<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error in Master Orchestrator Security Group in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277377#M4264</link>
    <description>&lt;P&gt;Thanks in order to request these are output commands&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expert@SG01-SITE-s01-01:0]# cphaprob list&lt;/P&gt;&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;&lt;P&gt;[Expert@SG01-SITE-s01-01:0]# ssh admin@192.0.2.2&lt;BR /&gt;This system is for authorized use only.&lt;BR /&gt;Last login: Thu May 21 22:29:29 2026 from 192.0.2.1&lt;BR /&gt;You have logged into the system.&lt;BR /&gt;Warning: System diagnostics failed on the following tests: System Health.&lt;BR /&gt;[Expert@SG01-SITE-s01-02:0]# cphaprob list&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 47.6 sec&lt;/P&gt;&lt;P&gt;[Expert@SG01-C5-s01-02:0]# ssh admin@192.0.2.3&lt;BR /&gt;This system is for authorized use only.&lt;BR /&gt;Last login: Thu May 21 22:23:00 2026 from 192.0.2.2&lt;BR /&gt;You have logged into the system.&lt;BR /&gt;Warning: System diagnostics failed on the following tests: System Health.&lt;BR /&gt;[Expert@SG01-SITE-s01-03:0]# cphaprob list&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Additional description: Policy installation failure&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 301146 sec&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 123.4 sec&lt;/P&gt;&lt;P&gt;Device Name: AMW&lt;BR /&gt;Registration number: 13&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 182.8 sec&lt;/P&gt;</description>
    <pubDate>Mon, 25 May 2026 16:35:52 GMT</pubDate>
    <dc:creator>SecdetKrypton</dc:creator>
    <dc:date>2026-05-25T16:35:52Z</dc:date>
    <item>
      <title>Error in Master Orchestrator Security Group</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277305#M4260</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have the following problem: I have a security group and I can ping the 3 members from the master orchestrator; they have licensing and have a correct connection, however they appear in a down state.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[Expert@SG01-SITE-s01-01:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local)&amp;nbsp; 192.0.2.1 100% ACTIVE&amp;nbsp; &amp;nbsp;SG01-SITE-s01-01&lt;BR /&gt;2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.0.2.2&amp;nbsp; &amp;nbsp; &amp;nbsp;0% DOWN&amp;nbsp; &amp;nbsp; &amp;nbsp;SG01-SITE-s01-02&lt;BR /&gt;3&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.0.2.3&amp;nbsp; &amp;nbsp; &amp;nbsp; 0% DOWN&amp;nbsp; &amp;nbsp; &amp;nbsp;SG01-SITE-s01-03&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-112004&lt;BR /&gt;State change: DOWN -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: USER DEFINED PNOTE&lt;BR /&gt;Event time: Thu May 21 21:17:57 2026&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2026 07:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277305#M4260</guid>
      <dc:creator>SecdetKrypton</dc:creator>
      <dc:date>2026-05-22T07:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Master Orchestrator Security Group</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277306#M4261</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Can you SSH to the other SGM's from the Orchestrator and get more information:&lt;BR /&gt;&lt;BR /&gt;#cphaprob stat&lt;BR /&gt;#cphaprob -l list&lt;BR /&gt;&lt;BR /&gt;What version are you running?&lt;BR /&gt;&lt;BR /&gt;Are there any custom pnotes configured?&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2026 07:48:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277306#M4261</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-05-22T07:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Master Orchestrator Security Group</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277326#M4262</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The curious thing is that it does switch and does not lose internet connection, but members 2 and 3 appear in a down state.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[Expert@SG01-SITE-s01-01:0]# cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 192.0.2.1 100% ACTIVE SG01--SITE-s01-01&lt;BR /&gt;2 192.0.2.2 0% DOWN SG01--SITE-s01-02&lt;BR /&gt;3 192.0.2.3 0% DOWN SG01--SITE-s01-03&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-112004&lt;BR /&gt;State change: DOWN -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: USER DEFINED PNOTE&lt;BR /&gt;Event time: Thu May 21 21:17:57 2026&lt;BR /&gt;[Expert@SG01-C5-SITE-s01-01:0]# cphaprob -l list&lt;/P&gt;&lt;P&gt;Built-in Devices:&lt;/P&gt;&lt;P&gt;Device Name: CoreXL Configuration&lt;BR /&gt;Current state: OK&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Additional description: Running&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 22662.8 sec&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 22660.1 sec&lt;/P&gt;&lt;P&gt;Device Name: during_boot&lt;BR /&gt;Registration number: 2&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 45584.3 sec&lt;/P&gt;&lt;P&gt;Device Name: routed&lt;BR /&gt;Registration number: 3&lt;BR /&gt;Timeout: none&lt;BR /&gt;Additional description: OK&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 45471.5 sec&lt;/P&gt;&lt;P&gt;Device Name: cxld&lt;BR /&gt;Registration number: 4&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 45786.2 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: HD&lt;BR /&gt;Registration number: 5&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 45786.2 sec&lt;/P&gt;&lt;P&gt;Device Name: fwd&lt;BR /&gt;Registration number: 6&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 45781.6 sec&lt;BR /&gt;Process Status: UP&lt;/P&gt;&lt;P&gt;Device Name: Init&lt;BR /&gt;Registration number: 7&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 45770.3 sec&lt;/P&gt;&lt;P&gt;Device Name: sgm_pmd&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 0.4 sec&lt;/P&gt;&lt;P&gt;Device Name: lb_configd&lt;BR /&gt;Registration number: 9&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 0.7 sec&lt;/P&gt;&lt;P&gt;Device Name: sgm_lsp&lt;BR /&gt;Registration number: 10&lt;BR /&gt;Timeout: 30 sec&lt;BR /&gt;Additional description: Member lost connectivity with the Orchestrators and other members in the Security Group&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 0.3 sec&lt;/P&gt;&lt;P&gt;Device Name: DSD&lt;BR /&gt;Registration number: 11&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 22621.9 sec&lt;/P&gt;&lt;P&gt;Device Name: Iterator&lt;BR /&gt;Registration number: 12&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 22650.1 sec&lt;/P&gt;&lt;P&gt;Device Name: LACP_SYNC&lt;BR /&gt;Registration number: 13&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 45529.1 sec&lt;/P&gt;&lt;P&gt;Device Name: cvpnd&lt;BR /&gt;Registration number: 14&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: OK&lt;BR /&gt;Time since last report: 0.7 sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2026 15:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277326#M4262</guid>
      <dc:creator>SecdetKrypton</dc:creator>
      <dc:date>2026-05-22T15:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Master Orchestrator Security Group</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277333#M4263</link>
      <description>&lt;P&gt;We need to see 'cphaprob list' from the other SGMs, from 2 and 3. From SGM1 if you use the command 'm 1_2' and 'm 1_3'&amp;nbsp; you can ssh over to the other SGMs to check their pnotes and see why they are down.&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2026 03:49:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277333#M4263</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-05-23T03:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Master Orchestrator Security Group</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277377#M4264</link>
      <description>&lt;P&gt;Thanks in order to request these are output commands&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expert@SG01-SITE-s01-01:0]# cphaprob list&lt;/P&gt;&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;&lt;P&gt;[Expert@SG01-SITE-s01-01:0]# ssh admin@192.0.2.2&lt;BR /&gt;This system is for authorized use only.&lt;BR /&gt;Last login: Thu May 21 22:29:29 2026 from 192.0.2.1&lt;BR /&gt;You have logged into the system.&lt;BR /&gt;Warning: System diagnostics failed on the following tests: System Health.&lt;BR /&gt;[Expert@SG01-SITE-s01-02:0]# cphaprob list&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 47.6 sec&lt;/P&gt;&lt;P&gt;[Expert@SG01-C5-s01-02:0]# ssh admin@192.0.2.3&lt;BR /&gt;This system is for authorized use only.&lt;BR /&gt;Last login: Thu May 21 22:23:00 2026 from 192.0.2.2&lt;BR /&gt;You have logged into the system.&lt;BR /&gt;Warning: System diagnostics failed on the following tests: System Health.&lt;BR /&gt;[Expert@SG01-SITE-s01-03:0]# cphaprob list&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Additional description: Policy installation failure&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 301146 sec&lt;/P&gt;&lt;P&gt;Device Name: Policy&lt;BR /&gt;Registration number: 1&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 123.4 sec&lt;/P&gt;&lt;P&gt;Device Name: AMW&lt;BR /&gt;Registration number: 13&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 182.8 sec&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2026 16:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277377#M4264</guid>
      <dc:creator>SecdetKrypton</dc:creator>
      <dc:date>2026-05-25T16:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Master Orchestrator Security Group</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277382#M4265</link>
      <description>&lt;P&gt;I found an error: the policy package is inconsistent. One GW had a policy package named 'Initial Policy', while the other two GWs had a policy package named 'Standard'. Thank you very much for your help anyway.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2026 21:29:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277382#M4265</guid>
      <dc:creator>SecdetKrypton</dc:creator>
      <dc:date>2026-05-25T21:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Master Orchestrator Security Group</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277542#M4267</link>
      <description>&lt;P&gt;Yep that'll do it, the SGMs will go into a Down state if they don't have the right policy on them. They should sync it from the SMO SGM, if this issue persists then you'll need to diagnose the sync issue.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 01:36:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Error-in-Master-Orchestrator-Security-Group/m-p/277542#M4267</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-05-28T01:36:39Z</dc:date>
    </item>
  </channel>
</rss>

