- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I failed over management servers yesterday. I failed back to the server we normally use as Active, and now the standby keeps resetting itself to active so I have a clash
I have a ticket open, but has anybody else seen this?
Here is the TAC solution. Trying it now.
Solution
An SMS in a Management HA setup should never set itself active without human intervention. Are you saying that you started with the Primary in active and Secondary in standby, then you set Secondary active (and Primary went standby), then you set Primary back to active (and Secondary went standby), and now you are saying the Secondary went active again on its own? Are you seeing a state of "Advanced" or "Collision"?
I am seeing collision.
Due to an earlier issue, we normally run our Secondary as the Active, and our Primary as the Backup, and all is fine.
I made the primary active yesterday, then made the secondary active again. I can set the primary as standby and do a full sunc, then a few minutes later I get the error that says both are active
If you are in a collision state you must force a manual sync to get back into the usual active/standby. Because both SMSs have changes, you need to pick a "winner" and a "loser". The winner syncs over top of the loser; any changes on the loser are lost except I think for SIC certificate changes/revocations which are merged. Would be a great idea to take backups of both SMSs first just in case you overwrite the "wrong" changes that you actually needed, as a manual sync cannot be undone.
A manual sync does not resolve the problem.
It shows a successful sync, then some minutes later back to collision.
Yep, that would be a TAC case then.
Here is the TAC solution. Trying it now.
Solution
I could be wrong when I say this, as I had not set and played with mgmt HA in some time, but I dont believe there is a preempt option in dashboard like you can set for gateways where one member can always act as master even when it comes back after reboot. I think that for mgmt HA, you have to do that manually if you want to fail them over. Now, from what you described, that sort of behaviour does not sound normal to me. Are there any logs you can see either in dashboard or command line? Maybe messages file, any core dumps?
Yeah, I did a manual failover, and a manual failback, but the failback didn't 'stick' on one of the boxes. Trying the TAC fix now.
Ok, great, let us know if that works. I think I seen that procedure before, I believe there is an sk for that. Hope it goes well.
It does sound odd. The real question is what's triggered this behaviour ie. what's the root cause of the issue.
Silly question but what values are returned when you run the following on both SMS appliances?
cprod_util FwIsActiveManagement
Primary Should = 1
Secondary Should = 0
Both devices returned 1, which explains the problem.
Since I set the standby to zero, it appears to be working.
What is interesting is that it didn't work from the GUI
Yes, thats very odd indeed. Let us know if they ever find a reason why it happened, I would be curious to know.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY