<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cluster broke down - SMB 9000 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246301#M12459</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;it's me again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now we have a problem with another cluster of two&amp;nbsp;SMB 9000. It was working good, then something happened. Maybe I did something wrong. Now the only one Node is online, another one doesn't respond, although I see its MAC.&lt;STRONG&gt; I even can't open the web-interfaces of the broken Node.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Some logs from the nodes. The working node doesn't see the neighbor:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[fws02:0]# cphaprob roles
ID         Role
2 (local)  Master

[fws02:0]# cphaprob state
Cluster Mode:   High Availability (Active Up) with IGMP Membership
ID         Unique Address  Assigned Load   State          Name                               
2 (local)  172.27.255.150  100%            ACTIVE         fws02

Active PNOTEs: LPRB
Last member state change event:
   Event Code:                 CLUS-114904
   State change:               ACTIVE(!) -&amp;gt; ACTIVE
   Reason for state change:    Reason for ACTIVE! alert has been resolved
   Event time:                 Sat Apr 12 11:17:48 2025

Cluster failover count:
   Failover counter:           0
   Time of counter reset:      Sat Apr 12 10:17:24 2025 (reboot)
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;The broken node:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[fws01:0]# cphaprob roles
ID         Role
1 (local)  Non-Master
2          Master

[fws01:0]# cphaprob state
Cluster Mode:   High Availability (Active Up) with IGMP Membership
ID         Unique Address  Assigned Load   State          Name
1 (local)  172.27.255.149  0%              DOWN           fws01
2          none            100%            ACTIVE         fws02

Active PNOTEs: FSYNC, POLICY, IAC
Last member state change event:
   Event Code:                 CLUS-112400
   State change:               INIT -&amp;gt; DOWN
   Reason for state change:    FULLSYNC PNOTE - Policy installation failure
   Event time:                 Sat Apr 12 11:19:12 2025

Cluster failover count:
   Failover counter:           0
   Time of counter reset:      Sat Apr 12 11:17:27 2025 (reboot)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Very appreciate your help &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 12 Apr 2025 10:05:15 GMT</pubDate>
    <dc:creator>Exonix</dc:creator>
    <dc:date>2025-04-12T10:05:15Z</dc:date>
    <item>
      <title>Cluster broke down - SMB 9000</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246301#M12459</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;it's me again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now we have a problem with another cluster of two&amp;nbsp;SMB 9000. It was working good, then something happened. Maybe I did something wrong. Now the only one Node is online, another one doesn't respond, although I see its MAC.&lt;STRONG&gt; I even can't open the web-interfaces of the broken Node.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Some logs from the nodes. The working node doesn't see the neighbor:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[fws02:0]# cphaprob roles
ID         Role
2 (local)  Master

[fws02:0]# cphaprob state
Cluster Mode:   High Availability (Active Up) with IGMP Membership
ID         Unique Address  Assigned Load   State          Name                               
2 (local)  172.27.255.150  100%            ACTIVE         fws02

Active PNOTEs: LPRB
Last member state change event:
   Event Code:                 CLUS-114904
   State change:               ACTIVE(!) -&amp;gt; ACTIVE
   Reason for state change:    Reason for ACTIVE! alert has been resolved
   Event time:                 Sat Apr 12 11:17:48 2025

Cluster failover count:
   Failover counter:           0
   Time of counter reset:      Sat Apr 12 10:17:24 2025 (reboot)
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;The broken node:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[fws01:0]# cphaprob roles
ID         Role
1 (local)  Non-Master
2          Master

[fws01:0]# cphaprob state
Cluster Mode:   High Availability (Active Up) with IGMP Membership
ID         Unique Address  Assigned Load   State          Name
1 (local)  172.27.255.149  0%              DOWN           fws01
2          none            100%            ACTIVE         fws02

Active PNOTEs: FSYNC, POLICY, IAC
Last member state change event:
   Event Code:                 CLUS-112400
   State change:               INIT -&amp;gt; DOWN
   Reason for state change:    FULLSYNC PNOTE - Policy installation failure
   Event time:                 Sat Apr 12 11:19:12 2025

Cluster failover count:
   Failover counter:           0
   Time of counter reset:      Sat Apr 12 11:17:27 2025 (reboot)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Very appreciate your help &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2025 10:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246301#M12459</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2025-04-12T10:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster broke down - SMB 9000</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246303#M12460</link>
      <description>&lt;P&gt;I don't understand this... it started working it self...&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2025 10:42:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246303#M12460</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2025-04-12T10:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster broke down - SMB 9000</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246304#M12461</link>
      <description>&lt;P&gt;So its complaining about the policy failure and sync...what does cphaprob symcstat show, as well as fw stat?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2025 11:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246304#M12461</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-12T11:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster broke down - SMB 9000</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246308#M12462</link>
      <description>&lt;P&gt;Did you install policy recently?&lt;/P&gt;
&lt;P&gt;Please share the firmware version &amp;amp; build of the gateways in question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2025 15:05:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246308#M12462</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-04-12T15:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster broke down - SMB 9000</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246309#M12463</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/65443"&gt;@Exonix&lt;/a&gt;&amp;nbsp;Chris made an excellent point there...even on regular Gaia cluster, clustering will NEVER work until you install the policy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2025 15:46:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-broke-down-SMB-9000/m-p/246309#M12463</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-12T15:46:31Z</dc:date>
    </item>
  </channel>
</rss>

