- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi All,
i have HA Checkpoint 16000 using VSX mode. i found this difference file fwkern.conf is exist on active device but not on standby device. this is mandatory by design or not?
any some one else same this issue?
[Expert@Active_Device-03:0]# cat /opt/CPsuite-R80.30/fw1/boot/modules/fwkern.conf
fwha_enable_state_machine_by_vs=0
[Expert@Active_Device-03:0]#
[Expert@Standby_Device-03:0]# less /opt/CPsuite-R80.30/fw1/boot/modules/fwkern.conf
/opt/CPsuite-R80.30/fw1/boot/modules/fwkern.conf: No such file or directory
thanks.
This file is created/modified manually. This does not exist after clean-installation. All kernel values have to be set on both nodes.
So just create it on second node and add the same values as already given in node 1
According to sk26202, fwkern.conf does not exist - it has to be created manually if used. Kernel parameter fwha_enable_state_machine_by_vs can not be found in any documentation / sk, so i assume you would need CP to know why it was used here at all, and only on one cluster node...
thanks for your reply.
do you know function fwkern.conf? any document explain it?
Rochim,
Fwkern.conf is a file created manually. In your case, just create the file on missing cluster member.
More details you can see on: Changing the kernel global parameters for Check Point Security Gateway
Regards,
Alisson Lima
hi
thanks for your reply, i want to know what function fwker and what means attribute "fwha_enable_state_machine_by_vs=0"
@firewall1-gx wrote:...Fwkern.conf is a file created manually...
That is not completely true. To my knowledge the file could be created by cpconfig.
fwha_enable_state_machine_by_vs indicates if VSLS is enabled or not which is a property controllable by cpconfig.
Could it be something linked to the 16K series though? I operate some in VSX (R80.40) and fwkern.conf exists with fwha_enable_state_machine_by_vs set to 1.
Edit: might be a Kernel 3.10 or something linked to some HFA thing. I checked another cluster of high-end VSX appliances running up-to-date R80.30 and the file is also there with the value set to 1.
hi,
the file existing on both device? i only missing on standby device.
@Alex- Just had a look on a 23k device on our side running R80.10 and this value is present here as well. Don't have the function of this value in mind as well.
When kernel values to be set, file has to exist on both nodes to be effective as well when failover node gets active.
I would assume this to be about machine state - active or standby - being different per VS, a feature that sounds more like VSLS, not HA VSX...
Yes, agree. The key message was just to have it not just on one side 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 14 | |
| 10 | |
| 10 | |
| 8 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Tue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityWed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceTue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityWed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY