<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet loss in 1800 HA Cluster internet probes caused by logging into webui in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/214693#M10665</link>
    <description>&lt;P&gt;Please try upgrading to the most recent version.&lt;BR /&gt;Latest R81.10.10 for the 1800 is here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/download/132304" target="_blank"&gt;https://support.checkpoint.com/results/download/132304&lt;/A&gt;&lt;BR /&gt;(Note the link requires your UserCenter account to have an active Software Subscription)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2024 15:42:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-05-17T15:42:36Z</dc:date>
    <item>
      <title>Packet loss in 1800 HA Cluster internet probes caused by logging into webui</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/214651#M10663</link>
      <description>&lt;P&gt;Current image name: R81_996001397_10_07&lt;BR /&gt;Current image version: 397&lt;/P&gt;&lt;P&gt;Bit of and odd issue with a brand new 1800 HA Cluster which i wonder if anyone else has seen?.&lt;/P&gt;&lt;P&gt;All works well when left alone but if i log into the web ui on the secondary it seems to trigger packet loss on the internet probes and causes a wobble and a failover event.&lt;/P&gt;&lt;P&gt;2024 May 16 21:01:10 FIREWALLHOSTNAME auth.notice login: [WebUI] Local User 'admin' logged-in to WebUI from '172.16.10.1' as 'Super Admin'&lt;BR /&gt;2024 May 16 21:01:11 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:01:11 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:01:11 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:01:11 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:01:12 FIREWALLHOSTNAME user.info lua: [Security Settings] A policy change has been applied&lt;BR /&gt;2024 May 16 21:01:12 FIREWALLHOSTNAME user.info lua: [Security Settings] High Availability policy change has been applied&lt;BR /&gt;2024 May 16 21:01:14 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:01:14 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:01:14 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:01:14 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:01:16 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:01:16 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:01:16 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:01:16 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:01:28 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.cloudflare.com&lt;BR /&gt;2024 May 16 21:01:28 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.opendns.com&lt;BR /&gt;2024 May 16 21:01:28 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.cloudflare.com&lt;BR /&gt;2024 May 16 21:01:31 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.cloudflare.com&lt;BR /&gt;2024 May 16 21:01:31 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.opendns.com&lt;BR /&gt;2024 May 16 21:01:31 FIREWALLHOSTNAME user.info cposd: [CPOSD] WAN connection "Internet1": Internet connection probe status has changed to Disconnected. servers: 3, fails: 10, attempts: 30&lt;BR /&gt;2024 May 16 21:01:31 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:01:31 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:01:31 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:01:31 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:01:58 FIREWALLHOSTNAME user.info cposd: [CPOSD] WAN connection "Internet1": Internet connection probe status has changed to Connected. servers: 3, fails: 9, attempts: 30&lt;BR /&gt;2024 May 16 21:03:00 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:03:00 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:03:00 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:03:00 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:03:18 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.cloudflare.com&lt;BR /&gt;2024 May 16 21:03:18 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.opendns.com&lt;BR /&gt;2024 May 16 21:03:21 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.cloudflare.com&lt;BR /&gt;2024 May 16 21:03:21 FIREWALLHOSTNAME user.err cposd: [CPOSD] Error: Could not resolve name for probed server dns.opendns.com&lt;BR /&gt;2024 May 16 21:03:21 FIREWALLHOSTNAME user.info cposd: [CPOSD] WAN connection "Internet1": Internet connection probe status has changed to Disconnected. servers: 3, fails: 10, attempts: 30&lt;BR /&gt;2024 May 16 21:03:21 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:03:21 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:03:21 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:03:21 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:03:35 FIREWALLHOSTNAME auth.notice login: [WebUI] Local User 'admin' logged-in to WebUI from '172.16.10.1' as 'Super Admin'&lt;BR /&gt;2024 May 16 21:03:39 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:03:39 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:03:39 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:03:39 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:03:40 FIREWALLHOSTNAME daemon.info dnsmasq: read /var/hosts - 17 addresses&lt;BR /&gt;2024 May 16 21:03:41 FIREWALLHOSTNAME daemon.info dnsmasq: reading /etc/resolv.conf&lt;BR /&gt;2024 May 16 21:03:41 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 217.172.141.44#53&lt;BR /&gt;2024 May 16 21:03:41 FIREWALLHOSTNAME daemon.info dnsmasq: using nameserver 8.8.8.8#53&lt;BR /&gt;2024 May 16 21:03:45 FIREWALLHOSTNAME user.info cposd: [CPOSD] WAN connection "Internet1": Internet connection probe status has changed to Connected. servers: 3, fails: 9, attempts: 30&lt;BR /&gt;2024 May 16 21:03:46 FIREWALLHOSTNAME user.notice discntd_ctrl: Started...&lt;BR /&gt;2024 May 16 21:03:46 FIREWALLHOSTNAME user.notice discntd_ctrl: Called as sender...&lt;BR /&gt;2024 May 16 21:03:46 FIREWALLHOSTNAME user.notice discntd_ctrl: File has changed...&lt;BR /&gt;2024 May 16 21:03:46 FIREWALLHOSTNAME user.notice discntd_apply: Started...&lt;BR /&gt;2024 May 16 21:03:57 FIREWALLHOSTNAME user.notice discntd_apply: Done...&lt;BR /&gt;2024 May 16 21:04:19 FIREWALLHOSTNAME user.notice discntd_ctrl: Started...&lt;BR /&gt;2024 May 16 21:04:19 FIREWALLHOSTNAME user.notice discntd_ctrl: Called as sender...&lt;BR /&gt;2024 May 16 21:04:19 FIREWALLHOSTNAME user.notice discntd_ctrl: File has changed...&lt;BR /&gt;2024 May 16 21:04:19 FIREWALLHOSTNAME user.notice discntd_apply: Started...&lt;BR /&gt;2024 May 16 21:04:30 FIREWALLHOSTNAME user.notice discntd_apply: Done...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet loss aggregations from yesterday correspond with the times i was testing my theory it was caused by the webui.&lt;/P&gt;&lt;P&gt;FIREWALLHOSTNAME&amp;gt; show internet probe-stats&lt;BR /&gt;wan1:&lt;BR /&gt;server: 8.8.8.8:&lt;BR /&gt;time avg[ms] min[ms] max[ms] packet loss[%]&lt;BR /&gt;10:00 4.00 3 5 0.08&lt;BR /&gt;11:00 4.00 3 5 0.00&lt;BR /&gt;12:00 4.06 3 12 10.56&lt;BR /&gt;13:00 4.14 4 12 0.00&lt;BR /&gt;14:00 4.14 4 13 0.00&lt;BR /&gt;15:00 4.17 4 15 0.00&lt;BR /&gt;16:00 4.13 4 12 0.00&lt;BR /&gt;17:00 4.15 4 16 0.00&lt;BR /&gt;18:00 4.14 4 20 6.94&lt;BR /&gt;19:00 4.14 4 14 0.16&lt;BR /&gt;20:00 4.16 4 15 0.08&lt;BR /&gt;21:00 4.13 4 15 2.25&lt;BR /&gt;22:00 4.16 4 13 0.00&lt;BR /&gt;23:00 4.14 4 10 0.00&lt;BR /&gt;00:00 4.11 4 7 0.00&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 09:51:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/214651#M10663</guid>
      <dc:creator>merscoob</dc:creator>
      <dc:date>2024-05-17T09:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Packet loss in 1800 HA Cluster internet probes caused by logging into webui</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/214693#M10665</link>
      <description>&lt;P&gt;Please try upgrading to the most recent version.&lt;BR /&gt;Latest R81.10.10 for the 1800 is here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/download/132304" target="_blank"&gt;https://support.checkpoint.com/results/download/132304&lt;/A&gt;&lt;BR /&gt;(Note the link requires your UserCenter account to have an active Software Subscription)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 15:42:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/214693#M10665</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-17T15:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Packet loss in 1800 HA Cluster internet probes caused by logging into webui</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/215006#M10689</link>
      <description>&lt;P&gt;Managed to get both on the latest version and still behaving the same. Oddly its showing failures on the failover counter but there's nothing in the history.&lt;/P&gt;&lt;P&gt;Definitely seems to correlate with me logging into the management on the secondary via the remote access VPN on the primary , which seems to cause the internet stability on both nodes.&lt;/P&gt;&lt;P&gt;The WAN links are connected to a colo datacentre L3 switch which looks to be running HSRP across their 2 core Cisco switches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: Available on member 1&lt;BR /&gt;Event time: Wed May 22 12:58:51 2024&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 4&lt;BR /&gt;Time of counter reset: Wed May 22 12:03:47 2024 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cluster failover history (last 20 failovers since reboot/reset on Wed May 22 12:03:47 2024):&lt;/P&gt;&lt;P&gt;No. Time: Transition: CPU: Reason:&lt;BR /&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;/P&gt;&lt;P&gt;No failover was detected since last reboot/reset&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 14:11:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/215006#M10689</guid>
      <dc:creator>merscoob</dc:creator>
      <dc:date>2024-05-22T14:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Packet loss in 1800 HA Cluster internet probes caused by logging into webui</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/215011#M10690</link>
      <description>&lt;P&gt;What was the reason you were logging into the secondary?&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 14:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/215011#M10690</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-22T14:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Packet loss in 1800 HA Cluster internet probes caused by logging into webui</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/215013#M10691</link>
      <description>&lt;P&gt;Open an SR# with CP TAC - this seems rather strange ! Remark: Usually, with SMB clusters you log into WebGUI with the VIP, as all config is only done on the active/primary node and then synced to the standby/secondary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 14:33:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/215013#M10691</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-05-22T14:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Packet loss in 1800 HA Cluster internet probes caused by logging into webui</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/217700#M10797</link>
      <description>&lt;P&gt;Just to draw a line under this. Updating to the latest firmware made no difference.&lt;/P&gt;&lt;P&gt;Our support company escalated to checkpoint who suggested we disabled the internet connection monitoring probes which seems to have done the trick and logging into the standby device no longer destabilises the cluster.&lt;/P&gt;&lt;P&gt;Doesn't really explain what was causing the issue but these 2 devices aren't going to be terminating the internet for much longer so it doesn't really make much odds to us.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 08:03:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Packet-loss-in-1800-HA-Cluster-internet-probes-caused-by-logging/m-p/217700#M10797</guid>
      <dc:creator>merscoob</dc:creator>
      <dc:date>2024-06-17T08:03:28Z</dc:date>
    </item>
  </channel>
</rss>

