- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hey guys,
I really want to run something by here, as I have my doubts about TAC claiming this is totally normal. So, customer and I added 2 new VLANS of eth1-01 interface and set them up as clustered with VIPand all, but they dont show up when running cphaprob -a if. The existing vlans of that interface (2 of them, vlan 20 and 500) show up, but new ones (vlans 762 and 764) do NOT, though they show up in virtual cluster interface section from cphaprob -a if, just NOT under required interfaces.
To me, this makes no sense, as I had never ever seen this before. Yes, traffic works, so it could be just cosmetic, but TAC guy said sometimes reboot is needed for this to show up properly (in my 15 years dealing with CP, I never had to reboot firewall when doing this for cluster, not once, so I dont believe for a second that reboot is required).
Any idea what we can do to make those 2 new clustered vlans show up in cphaprob -a if? Version is R81.10 jumbo 81.
Btw, failover works fine, no issues.
Cheers and thanks for the help as always!
Newly added VLAN interfaces (in case you added a new highest or lowest VLAN) should be added to the ClusterXL kernel module. Those are initialized during reboot or cpstop/cpstart.
I dont know if this is indeed needed, but TAC sent us below and it appears cpstop and cpstart is needed to fix it. Not sure if someone could confirm this 100%, but if thats the case, customer wont bother, if its only cosmetic.
ClusterXL VLAN monitoring (checkpoint.com)
Newly added VLAN interfaces (in case you added a new highest or lowest VLAN) should be added to the ClusterXL kernel module. Those are initialized during reboot or cpstop/cpstart.
I tested this in my R81.10 clusterxl lab and did not need reboot, any kernel parameter change, reboot at all. All I did was added vlans 999 and 1000, got interfaces without topology, pushed the policy and both vlans came up as clustered under cphaprob -a if.
It is not about how they show in cphaprob. It is about which VLAN is monitored with CCP packets. By default, it is the lowest and highest VLANs, but if you add one with a higher/lower number, you need to reload cluster modules to change probing.
You did refer to an SK about it yourself.
Ok, I think I see what you are saying. So, in customer's scenario, there are 4 vlans, ...20.500, 762 and 764 and ONLY 20 and 764 show up, which makes sense, since those are lowest and highest. Question, so is only cpstop; cpstart needed or any kernel parameter change? Its not 100% clear from the sk.
Only if you want one kernel parameter from sk92826 to be set differently from its default value !
K, good now thanks! Tested with vlans 999, 1000 and 1500 and when added vlan 1500, vlan 1000 did NOT show up in cphaprob -a if, but after doing cpstop/cpstart, it did.
Thanks a lot @_Val_ abd @G_W_Albrecht , appreciate the clarification.
Hmm really strange. I do not remember for need of reboot or cpstart/cpstop for this during my whole experience with Check Point. Could you please share some output as well?
I will test this today in my R81.10 clusterxl lab and see what happens. Will add say 2 new VLANS, 900 and 950 and see if those interfaces show up when I cluster them via cphaprob -a if.
If they dont, will do cpstop; cpstart without making any kernel parameters changes from sk TAC gave.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY