- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
HI Checkmates
Today i have seen new issue on cluster XL.
Environment: Distribution architecture
Version : R81.20
Hotfix : 84
Cluster members : 2 checkpoint appliances
When i do a cluster failover, secondary member takes at least 10 minutes to process the traffic. That time our all the services are goes down, after 10 minutes everything works fine. i did not observe any drops on log (smart console).
but the cluster state show active/standby states correctly. no delay on this part.
Kindly help me to sort out the new problem.
Thanks
Rajkumar T
Can you please send outputs of below when this happens?
Andy
**********************
cphaprob roles
cphaprob state
cphaprob -a if
cphaprob -i list
cphaprob -l list
cphaprob syncstat
********************************
Personally, never seen such an issue myself, even back in R55.
Is there any dynamic routing involved or are there issues with stale ARP entries?
Do the issue occur regardless of which member is active or standby?
HI Chris
There is no dynamic routing.
Have you run any tcpdumps and/or traffic captures to see if the packets are reaching the gateway during the outage period?
Sounds like a Gratuitous ARP issue (which is the default setting), do you have VMAC set on the cluster object? That should help but if you still experience a 10-12 second delay upon failover even after setting VMAC you'll need to set portfast (NOT disable STP) on the switch ports the firewalls are connected to.
If everything is working properly, upon failover you should see the following traffic behavior:
Catastrophic Failover (active completely dies/crashes): Outage of up to 2.5 seconds
Non-Catastrophic Failover (active interface failure, clusterXL_admin down, etc.): Outage of up to 300 milliseconds
Actually, @Timothy_Hall makes super valid point. Can you see if below is enabled or not?
Andy
Dear Timothy
Thanks i will try this.
Thanks
Rajkumar T
Try to toggle that option and install policy and then do a failover test and see what happens. If no change, naybe open TAC case to further investigate.
Andy
share fw tab -t connections -s from both members at the same time.
This will show if the connections are synced.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 54 | |
| 41 | |
| 15 | |
| 14 | |
| 12 | |
| 11 | |
| 11 | |
| 11 | |
| 10 | |
| 8 |
Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY