- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi All,
I'm building a new VSX in our environment and noticed that when creating virtual systems, they are not being created with HA and keep giving the 'HA module not started' when running the cphaprob stat command. i can't seem to figure out how to turn this on. Does anyone have any insight on this? I do have a TAC case open but figured I'd try to get some knowledge here as well.
This VSX cluster does have VSLS enabled.
HA status is, at least partially, a function of the installed policy.
No policy, no HA.
Have you installed policy to the VS in question?
Also what version/JHF is this?
This is on R81.20 take 84.
The policy actually keeps failing to push on the VS due to updatable object issue saying the package is missing on the gateway. I'm thinking this might be something related to DNS, as I've seen this error before due to a DNS issue.
I will say tho also, shouldnt the Virtual systems be automatically created with HA? regardless of a DNS issue.
HA status is, at least partially, a function of the installed policy.
No policy, no HA.
Thank you PhoneBoy. I definitely did not realize that the HA would show as not started if there was no policy.
Just to keep this thread up to date. it looks like the team who configured the switch side of things had changed the native vlan from the default, which is not supported. once that was changed back to default, we were able to push policy.
sk120684 documents this when working with Bonds.
As already mentioned, you have to install policy after VS creation.
If you have troubles with policy installation for existing policy package, try to create new policy package with any-any-any-drop rule as the only rule and install it on newly created VS.
We did try this and still failed. I will need to dig deeper internally once again and see if the networking side of things is configured properly. Thank you
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 40 | |
| 26 | |
| 14 | |
| 13 | |
| 11 | |
| 11 | |
| 10 | |
| 9 | |
| 8 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY