Hello everybody,
we are having a Cluster of 12600 appliances, having a policy with 800 rules and only very very less traffic (< 100Mbit/s, 5000 concurrent Connections) and very less CPU load.
in the beginning we had 200s configured, then we noticed that secondary was going down when doing policy install. We opened a ticket and Support suggested us to increase timeout.
So we increased from 200 - 300s and then a week later from 300 to 600. Did not solve the Problem.
We did not reboot but we did "fw ctl set int fwha_freeze_state_machine_timeout" to modify it live.
Any suggestions:
- how to measure a usefull freeze_timeout for am policy install?
- which values are usefull to set and which value we should not exceed?
Regards