<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro dual site failover in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/196106#M2289</link>
    <description>&lt;P&gt;Maestro clustering and regular clustering work differently. We don't do the same interface monitoring in Maestro like we do in regular CXL, hence you are not getting meaningful output from the commands you are running. Please monitor Maestro clustering with asg stat commands (asg stat -v, asg stat vs all, asg stat vs).&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2023 08:31:24 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2023-10-25T08:31:24Z</dc:date>
    <item>
      <title>Maestro dual site failover</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/187895#M2119</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Maestro dual site scenario, Security Group Active/Standby mode, Active security gateways on one site, Standby on other site.&lt;/P&gt;&lt;P&gt;How works failover?&lt;/P&gt;&lt;P&gt;What will happen if&amp;nbsp;interconnect link is down between sites?&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will happen after the link is up?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 15:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/187895#M2119</guid>
      <dc:creator>EugeneK</dc:creator>
      <dc:date>2023-07-27T15:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site failover</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/188365#M2150</link>
      <description>&lt;P&gt;Failover occurs when the active site has degraded sufficiently to trigger a failover, according to the weighting seen in 'asg stat'. By default, if you lose a bond on the active site, it'll fail over. If you lose an orchestrator, it'll fail over. If you lose one SGM it will not fail over, but if you lose two it will.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Failover functionally works like any Check Point A/S cluster. Connections are maintained and continued on the other site.&lt;/P&gt;
&lt;P&gt;If the site sync link goes down the two sites will try to discover each other via the uplinks. They will maintain the current cluster state until sync is restored. Once the link is back up, sync is restored and you're back to normal.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 07:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/188365#M2150</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2023-08-02T07:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site failover</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/195405#M2283</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I have some doubt about VSLS failover over Maestro dual site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured a security group with VSX and set it as VSLS "set chassis high-availability mode 3", I have some VS active on Chassis 1 and some other active on Chassis 2.&lt;/P&gt;&lt;P&gt;Running "show cluster members interfaces all" from a VS I see the following output:&lt;/P&gt;&lt;P&gt;CCP mode: Automatic&lt;BR /&gt;Required interfaces: 1&lt;BR /&gt;Required secured interfaces: 0&lt;/P&gt;&lt;P&gt;Interface Name: Status:&lt;/P&gt;&lt;P&gt;Sync (S) UP&lt;BR /&gt;bond1.200 (LS) DOWN&lt;BR /&gt;bond2.100 (LS) DOWN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running "cphaprob stat" I see:&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 192.0.2.1 50% ACTIVE admin-ch01-01&lt;BR /&gt;2 192.0.2.2 50% ACTIVE admin-ch01-02&lt;BR /&gt;15 192.0.2.15 50% ACTIVE admin-ch02-01&lt;BR /&gt;16 192.0.2.16 50% ACTIVE admin-ch02-02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I have all link down on both sites for maintenance but I see that VS is Active because is required only 1 interface on cluster.&lt;/P&gt;&lt;P&gt;Is this correct? Why default configuration have only 1 interface required even if I have 6 interfaces presents?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With VSLS configuration if all the slave of a bond interface on chassis 1 (where VS is active) goes down, VS have to failover over chassis 2. Is this correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:05:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/195405#M2283</guid>
      <dc:creator>Marco32</dc:creator>
      <dc:date>2023-10-17T13:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site failover</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/195437#M2284</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;In general, all SGM modules are active. The state in 'cphaprob' is OK. As all interfaces on both sites are down, the chassis grade is equal. Once the interfaces on one site become up, the chassis grade will change and you will see one site down.&lt;/P&gt;
&lt;P&gt;The correct tool for monitoring the status in a maestro vsls environment is '&lt;STRONG&gt;asg monitor&lt;/STRONG&gt;'.&lt;BR /&gt;If you use '&lt;STRONG&gt;asg moni&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;tor vs all&lt;/STRONG&gt;' you see status of all virtual systems across both sites (chassis1, chassis2).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please check in addition:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;nbsp;&lt;STRONG&gt;asg_bond&lt;/STRONG&gt; (if you use bonded interfaces)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- per VS the '&lt;STRONG&gt;asg if&lt;/STRONG&gt;' command&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:52:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/195437#M2284</guid>
      <dc:creator>Jochen_Hoechner</dc:creator>
      <dc:date>2023-10-17T14:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site failover</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/195515#M2285</link>
      <description>&lt;P&gt;Hi Jochen, thanks for your support.&lt;/P&gt;&lt;P&gt;So I have to plug the cable to see different status in cphaprob. For VS that run on Chassis1 will I see ACTIVE for the SGM on site 1 and some different info for SGM on site 2?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Locking with "asg_bond" I see that bonds are in Failed because eth of both site are now DOWN and "asg if" teel me that every interface (ex. bond1.200 and so on) are in down for both chassis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What about the output of "show cluster members interfaces all"? Why I see "Required interfaces: 1" even if I have several interfaces? S&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;houldn't I have multiple interfaces here?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 09:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/195515#M2285</guid>
      <dc:creator>Marco32</dc:creator>
      <dc:date>2023-10-18T09:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site failover</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/196106#M2289</link>
      <description>&lt;P&gt;Maestro clustering and regular clustering work differently. We don't do the same interface monitoring in Maestro like we do in regular CXL, hence you are not getting meaningful output from the commands you are running. Please monitor Maestro clustering with asg stat commands (asg stat -v, asg stat vs all, asg stat vs).&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 08:31:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-failover/m-p/196106#M2289</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2023-10-25T08:31:24Z</dc:date>
    </item>
  </channel>
</rss>

