each other (not recommended) or via a switch.&lt;/P&gt;
&lt;P&gt;My preferred way is to have two sync interfaces in a non-LACP bond (eg. round robin works) going to two separate switches.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 08:20:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188877#M31667</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-08-08T08:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188879#M31668</link>
      <description>&lt;P&gt;True for sure there is switches between them, not directly connected.. so this could be a factor also.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 08:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188879#M31668</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-08-08T08:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188882#M31670</link>
      <description>&lt;P&gt;Dear Bro,&lt;/P&gt;&lt;P&gt;Please check status of physical interface or compare VLAN access for that interface.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 08:44:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/188882#M31670</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2023-08-08T08:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/189003#M31695</link>
      <description>&lt;P&gt;Why not recommended direct cable between FWs? In my opinion switch is an added point of failure&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 21:33:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/189003#M31695</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-08-08T21:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/189010#M31696</link>
      <description>&lt;P&gt;I can think of this as user need. Because you can plug the cable directly between 2 devices as long as both things are in the same rack.&lt;/P&gt;&lt;P&gt;If both devices are located in 2 different racks, then plugging through the switch will create aesthetics and make it easier to change cables when there is a problem in the physical layer.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 03:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/189010#M31696</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2023-08-09T03:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/189016#M31698</link>
      <description>&lt;P data-unlink="true"&gt;First off - there is Check Point's &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Content/Topics-CXLG/ClusterXL-Requirements-and-Compatibility.htm?tocpath=ClusterXL%20Requirements%20and%20Compatibility%7C_____6#Supported_Topologies_for_Synchronization_Network" target="_self"&gt;guidance on supported topologies for the sync network&lt;/A&gt;.&amp;nbsp; Note how on all there is a switch specified.&lt;/P&gt;
&lt;P data-unlink="true"&gt;I could build out a couple of failure scenarios - but&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;has already done a better job of it than what I can on this &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Best-Practice-for-HA-sync-interface/m-p/15558" target="_self"&gt;CheckMates post here&lt;/A&gt;.&lt;/P&gt;
&lt;P data-unlink="true"&gt;If you are concerned about a switch being a single point of failure, then likely it is a SPOF for other things in your environment as well.&amp;nbsp; Solve this issue with&amp;nbsp;two sync interfaces in a non-LACP bond (eg. round robin works) going to two separate switches.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 05:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/189016#M31698</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-08-09T05:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/190149#M31853</link>
      <description>&lt;P&gt;Hi all, to confirm it was a faulty SFP, so indeed a physical issue. The SFP was allowed to be RMA'd with Checkpoint, and the replacement SFP brought the link back online.&lt;/P&gt;&lt;P&gt;Thanks all for your assistance.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 13:45:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/190149#M31853</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-08-22T13:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sync interface DOWN after reboot of Standby Member - any other TShoot options?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/190218#M31866</link>
      <description>&lt;P&gt;It is good news =))&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 02:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sync-interface-DOWN-after-reboot-of-Standby-Member-any-other/m-p/190218#M31866</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2023-08-23T02:14:24Z</dc:date>
    </item>
  </channel>
</rss>

