<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SGM fails to join cluster after upgrade to Take130 due to CPSSH config file mismatch. in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SGM-fails-to-join-cluster-after-upgrade-to-Take130-due-to-CPSSH/m-p/207332#M2440</link>
    <description>&lt;P&gt;I have recently upgraded my Maestro setup from R81.10 Take110 to Take130. As per the Maestro documentation, I always upgrade one SGM first, and then the other (two SGMs, single site).&lt;/P&gt;&lt;P&gt;After Take130 installed on the first member, it rebooted, but failed to join the cluster. It then proceeded to reboot 5 times, after which it stayed in&amp;nbsp;&lt;STRONG&gt;DOWN&lt;/STRONG&gt; state. Looking at some log files, it appears that the member failed to obtain a SSH DPI config file (despite us not running SSH deep packet inspection).&lt;/P&gt;&lt;P&gt;Looking at the log files on the problematic member in the&amp;nbsp;&lt;STRONG&gt;DOWN&amp;nbsp;&lt;/STRONG&gt;state:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# cat &lt;EM&gt;&lt;STRONG&gt;/var/log/pull_config_report.log&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Report of "apply all":&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| 192.0.2.1] Configuration mismatch (refer to /var/log/configuration_reboot_reason.log)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;reboot retry left: 0/5. Reboot is aborted.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# cat &lt;EM&gt;&lt;STRONG&gt;/var/log/configuration_reboot_reason.log&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;Reboot was performed due to configuration mismatch:&lt;BR /&gt;- /opt/CPsuite-R81.10/fw1/conf/cpssh/settings.fwset&lt;BR /&gt;Remote file '/opt/CPsuite-R81.10/fw1/conf/cpssh/settings.fwset' &lt;EM&gt;does not exist&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So the upgraded member failed to get the /cpssh/settings.fwset file from the &lt;STRONG&gt;ACTIVE&lt;/STRONG&gt; member (even though SSH DPI is not turned on, this file is apparently necessary). Note that these files were not present on either member prior to the upgrade.&lt;/P&gt;&lt;P&gt;To overcome this, I have run the following commands on the&amp;nbsp;&lt;STRONG&gt;ACTIVE&amp;nbsp;&lt;/STRONG&gt;member:&lt;/P&gt;&lt;P&gt;# cpssh_config&lt;/P&gt;&lt;P&gt;# cpssh_config istatus&lt;/P&gt;&lt;P&gt;After running the above, the relevant files were created on the&amp;nbsp;&lt;STRONG&gt;ACTIVE&lt;/STRONG&gt; member, and after rebooting the&amp;nbsp;&lt;STRONG&gt;DOWN&lt;/STRONG&gt; member, it joined the cluster and started handling traffic.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2024 03:38:05 GMT</pubDate>
    <dc:creator>JH_Ranger</dc:creator>
    <dc:date>2024-02-28T03:38:05Z</dc:date>
    <item>
      <title>SGM fails to join cluster after upgrade to Take130 due to CPSSH config file mismatch.</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SGM-fails-to-join-cluster-after-upgrade-to-Take130-due-to-CPSSH/m-p/207332#M2440</link>
      <description>&lt;P&gt;I have recently upgraded my Maestro setup from R81.10 Take110 to Take130. As per the Maestro documentation, I always upgrade one SGM first, and then the other (two SGMs, single site).&lt;/P&gt;&lt;P&gt;After Take130 installed on the first member, it rebooted, but failed to join the cluster. It then proceeded to reboot 5 times, after which it stayed in&amp;nbsp;&lt;STRONG&gt;DOWN&lt;/STRONG&gt; state. Looking at some log files, it appears that the member failed to obtain a SSH DPI config file (despite us not running SSH deep packet inspection).&lt;/P&gt;&lt;P&gt;Looking at the log files on the problematic member in the&amp;nbsp;&lt;STRONG&gt;DOWN&amp;nbsp;&lt;/STRONG&gt;state:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# cat &lt;EM&gt;&lt;STRONG&gt;/var/log/pull_config_report.log&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Report of "apply all":&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| 192.0.2.1] Configuration mismatch (refer to /var/log/configuration_reboot_reason.log)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;reboot retry left: 0/5. Reboot is aborted.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# cat &lt;EM&gt;&lt;STRONG&gt;/var/log/configuration_reboot_reason.log&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;Reboot was performed due to configuration mismatch:&lt;BR /&gt;- /opt/CPsuite-R81.10/fw1/conf/cpssh/settings.fwset&lt;BR /&gt;Remote file '/opt/CPsuite-R81.10/fw1/conf/cpssh/settings.fwset' &lt;EM&gt;does not exist&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So the upgraded member failed to get the /cpssh/settings.fwset file from the &lt;STRONG&gt;ACTIVE&lt;/STRONG&gt; member (even though SSH DPI is not turned on, this file is apparently necessary). Note that these files were not present on either member prior to the upgrade.&lt;/P&gt;&lt;P&gt;To overcome this, I have run the following commands on the&amp;nbsp;&lt;STRONG&gt;ACTIVE&amp;nbsp;&lt;/STRONG&gt;member:&lt;/P&gt;&lt;P&gt;# cpssh_config&lt;/P&gt;&lt;P&gt;# cpssh_config istatus&lt;/P&gt;&lt;P&gt;After running the above, the relevant files were created on the&amp;nbsp;&lt;STRONG&gt;ACTIVE&lt;/STRONG&gt; member, and after rebooting the&amp;nbsp;&lt;STRONG&gt;DOWN&lt;/STRONG&gt; member, it joined the cluster and started handling traffic.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 03:38:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SGM-fails-to-join-cluster-after-upgrade-to-Take130-due-to-CPSSH/m-p/207332#M2440</guid>
      <dc:creator>JH_Ranger</dc:creator>
      <dc:date>2024-02-28T03:38:05Z</dc:date>
    </item>
  </channel>
</rss>

