- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
we have a centrally managed 1550 Cluster XL running R80.20.15 - Build 682
when i try to install policy it always fails on the active member and installs on the standby no issues.
The message is indicating a memory error but the boxes do not seem to be running out of memory.
[Expert@GW1]# free -m
total used free shared buffers cached
Mem: 2000884 1677392 323492 46460 12196 516604
-/+ buffers/cache: 1148592 852292
Swap: 0 0 0
I've had a ticket open with TAC for about 10 days with still no resolution . Though I would check in the forums for any ideas?
[Expert@GW2]# free -m
total used free shared buffers cached
Mem: 2000884 1738000 262884 56924 8056 560276
-/+ buffers/cache: 1169668 831216
Swap: 0 0 0
This post should be in SMB ! What happens if you do a policy pull on the active node ? What happens after a failover ?
I've manually forced a failover and tried that as well. again it will ONLY fail on the active member of the ClusterXL.
I've only tried pushing policy from the MDS
Connect using SSH to each node and issue
# fetch policy mgmt-ipv4-address <sms IP>
same message on both :
HQ-FW2> fetch policy mgmt-ipv4-address x.x.x.x
Fetching policy from x.x.x.x
Fetching Security Policy from 'x.x.x.x'
Local Security Policy is Up-To-Date.
Installing Security Policy...
IPS package: Compiled OK.
Installing Security Policy Succeeded.
Done.
sfw_mac_filtering_config: ioctl SFW_MAC_FILTERING failed.
ioctl 43 to the sim device failed (ppak_id=0, rc=-1, errno=22)
sim_arp_spoofing: ioctl to the SecureXL device failed -1
Unable to configure anti ARP spoofing
sk167416 - "sfw_mac_filtering_config: ioctl SFW_MAC_FILTERING failed" message when pushing policy on a 1500 device
Both nodes have the current policy - alter the policy, install and try on the failing node again.
install via fetch or via sms push?
What version/JHF are you pushing from?
Also, has TAC asked you to debug the policy installation process yet?
Send the SR number in a PM.
80.40 take 89
yes they have taken a debug during policy push and nothing has been resolved yet.
i will send the SR in a PM
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY