<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1600 Cluster sync issues in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151374#M6987</link>
    <description>&lt;P&gt;You cite from Locally Managed SMBs R80.20.20 manual but ask if&lt;SPAN&gt;&amp;nbsp;they report smth wrong in SmartConsole - we should better know the deployment before guessing...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Concerning the Sync Port: Both 1600 + 1800 have port 2 named as sync, 1600 with 1GbE and 1800 with 2,5 GbE.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2022 14:45:39 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2022-06-21T14:45:39Z</dc:date>
    <item>
      <title>1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151366#M6983</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a newly delivered(May 2022) 2x1600 Spark R80.20.35 appliances that have been configured as a cluster.&lt;/P&gt;&lt;P&gt;My colleague that did the configuration is long time on Check Point and I have no doubt that the configuration was done as usual - to work :).&lt;/P&gt;&lt;P&gt;After the configuration was done, we observed that the cluster members do not sync.&lt;/P&gt;&lt;P&gt;Have anyone encountered that recently?&lt;/P&gt;&lt;P&gt;If I should post more info about the issue, please let me know and I will anonymize mentioned configs and I will post it here - but I belive that this is not related to configs or ISP.&lt;/P&gt;&lt;P&gt;Best wishes,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrei&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 14:00:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151366#M6983</guid>
      <dc:creator>ABosinceanu</dc:creator>
      <dc:date>2022-06-21T14:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151369#M6984</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we need more details on what/how is configured, as if they don't sync then, do they report smth wrong in SmartConsole ?&lt;/P&gt;
&lt;P&gt;(as I've seen they support ClusterXL)&lt;/P&gt;
&lt;P&gt;Usually the 15K series I use have a SYNC interface that you set it as synchronization and is used specifically for that, but on 1600 I don't see that, so most likely you define some of the LAN ports to be used for sync.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;
&lt;P&gt;PS: &lt;A href="https://sc1.checkpoint.com/documents/SMB_R80.20.20/AdminGuides/Locally_Managed/EN/Topics/Configuring-High-Availability.htm?TocPath=Appliance%20Configuration%7CManaging%20the%20Device%7C_____18" target="_self"&gt;from here&lt;/A&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;
&lt;H1&gt;Configuring&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ha variable"&gt;High Availability&lt;/SPAN&gt;&lt;/H1&gt;
&lt;DIV data-mc-conditions="Condition-Tag-Set-Deliverables.Deliverable_2_Admin_Guide_Locally_Managed,Condition-Tag-Set-Deliverables.Deliverable_4_Help_Locally_Managed"&gt;
&lt;P&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Device&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Variable_Menu_Options mc-variable Vars_BladesFeatures.tp_ha variable"&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page you can create a cluster of two appliances for high availability.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- You cannot create a cluster when you have a switch or bridge defined in your network settings on the appliance. If necessary, change network settings in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Device&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Local Network&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page.&lt;/P&gt;
&lt;P&gt;After you define a cluster, you can select to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Enable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Disable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the cluster.&lt;/P&gt;
&lt;P&gt;The page shows the configured interfaces for monitoring or high availability enabled in a table, where you can edit them.&lt;/P&gt;
&lt;DIV class="No_Page_Break_Inside"&gt;
&lt;P&gt;Interface options in cluster mode:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Variable_Menu_Options mc-variable Vars_BladesFeatures.tp_ha variable"&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Two physical interfaces in 2 cluster members act as a single interface toward the network, using a single virtual IP address.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Note&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- In this cluster solution, each interface has a local IP address in addition to the shared single virtual IP address.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;U&gt;&lt;SPAN class="Menu_Options"&gt;Sync&lt;/SPAN&gt;&amp;nbsp;- Two physical interfaces must be defined as Sync interfaces and connected between the members to allow proper failover as needed. The default is to use LAN2/Sync physical port.&lt;/U&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Non HA&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(also called&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;private&lt;/SPAN&gt;) - The physical interface in this member does not participate in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ha variable"&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;functions.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Monitored&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(also called&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;private monitored&lt;/SPAN&gt;) - The physical interface in this member is not coupled with another interface on the other member as in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ha variable"&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;interface mode. The interface's status is still monitored, and if a problem occurs the member will fail over to the second one.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 21 Jun 2022 14:19:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151369#M6984</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-21T14:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151371#M6985</link>
      <description>&lt;P&gt;1600 SMB appliances HA cluster are much different to GAiA clusters - you only configure the active node in detail, and after selecting the second node in FTW as standby HA node, all config will be synchronized from active node. You did not write about it, but i assume you have a locally managed SMB cluster, so this applies:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121096&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;sk121096: How to configure a &lt;STRONG&gt;cluster&lt;/STRONG&gt; between locally managed &lt;STRONG&gt;SMB&lt;/STRONG&gt; appliances&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 14:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151371#M6985</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-21T14:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151372#M6986</link>
      <description>&lt;P&gt;Depending on the deployment scenario there is R80.20.40 available now with some clustering enhancements.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 14:36:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151372#M6986</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-21T14:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151374#M6987</link>
      <description>&lt;P&gt;You cite from Locally Managed SMBs R80.20.20 manual but ask if&lt;SPAN&gt;&amp;nbsp;they report smth wrong in SmartConsole - we should better know the deployment before guessing...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Concerning the Sync Port: Both 1600 + 1800 have port 2 named as sync, 1600 with 1GbE and 1800 with 2,5 GbE.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 14:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151374#M6987</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-21T14:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151417#M6989</link>
      <description>&lt;P&gt;I would suggest to upgrade to R80.20.40 asap !&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 07:24:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151417#M6989</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-22T07:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151491#M6995</link>
      <description>&lt;P&gt;Centrally or locally managed SMBs ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 14:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151491#M6995</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-22T14:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151714#M7006</link>
      <description>&lt;P&gt;Locally managed.&lt;/P&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;1. We performed upgrade to R80.20.40 and the issue persisted.&lt;/P&gt;&lt;P&gt;2. We went back to R80.20.35 and recreated the cluster from scratch + adding specific policies to allow traffic between cluster members and the sync issue was solved. That specific policies where there from the first time, so that was not the issue.&lt;/P&gt;&lt;P&gt;I have no clue what was that. The procedure of setup was the same in both Cluster setup configurations...same order for steps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 12:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151714#M7006</guid>
      <dc:creator>ABosinceanu</dc:creator>
      <dc:date>2022-06-24T12:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: 1600 Cluster sync issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151827#M7014</link>
      <description>&lt;P&gt;As long as you do follow&amp;nbsp;&lt;SPAN&gt;sk121096How to configure a cluster between locally managed SMB appliances sync should work. Afaik specific policies to allow traffic between cluster members are only needed in Strict Mode.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 11:41:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1600-Cluster-sync-issues/m-p/151827#M7014</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-27T11:41:34Z</dc:date>
    </item>
  </channel>
</rss>

