- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I am facing serious problems in my 5600 two node cluster running R80.30. PBR ist active since we installed them 2 years ago running fine.
Over the last months every change in Gaia on routing, ospf or similar is followd by a pnote event causing the cluster to switch over. Doing the chnages on the other node causes the same vice versa. Also doing changes on the passive node creates pnote event. We checked config several times for inequality, but its fine. So this was the time to inolve TAC and my service partner created a support ticket.
Now Checkpoint points to SK100500, where several features/blades are mentioned to be incompatible with PBR, e.g. URL Filtering, IPS and VPN Features and refuses any further investigations on the case.
Here is a discussion on thes limitation, questioning the real meaning of limitation and aksing for a Checkpoint Official to comment on it, but theres no answering.I can not believe that such core features like IPS is not compatible with PBR and would like to have this analyzed and commented.
Its like a car manufacturer saying that driving a right turn is not supported if there are more than 2 persons in the car...
I have severe problems and curently no chance to get further support from Checkpoint
In this thread the members @Peter_Lyndley and @FedericoMeiners have similar problems and doubts about this limitation.
Thanks for any contribution
Frank
Hi PhoneBoy,
did you get any furter information on these limitations? There is a new sk167135, but limitation are the same.... very annoying...
URLF is definitely a limitation, IPS doesn't work with certain protections as I recall.
This does indeed sound like routed is crashing, which is what needs to be looked at. For sure engage support about the pnote. I'm gussing you have core files in /var/log/dump/usermode. Also you can enable tracing on routed which will create a log file /var/log/routed.log.
trace ospf all on
trace kernel all on
trace global all on
something like that. Use off to disable. Once tracing is enabled (do on both members btw) and the cluster is active/standby make a change known to cause the problem then check those files on both members.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY