- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I am new to Checkpoint Quantum Spark, and I am experiencing an issue where configurations are not syncing after a failover. I have set up High Availability (HA) with local management and attempted a failover, but the configuration on the primary device is not syncing to the secondary one. Is this normal, or do I need to configure the policy on both devices? Is this setup similar to VRRP?
Hi,
Configuration should synchronize in Spark cluster setup.
Your issue may be related to SIC failure between the members.
In order to verify SIC is valid you can test file copying between the members over SIC channel. This is an example of a command you can initiate from the primary member, assuming you are using default Sync settings:
cprid_util getfile -local_file /logs/test_pt -remote_file /pfrm2.0/bin/pt -server 10.231.149.2
If /logs/test_pt is successfully created then SIC and communication between the members is functioning well. If not then please issue support ticket and include return value of this command.
Thanks.
Could you also confirm the firmware version/build used, is it R81.10.10 or something else?
Currently it is R81.10.08. I will upgrade to R81.10.10 and will try it.
My understanding is configuration is supposed to sync.
Make sure you've configured the cluster per: https://support.checkpoint.com/results/sk/sk121096
There are debug instructions below that might provide some useful information...possibly may need to involve TAC.
I saw that same sk Phoneboy gave you. Debug commands should be same, but you can also try run below ones to make sure all matches.
Andy
cphaprob roles
cphaprob state
cphaprob -a if
cphaprob -i list
cphaprob -l list
cphaprob syncstat
@the_rock , I have checked all command which you provided. But, unfortunately config is still not SYNC although all command outputs are same. As i noticed, config are SYNC in only a few minute after HA setup, then not SYNC anymore. Is there any special procedure to SYNC the configuration?
Not that I can think of. Just make sure everything matches on both devices and that you followed sk Phoneboy gave, which also does contain debug process. Not sure if cphastop and cphastart commands wotk on SMB or not, but you can try. If reboot if possible, I would do that as well.
Otherwise, would call TAC and see if you can do remote.
Andy
Hi,
Configuration should synchronize in Spark cluster setup.
Your issue may be related to SIC failure between the members.
In order to verify SIC is valid you can test file copying between the members over SIC channel. This is an example of a command you can initiate from the primary member, assuming you are using default Sync settings:
cprid_util getfile -local_file /logs/test_pt -remote_file /pfrm2.0/bin/pt -server 10.231.149.2
If /logs/test_pt is successfully created then SIC and communication between the members is functioning well. If not then please issue support ticket and include return value of this command.
Thanks.
Could you also confirm the firmware version/build used, is it R81.10.10 or something else?
Currently it is R81.10.08. I will upgrade to R81.10.10 and will try it.
Glad that worked for you!
Andy
After upgrading to R81.10.10, the issue was resolved. Thanks for your support.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
4 | |
3 | |
3 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY