Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sanjay_S
Advisor
Jump to solution

ClusterXL

Hi Guys, Need a help with the ClusterXL issue. We have High Availability between 2 firewalls(ClusterXL). In the active firewall the output of 'cphaprob stat' shows Active/Down, however in the standby firewall shows Active/Standby. In the tracker when i checked the information contains CCP we got these packets with the info (cluster_info: (ClusterXL) CCP was not heard from member 2 on ifn ethx.xxx. Please check network configuration.) Could you please help us in fixing this issue.

0 Kudos
1 Solution

Accepted Solutions
HeikoAnkenbrand
Champion Champion
Champion

Hi @Sanjay_S ,

Check this on both members:

- is the OS version the same (fw ver)
- check 32/64 bit     (uname -all)
- check the cluster id     (tcpdump -vv -nn -e -i <ethX> port 8116)
- check ccp (broadcast, multicast, unicast). (cphaprob-a if)
- check interface issues  (cphaprob -a if)
- check CoreXL (cpconfig > CoreXL)
- check long cluster error message (cpstat ha -f all)

59B6EA34-F11A-4BBD-AF06-F5FE64F6D3A7.jpeg

More infos to cluster id and ccp can you found  here:
R80.x - cheat sheet - ClusterXL

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

View solution in original post

6 Replies
Marco_Valenti
Advisor

On the active meber

output of cphaprob -a if

output of cphaprob -ia list

did you try to cpstop ; cpstart problematic memeber yet?

Sumanth_Parvath
Explorer

Hi Sanjay, How did you guys resolve this issue??? We've two 23800's configured in Cluster running on R80.10 Take-42 since December-2017. Recently we discovered the same issue as yours, In the active firewall the output of 'cphaprob stat' shows Active/Down, however in the standby firewall shows Active/Standby.We tried cpstop & cptstart and rebooted problematic one, but that doesn't resolved our issue.

0 Kudos
Vanesa_Benito_O
Contributor

Hi Sanjay, How did you guys resolve this issue??? I've two appliance configured in Cluster running on R80.30 Take-200. Recently we discovered the same issue as yours, I tried cpstop & cptstart and rebooted problematic one, but that doesn't resolved our issue.
Can you tell me the SK where it is said how to solve the problem?

0 Kudos
Chinmaya_Naik
Advisor

Hi

It's interesting

Which version are you running ?

Are you able to do failover successfully?

update the below output.

cphaprob stat

cphaprob -a if

cphaprob -ia if

fwaccel stat

fw ctl affinity -l -r

0 Kudos
_Val_
Admin
Admin

Wither cluster ID or CoreXL are not the same on both members. 

0 Kudos
HeikoAnkenbrand
Champion Champion
Champion

Hi @Sanjay_S ,

Check this on both members:

- is the OS version the same (fw ver)
- check 32/64 bit     (uname -all)
- check the cluster id     (tcpdump -vv -nn -e -i <ethX> port 8116)
- check ccp (broadcast, multicast, unicast). (cphaprob-a if)
- check interface issues  (cphaprob -a if)
- check CoreXL (cpconfig > CoreXL)
- check long cluster error message (cpstat ha -f all)

59B6EA34-F11A-4BBD-AF06-F5FE64F6D3A7.jpeg

More infos to cluster id and ccp can you found  here:
R80.x - cheat sheet - ClusterXL

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events