- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
Has anyone seen this issue before?
Upgraded Firewall from R81.10 to R81.20. After rebooy and push policy to the upgraded Firewall, am not able to login into the Firewall. It looks healthy and good on the Smart Console.
When I checked the the Active member, it shows me this below that the secondary is LOST. TO WHERE, I ASKED.
1 (local) 10.64.0.252 100% ACTIVE(!)
2 none 0% LOST
Active PNOTEs: LPRB, IAC
Last member state change event:
Event Code: CLUS-110305
State change: ACTIVE -> ACTIVE(!)
Reason for state change: Interface eth2.203 is down (Cluster Control Protocol packets are not received)
Attached is the error.
Regards
Olu
you say "it looks healthy on smart console"
are you saying both cluster members have SIC established and are reachable from the management?
does it respond to ssh on any of the interfaces?
What about via the sync from the active firewall?
Have you LOM access or physical access to check console?
Hi Gojira,
you say "it looks healthy on smart console" - Yes on Smart Console is Green
are you saying both cluster members have SIC established and are reachable from the management? Both have SIC Established
does it respond to ssh on any of the interfaces? It does not respond to https from all the interfaces, so I presume ssh will not work as well.
What about via the sync from the active firewall? Tried (ssh myusername@ipaddress) from the active Firewall.
It is a very strange one to be honesst and MVC is ON as well.
Had the same issue today. Have you tried to login via sync interface from the active one. That worked for me.
After that I did a "cphaconf mvc on" and everything was fine.
Hi Oliver,
I tried it already, it says "connection time out."
If SIC from management is working fine, you can use cprid_util from management to execute any command(s).
Ok will try it.
Thanks
Olu
Hi Oliver, a quick question please. Which command did you use to login from Active to the Standby.
ssh username@ip address - Is this correct
Thanks
Thanks Legend. Much Appreciated.
For you, no charge ; - )
By the way, forgot to mention, to me, appears that based on the output in your original post, clearly if the other member shows as lost, then clustering is broken. Can you check below commands:
cphaprob -a if
cphaprob -i list
cphaprob -l list
cphaprob syncstat
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 40 | |
| 21 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY