- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
One of the VSs (out of 4), started reporting today:
State: Connection with 'fw-vsx-n01' is lost
There are no issues reported from the SSH session -- this node is active and handles the load.
cphaprob state, cphaprob -a if, cphaprob -ia list, revealed nothing wrong.
Tried to reboot the management but it didn't help.
Management: R81.20 Take 65
CP VSX: R81.20 Take 90
Thank you.
The https://support.checkpoint.com/results/sk/sk101484 said:
[ERROR] CPD (pid_of_cpd) did not send keep-alive message for x number of times
What does 'vsx stat -v' show?
Looks healthy too.
The one that is complaining about one of the nodes being down is VS5 (fw-vs-cloud):
VSX Gateway Status
==================
Name: fw-vsx-ext-n01
Access Control Policy: fw-vsx-external-vsx
Installed at: 14Jan2025 15:27:58
Threat Prevention Policy: <No Policy>
SIC Status: Trust
Number of Virtual Systems allowed by license: 6
Virtual Systems [active / configured]: 3 / 3
Virtual Routers and Switches [active / configured]: 2 / 2
Total connections [current / limit]: 32393 / 96500
Virtual Devices Status
======================
ID | Type & Name | Access Control Policy | Installed at | Threat Prevention Policy | SIC Stat
-----+-------------------------+-----------------------+-----------------+--------------------------+---------
1 | S fw-vs-test | fw-vs-test-policy | 23Jan2025 16:18 | <No Policy> | Trust
2 | W vsw-ext | <Not Applicable> | | <Not Applicable> | Trust
3 | W vsw-transit | <Not Applicable> | | <Not Applicable> | Trust
4 | S fw-vs-ext | fw-vs-ext-policy | 27Jan2025 11:47 | <No Policy> | Trust
5 | S fw-vs-cloud | fw-vs-cloud-policy | 24Jan2025 11:00 | <No Policy> | Trust
Type: S - Virtual System, B - Virtual System in Bridge mode,
R - Virtual Router, W - Virtual Switch.
Maybe the cpd process crashes.
Have a look at on this: https://support.checkpoint.com/results/sk/sk101484
What does cpwd.elg say?
Akos
Hi @AkosBakos
No, this is the first time it happened.
I checked cpwd.elg on the affected node, and although I see 'did not send keep-alive message for 1 number of times' error messages, none of them are related to CPD, but rather MSGD:
[cpWatchDog 19785 4133372096]@fw-vsx-n01[27 Jan 11:47:49] [ERROR] MSGD (pid=30558) did not send keep-alive message for 1 number of times
[cpWatchDog 19785 4133372096]@fw-vsx-n01[27 Jan 11:49:34] [ERROR] MSGD (pid=30661) did not send keep-alive message for 1 number of times
The https://support.checkpoint.com/results/sk/sk101484 said:
[ERROR] CPD (pid_of_cpd) did not send keep-alive message for x number of times
Hi @AkosBakos
Yes, but SK mentions that it's CPD daemon that is reporting the error. In my case it's MSGD -- do you think it's the same?
There are no traces of core dumps in the logs and no high CPU observed. SIC is also fine. I haven't tried to push the policy on the affected VS though.
Because the lack of information, I can't say this is the same or not, but there are symptomes which are the same.
In this case, the best thing what you can do to ask the TAC about this issue.
Akos
Concur, anything of note flagged in HCP ?
Otherwise some suggestions:
- Attempt policy install
- Restart cpd per sk97638
- Failover / Reboot gateways
- Patch with latest recommended JHF
- Open a TAC case (attach HCP & CPinfo)
Thank you for the hint @AkosBakos !
With the help of our CP partner the issue has been identified. CPD crashed and was failing to restart since then. No CPEPS database corruption has been observed, so killing the stale process and stopping/starting CPD manually in the context of affected VS fixed the issue.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 37 | |
| 19 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY