- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi All,
Has anyone seen this issue before?
Upgraded Firewall from R81.10 to R81.20. After rebooy and push policy to the upgraded Firewall, am not able to login into the Firewall. It looks healthy and good on the Smart Console.
When I checked the the Active member, it shows me this below that the secondary is LOST. TO WHERE, I ASKED.
1 (local) 10.64.0.252 100% ACTIVE(!)
2 none 0% LOST
Active PNOTEs: LPRB, IAC
Last member state change event:
Event Code: CLUS-110305
State change: ACTIVE -> ACTIVE(!)
Reason for state change: Interface eth2.203 is down (Cluster Control Protocol packets are not received)
Attached is the error.
Regards
Olu
you say "it looks healthy on smart console"
are you saying both cluster members have SIC established and are reachable from the management?
does it respond to ssh on any of the interfaces?
What about via the sync from the active firewall?
Have you LOM access or physical access to check console?
Hi Gojira,
you say "it looks healthy on smart console" - Yes on Smart Console is Green
are you saying both cluster members have SIC established and are reachable from the management? Both have SIC Established
does it respond to ssh on any of the interfaces? It does not respond to https from all the interfaces, so I presume ssh will not work as well.
What about via the sync from the active firewall? Tried (ssh myusername@ipaddress) from the active Firewall.
It is a very strange one to be honesst and MVC is ON as well.
Had the same issue today. Have you tried to login via sync interface from the active one. That worked for me.
After that I did a "cphaconf mvc on" and everything was fine.
Hi Oliver,
I tried it already, it says "connection time out."
If SIC from management is working fine, you can use cprid_util from management to execute any command(s).
Ok will try it.
Thanks
Olu
Hi Oliver, a quick question please. Which command did you use to login from Active to the Standby.
ssh username@ip address - Is this correct
Thanks
Thanks Legend. Much Appreciated.
For you, no charge ; - )
By the way, forgot to mention, to me, appears that based on the output in your original post, clearly if the other member shows as lost, then clustering is broken. Can you check below commands:
cphaprob -a if
cphaprob -i list
cphaprob -l list
cphaprob syncstat
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
9 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 | |
5 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY