<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster checkpoint in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cluster-checkpoint/m-p/219986#M36646</link>
    <description>&lt;P&gt;If you want to understand how ClusterXL works, start with the documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Introduction-to-ClusterXL.htm?tocpath=Introduction%20to%20ClusterXL%7C_____0#Introduction_to_ClusterXL" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Introduction-to-ClusterXL.htm?tocpath=Introduction%20to%20ClusterXL%7C_____0#Introduction_to_ClusterXL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other members "take over" when they see issues on the other node.&lt;BR /&gt;The management pushes policy to both members independently&lt;BR /&gt;To remove a firewall from a cluster, it would need to be removed from the relevant cluster object and a policy installation done.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2024 18:02:21 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-07-08T18:02:21Z</dc:date>
    <item>
      <title>Cluster checkpoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-checkpoint/m-p/219721#M36607</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm a beginner&lt;/P&gt;&lt;P&gt;Can you tell me how the members of a checkpoint cluster communicate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's my question:&lt;BR /&gt;1)Let's imagine that one of the interfaces of firewall 1 goes down, for example eth1: 192.168.10.1 ( in the picture)&lt;BR /&gt;Firewall 1 will become backup and firewall 2 nominal.&lt;BR /&gt;Who triggers this switchover?&lt;/P&gt;&lt;P&gt;2) another question. Is the HA interface used to send the rules compiled on firewall 1 to firewall 2?&lt;/P&gt;&lt;P&gt;3) when you have 2 firewalls in a cluster, how do you remove one of the firewalls from the cluster so that the 2 firewalls become independent?&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 15:17:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-checkpoint/m-p/219721#M36607</guid>
      <dc:creator>samdin</dc:creator>
      <dc:date>2024-07-04T15:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster checkpoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-checkpoint/m-p/219725#M36609</link>
      <description>&lt;P&gt;I have fully working cluster lab, so can easily show you. Key is that whatever you configure as cluster interfaces, if one of them goes down, there will be failover. I gave some exampled below from the lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26619i79ACF7E065292040/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;master fw:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob roles&lt;/P&gt;
&lt;P&gt;ID Role&lt;/P&gt;
&lt;P&gt;1 (local) Master&lt;BR /&gt;2 Non-Master&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob state&lt;/P&gt;
&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;
&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;
&lt;P&gt;1 (local) 169.254.0.112 100% ACTIVE CP-FW-01&lt;BR /&gt;2 169.254.0.111 0% STANDBY CP-FW-02&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114704&lt;BR /&gt;State change: STANDBY -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: No other ACTIVE members have been found in the cluster&lt;BR /&gt;Event time: Wed Jul 3 08:34:59 2024&lt;/P&gt;
&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 2 -&amp;gt; Member 1&lt;BR /&gt;Reason: ADMIN_DOWN PNOTE&lt;BR /&gt;Event time: Wed Jul 3 08:34:59 2024&lt;/P&gt;
&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 4&lt;BR /&gt;Time of counter reset: Thu Jun 27 20:23:48 2024 (reboot)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-FW-01:0]# cphaprob -a if&lt;/P&gt;
&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;
&lt;P&gt;eth0 (LM) UP&lt;BR /&gt;eth1 (LM) UP&lt;BR /&gt;eth2 (LM) UP&lt;BR /&gt;eth3 (S) UP&lt;/P&gt;
&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;
&lt;P&gt;Virtual cluster interfaces: 3&lt;/P&gt;
&lt;P&gt;eth0 172.16.10.246&lt;BR /&gt;eth1 172.31.10.246&lt;BR /&gt;eth2 192.168.10.246&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob -i list&lt;/P&gt;
&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob -l list&lt;/P&gt;
&lt;P&gt;Built-in Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Registered Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 9772.6 sec&lt;/P&gt;
&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 9771.4 sec&lt;/P&gt;
&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 96711.5 sec&lt;/P&gt;
&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 238143 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 238143 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 238130 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: Init&lt;BR /&gt;Registration number: 6&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 238125 sec&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*************************************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;backup fw:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]#&lt;BR /&gt;[Expert@CP-FW-02:0]# cphaprob roles&lt;/P&gt;
&lt;P&gt;ID Role&lt;/P&gt;
&lt;P&gt;1 Master&lt;BR /&gt;2 (local) Non-Master&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]# cphaprob state&lt;/P&gt;
&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;
&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;
&lt;P&gt;1 169.254.0.112 100% ACTIVE CP-FW-01&lt;BR /&gt;2 (local) 169.254.0.111 0% STANDBY CP-FW-02&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114802&lt;BR /&gt;State change: DOWN -&amp;gt; STANDBY&lt;BR /&gt;Reason for state change: There is already an ACTIVE member in the cluster (member 1)&lt;BR /&gt;Event time: Wed Jul 3 08:35:00 2024&lt;/P&gt;
&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 2 -&amp;gt; Member 1&lt;BR /&gt;Reason: ADMIN_DOWN PNOTE&lt;BR /&gt;Event time: Wed Jul 3 08:34:59 2024&lt;/P&gt;
&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 4&lt;BR /&gt;Time of counter reset: Thu Jun 27 20:23:48 2024 (reboot)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-FW-02:0]# cphaprob -a if&lt;/P&gt;
&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;
&lt;P&gt;eth0 (LM) UP&lt;BR /&gt;eth1 (LM) UP&lt;BR /&gt;eth2 (LM) UP&lt;BR /&gt;eth3 (S) UP&lt;/P&gt;
&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;
&lt;P&gt;Virtual cluster interfaces: 3&lt;/P&gt;
&lt;P&gt;eth0 172.16.10.246&lt;BR /&gt;eth1 172.31.10.246&lt;BR /&gt;eth2 192.168.10.246&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]# cphaprob syncstat&lt;/P&gt;
&lt;P&gt;Delta Sync Statistics&lt;/P&gt;
&lt;P&gt;Sync status: OK&lt;/P&gt;
&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;
&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;
&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 1736600&lt;BR /&gt;Sent retransmission requests................. 0&lt;BR /&gt;Sent retransmission updates.................. 0&lt;BR /&gt;Peak fragments per update.................... 2&lt;/P&gt;
&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 625084&lt;BR /&gt;Received retransmission requests............. 0&lt;/P&gt;
&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... eth3&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 20190 [Bps]&lt;BR /&gt;Peak rate.................................... 236430[Bps]&lt;BR /&gt;Link usage................................... 0%&lt;BR /&gt;Total........................................ 18331 [MB]&lt;/P&gt;
&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;
&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;
&lt;P&gt;Reset on Mon Jul 1 16:46:36 2024 (triggered by fullsync).&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]# cphaprob -i list&lt;/P&gt;
&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]# cphaprob -l list&lt;/P&gt;
&lt;P&gt;Built-in Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Device Name: Recovery Delay&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;
&lt;P&gt;Registered Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 9833.7 sec&lt;/P&gt;
&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 9832.4 sec&lt;/P&gt;
&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 239927 sec&lt;/P&gt;
&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 240004 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 240004 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: cphad&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 239991 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;
&lt;P&gt;Device Name: Init&lt;BR /&gt;Registration number: 6&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 239986 sec&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To gracefully failover, you do this on MASTER member:&lt;/P&gt;
&lt;P&gt;clusterXL_admin down;clusterXL_admin up&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 15:30:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-checkpoint/m-p/219725#M36609</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-04T15:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster checkpoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-checkpoint/m-p/219986#M36646</link>
      <description>&lt;P&gt;If you want to understand how ClusterXL works, start with the documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Introduction-to-ClusterXL.htm?tocpath=Introduction%20to%20ClusterXL%7C_____0#Introduction_to_ClusterXL" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Introduction-to-ClusterXL.htm?tocpath=Introduction%20to%20ClusterXL%7C_____0#Introduction_to_ClusterXL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other members "take over" when they see issues on the other node.&lt;BR /&gt;The management pushes policy to both members independently&lt;BR /&gt;To remove a firewall from a cluster, it would need to be removed from the relevant cluster object and a policy installation done.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 18:02:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-checkpoint/m-p/219986#M36646</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-08T18:02:21Z</dc:date>
    </item>
  </channel>
</rss>

