- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
We have a problem with Connectcontrol and logical server with 2 hosts. When we take down one of the hosts behind the logical server it seems like it doesnt know that the host is down and keeps sending traffic towards it, witch result in error at the clientside ofcourse.
Any tips is appreciated
Rgds
Knut
After fiddling back and forth we actually found the culprit.
Removed the checkmark for "Use persistent server mode" on the Logical server object and it works like a charm😀
Review the following SK for supported configurations: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
I believe this is expected behavior since we're not monitoring the remote server at all.
Hi PhoneBoy
Thanks for the reply.
According to the document you mention, it states this:
ConnectControl runs on the Security Gateway and does not impose any additional memory or processing requirements. It continuously checks the availability of each server, and if a server fails or is unreachable, ConnectControl stops directing connections to that server until it becomes available
However when a server becomes unavailable, no new connections can be made to any of the remaining servers in the group either?
Hi @KnutG
There is an internal note on that SK stating that this feature is considered a legacy one, and has not been developed or tested on any of the supported versions today.
You may want to open a TAC request, to get an official answer here. Personally, I would advise putting an application load-balancer before the servers instead of using a ConnectControl feature.
Thanks _Val_
We are trying to eliminate singel point of failure, so adding an extra point of failure is defeating the purpose.
Everything works very well as long as all members are alive, when one member dies, the gateway stops serving all request, when bringing the dead server online again every thing starts to act normal again and gets distributed evenly.
I understand. Look here, just in case: https://www.nginx.com/products/nginx/high-availability/
After fiddling back and forth we actually found the culprit.
Removed the checkmark for "Use persistent server mode" on the Logical server object and it works like a charm😀
Great, I am happy it is working for you now. Legacy service note, it still stands 🙂
Every available version of the admin guides, still states that Server Persistency - by server - works and is available to use - however it does not.
If there is an Internal SK note, not publically available, how are we meant to prove to customers that this feature is no longer there and they need a different solution ? Can someone double confirm that Server Persistency cannot work (due to no healthchecking of the servers) and make it public please.
We've recently updated https://support.checkpoint.com/results/sk/sk31162 to list the options that are supported.
It does not explicitly mention the "persistent server" option as unsupported, but I suspect it isn't.
I will see if we can get the SK updated with this.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Wed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesWed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY