This script provided general HA cluster health/any known issues. dos2unix and chmod 777 on the file might be needed before running it.
lab example:
[Expert@CP-FW-01:0]# ./cp_cluster_ha_report.sh
Check Point ClusterXL / HA Report
Generated: Mon Jan 19 15:05:40 EST 2026
Host: CP-FW-01
Output file: /var/log/ha_cluster_report/CP-FW-01_ha_report_20260119_150540.txt
===================================================================
1) System / Platform Context
===================================================================
---- Uptime
$ uptime
15:05:40 up 12 days, 4:36, 1 user, load average: 0.30, 0.41, 0.26
---- OS Release (if present)
$ test -r /etc/os-release && cat /etc/os-release || true
---- CLISH: show version all
$ clish -c "show version all"
Product version Check Point Gaia R81.20
OS build 634
OS kernel version 3.10.0-1160.15.2cpx86_64
OS edition 64-bit
---- Environment (CP variables)
$ env | egrep '^(CPDIR|FWDIR|MDSDIR|MDS_FWDIR|MDS_CPDIR|VSXDIR)=' || true
FWDIR=/opt/CPsuite-R81.20/fw1
MDS_FWDIR=/opt/CPsuite-R81.20/fw1
CPDIR=/opt/CPshrd-R81.20
---- Disk usage
$ df -h
Filesystem Size Used Avail Use% Mounted on
/dev/mapper/vg_splat-lv_current 40G 14G 27G 35% /
/dev/vda2 291M 45M 232M 17% /boot
/dev/mapper/vg_splat-lv_log 50G 17G 34G 34% /var/log
tmpfs 7.6G 36M 7.5G 1% /dev/shm
---- Memory
$ free -m 2>/dev/null || vmstat -s 2>/dev/null || true
total used free shared buff/cache available
Mem: 15419 4191 7048 51 4179 10115
Swap: 8191 0 8191
---- Top CPU processes (snapshot)
$ ps -eo pid,ppid,user,%cpu,%mem,etime,cmd --sort=-%cpu | head -n 25
PID PPID USER %CPU %MEM ELAPSED CMD
8065 8043 admin 11.9 14.4 12-04:35:23 fwk
8394 8006 admin 1.0 1.0 12-04:35:19 cpd
10420 8006 admin 0.7 0.0 12-04:34:43 wsdnsd
8946 7777 admin 0.4 0.0 00:20 sshd: admin [priv]
6 2 admin 0.3 0.0 12-04:36:12 [ksoftirqd/0]
8006 1 admin 0.2 0.0 12-04:35:25 /opt/CPshrd-R81.20/bin/cpwd
9481 8006 admin 0.2 0.0 12-04:35:11 lpd
7187 7164 admin 0.1 0.0 12-04:35:38 /bin/redis-server 127.0.0.1:6379
7258 7164 admin 0.1 0.1 12-04:35:38 /opt/CPsuite-R81.20/fw1/Python/bin/python3.7 /bin/celery -A taskmanager.taskManager.celery worker --loglevel=info --pidfile /tmp/celery.pid --logfile /var/log/celery.log --concurrency 2
8330 8006 admin 0.1 0.1 12-04:35:20 cpview_services
8639 8006 admin 0.1 0.8 12-04:35:17 fwd
8958 8957 admin 0.1 0.0 00:19 -bash
10989 8639 admin 0.1 0.3 12-04:34:39 vpnd 0
10990 8639 admin 0.1 0.3 12-04:34:39 iked 0
10991 8639 admin 0.1 0.2 12-04:34:39 iked 1
10992 8639 admin 0.1 0.2 12-04:34:39 iked 2
1 0 admin 0.0 0.0 12-04:36:12 init [3]
2 0 admin 0.0 0.0 12-04:36:12 [kthreadd]
4 2 admin 0.0 0.0 12-04:36:12 [kworker/0:0H]
7 2 admin 0.0 0.0 12-04:36:12 [migration/0]
8 2 admin 0.0 0.0 12-04:36:12 [rcu_bh]
9 2 admin 0.0 0.0 12-04:36:12 [rcu_sched]
10 2 admin 0.0 0.0 12-04:36:12 [rcuob/0]
11 2 admin 0.0 0.0 12-04:36:12 [rcuos/0]
===================================================================
2) Cluster State (Clish + Expert equivalents)
===================================================================
---- CLISH: show cluster state
$ clish -c "show cluster state"
Cluster Mode: High Availability (Active Up) with IGMP Membership
ID Unique Address Assigned Load State Name
1 (local) 169.254.0.248 100% ACTIVE CP-FW-01
2 169.254.0.247 0% STANDBY CP-FW-02
Active PNOTEs: None
Last member state change event:
Event Code: CLUS-114904
State change: ACTIVE(!) -> ACTIVE
Reason for state change: Reason for ACTIVE! alert has been resolved
Event time: Wed Jan 7 10:31:57 2026
Cluster failover count:
Failover counter: 0
Time of counter reset: Wed Jan 7 10:30:19 2026 (reboot)
---- CLISH: show cluster release
$ clish -c "show cluster release"
Release: R81.20 T634
Kernel build: 997000067
FW1 build: 997000059
FW1 private fixes: HOTFIX_GOT_TPCONF_AUTOUPDATE
HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE
HOTFIX_R81_20_JUMBO_HF_MAIN
HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE
HOTFIX_INEXT_NANO_EGG_AUTOUPDATE
HOTFIX_TEX_ENGINE_R8120_AUTOUPDATE
ID SW release
1 (local) R81.20 T634
2 R81.20 T634
---- CLISH: show cluster failover
$ clish -c "show cluster failover"
Cluster failover count:
Failover counter: 0
Time of counter reset: Wed Jan 7 10:30:19 2026 (reboot)
Cluster failover history (last 20 failovers since reboot/reset on Wed Jan 7 10:30:19 2026):
No. Time: Transition: CPU: Reason:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
No failover was detected since last reboot/reset
---- CLISH: show cluster statistics sync
$ clish -c "show cluster statistics sync"
Delta Sync Statistics
Sync status: OK
Drops:
Lost updates................................. 0
Lost bulk update events...................... 0
Oversized updates not sent................... 0
Sync at risk:
Sent reject notifications.................... 0
Received reject notifications................ 0
Sent messages:
Total generated sync messages................ 16100344
Sent retransmission requests................. 0
Sent retransmission updates.................. 1
Peak fragments per update.................... 1
Received messages:
Total received updates....................... 1219074
Received retransmission requests............. 1
Sync Interface:
Name......................................... eth3
Link speed................................... 1000Mb/s
Rate......................................... 136380[Bps]
Peak rate.................................... 1116 [KBps]
Link usage................................... 0%
Total........................................ 121208[MB]
Queue sizes (num of updates):
Sending queue size........................... 512
Receiving queue size......................... 256
Fragments queue size......................... 50
Timers:
Delta Sync interval (ms)..................... 100
Reset on Wed Jan 7 10:31:57 2026 (triggered by fullsync).
---- cphaprob state (member states)
$ cphaprob state
Cluster Mode: High Availability (Active Up) with IGMP Membership
ID Unique Address Assigned Load State Name
1 (local) 169.254.0.248 100% ACTIVE CP-FW-01
2 169.254.0.247 0% STANDBY CP-FW-02
Active PNOTEs: None
Last member state change event:
Event Code: CLUS-114904
State change: ACTIVE(!) -> ACTIVE
Reason for state change: Reason for ACTIVE! alert has been resolved
Event time: Wed Jan 7 10:31:57 2026
Cluster failover count:
Failover counter: 0
Time of counter reset: Wed Jan 7 10:30:19 2026 (reboot)
---- cphaprob stat (roles/active/standby details)
$ cphaprob stat
Cluster Mode: High Availability (Active Up) with IGMP Membership
ID Unique Address Assigned Load State Name
1 (local) 169.254.0.248 100% ACTIVE CP-FW-01
2 169.254.0.247 0% STANDBY CP-FW-02
Active PNOTEs: None
Last member state change event:
Event Code: CLUS-114904
State change: ACTIVE(!) -> ACTIVE
Reason for state change: Reason for ACTIVE! alert has been resolved
Event time: Wed Jan 7 10:31:57 2026
Cluster failover count:
Failover counter: 0
Time of counter reset: Wed Jan 7 10:30:19 2026 (reboot)
---- cphaprob release (version/hotfix match across members)
$ cphaprob release
Release: R81.20 T634
Kernel build: 997000067
FW1 build: 997000059
FW1 private fixes: HOTFIX_GOT_TPCONF_AUTOUPDATE
HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE
HOTFIX_R81_20_JUMBO_HF_MAIN
HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE
HOTFIX_INEXT_NANO_EGG_AUTOUPDATE
HOTFIX_TEX_ENGINE_R8120_AUTOUPDATE
ID SW release
1 (local) R81.20 T634
2 R81.20 T634
===================================================================
3) Interfaces / Pnotes / Monitoring Health
===================================================================
---- cphaprob -a if (ClusterXL view of interface states)
$ cphaprob -a if
CCP mode: Manual (Unicast)
Required interfaces: 4
Required secured interfaces: 1
Interface Name: Status:
eth0 (LM) UP
eth1 (LM) UP
eth2 (LM) UP
eth3 (S-LM) UP
S - sync, HA/LS - bond type, LM - link monitor, P - probing
Virtual cluster interfaces: 3
eth0 172.16.10.246
eth1 192.168.10.246
eth2 172.31.10.246
---- cphaprob -l list (pnotes / critical devices full list)
$ cphaprob -l list
Built-in Devices:
Device Name: Interface Active Check
Current state: OK
Device Name: Recovery Delay
Current state: OK
Device Name: CoreXL Configuration
Current state: OK
Registered Devices:
Device Name: Fullsync
Registration number: 0
Timeout: none
Current state: OK
Time since last report: 20750.4 sec
Device Name: Policy
Registration number: 1
Timeout: none
Current state: OK
Time since last report: 20748.7 sec
Device Name: routed
Registration number: 2
Timeout: none
Current state: OK
Time since last report: 1.05255e+06 sec
Device Name: cxld
Registration number: 3
Timeout: 30 sec
Current state: OK
Time since last report: 1.05261e+06 sec
Process Status: UP
Device Name: fwd
Registration number: 4
Timeout: 30 sec
Current state: OK
Time since last report: 1.05261e+06 sec
Process Status: UP
Device Name: cphad
Registration number: 5
Timeout: 30 sec
Current state: OK
Time since last report: 1.05258e+06 sec
Process Status: UP
Device Name: Init
Registration number: 6
Timeout: none
Current state: OK
Time since last report: 1.05258e+06 sec
---- cphaprob list (pnotes in problem state summary)
$ cphaprob list
There are no pnotes in problem state
---- CLISH: show cluster members interfaces all
$ clish -c "show cluster members interfaces all"
CCP mode: Manual (Unicast)
Required interfaces: 4
Required secured interfaces: 1
Interface Name: Status:
eth0 (LM) UP
eth1 (LM) UP
eth2 (LM) UP
eth3 (S-LM) UP
S - sync, HA/LS - bond type, LM - link monitor, P - probing
Virtual cluster interfaces: 3
eth0 172.16.10.246
eth1 192.168.10.246
eth2 172.31.10.246
No VLANs are monitored on the member
---- CLISH: show cluster members pnotes all
$ clish -c "show cluster members pnotes all"
Built-in Devices:
Device Name: Interface Active Check
Current state: OK
Device Name: Recovery Delay
Current state: OK
Device Name: CoreXL Configuration
Current state: OK
Registered Devices:
Device Name: Fullsync
Registration number: 0
Timeout: none
Current state: OK
Time since last report: 20751.1 sec
Device Name: Policy
Registration number: 1
Timeout: none
Current state: OK
Time since last report: 20749.4 sec
Device Name: routed
Registration number: 2
Timeout: none
Current state: OK
Time since last report: 1.05255e+06 sec
Device Name: cxld
Registration number: 3
Timeout: 30 sec
Current state: OK
Time since last report: 1.05261e+06 sec
Process Status: UP
Device Name: fwd
Registration number: 4
Timeout: 30 sec
Current state: OK
Time since last report: 1.05261e+06 sec
Process Status: UP
Device Name: cphad
Registration number: 5
Timeout: 30 sec
Current state: OK
Time since last report: 1.05258e+06 sec
Process Status: UP
Device Name: Init
Registration number: 6
Timeout: none
Current state: OK
Time since last report: 1.05258e+06 sec
===================================================================
4) Synchronization Health (Delta Sync / Transport)
===================================================================
---- cphaprob syncstat (Delta Sync statistics)
$ cphaprob syncstat
Delta Sync Statistics
Sync status: OK
Drops:
Lost updates................................. 0
Lost bulk update events...................... 0
Oversized updates not sent................... 0
Sync at risk:
Sent reject notifications.................... 0
Received reject notifications................ 0
Sent messages:
Total generated sync messages................ 16100399
Sent retransmission requests................. 0
Sent retransmission updates.................. 1
Peak fragments per update.................... 1
Received messages:
Total received updates....................... 1219074
Received retransmission requests............. 1
Sync Interface:
Name......................................... eth3
Link speed................................... 1000Mb/s
Rate......................................... 174630[Bps]
Peak rate.................................... 1116 [KBps]
Link usage................................... 0%
Total........................................ 121208[MB]
Queue sizes (num of updates):
Sending queue size........................... 512
Receiving queue size......................... 256
Fragments queue size......................... 50
Timers:
Delta Sync interval (ms)..................... 100
Reset on Wed Jan 7 10:31:57 2026 (triggered by fullsync).
---- cphaprob ldstat (sync serialization statistics)
$ cphaprob ldstat
Operand Calls Bytes Average Ratio %
----------------------------------------------------------
ERROR 0 0 0 0
SET 1582182 456441420 288 3
RENAME 0 0 0 0
REFRESH 2854469 148432988 52 2
DELETE 370191 13245436 35 1
SLINK 657911 42106304 64 5
UNLINK 0 0 0 0
MODIFYFIELDS 2024816 161985304 80 4
RECORD DATA CONN 0 0 0 0
COMPLETE DATA CONN 0 0 0 0
GHTAB SYNC 0 0 0 0
Total bytes sent: 852170088 (852 MB) in 3454370 packets. Average 246
===================================================================
5) Failover History / Counters
===================================================================
---- cphaprob show_failover (up to 50 events if supported)
$ cphaprob -l 50 show_failover || cphaprob show_failover
Cluster failover count:
Failover counter: 0
Time of counter reset: Wed Jan 7 10:30:19 2026 (reboot)
Cluster failover history (last 50 failovers since reboot/reset on Wed Jan 7 10:30:19 2026):
No. Time: Transition: CPU: Reason:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
No failover was detected since last reboot/reset
===================================================================
6) cpstat snapshots (HA + OS + FW policy metadata)
===================================================================
---- cpstat ha -f all
$ cpstat ha -f all
Product name: High Availability
Major version: 6
Minor version: 0
Service pack: 5
Version string: N/A
Status code: 0
Status short: OK
Status long: Refer to the Notification and Interfaces tables for information about the problem
HA installed: 1
Working mode: High Availability (Active Up)
HA protocol version: 2
HA started: yes
HA state: active
HA identifier: 1
Interface table
------------------------------------------------------------------
|Name|IP |Status|Verified|Trusted|Shared|Netmask |
------------------------------------------------------------------
|eth0| 172.16.10.248|Up | 200| 0| 2|255.255.255.0|
|eth1|192.168.10.248|Up | 200| 0| 2|255.255.255.0|
|eth2| 172.31.10.248|Up | 200| 0| 2|255.255.255.0|
|eth3| 169.254.0.248|Up | 200| 1| 2|255.255.255.0|
------------------------------------------------------------------
Problem Notification table
-----------------------------------------
|Name |Status|Priority|Verified|Descr|
-----------------------------------------
|Fullsync|OK | 0| 20751| |
|Policy |OK | 0| 20749| |
|routed |OK | 0| 1052555| |
|cxld |OK | 0| 1052607| |
|fwd |OK | 0| 1052606| |
|cphad |OK | 0| 1052584| |
|Init |OK | 0| 1052579| |
-----------------------------------------
Cluster IPs table
-----------------------------------------------------------------
|Name|IP |Netmask |Member Network|Member Netmask|
-----------------------------------------------------------------
|eth0| 172.16.10.246|255.255.255.0| 172.16.10.0| 255.255.255.0|
|eth1|192.168.10.246|255.255.255.0| 192.168.10.0| 255.255.255.0|
|eth2| 172.31.10.246|255.255.255.0| 172.31.10.0| 255.255.255.0|
-----------------------------------------------------------------
Sync table
----------------------------------
|Name|IP |Netmask |
----------------------------------
|eth3|169.254.0.248|255.255.255.0|
----------------------------------
---- cpstat os -f all
$ cpstat os -f all
Product Name: SVN Foundation
SVN Foundation Major Version: 9
SVN Foundation Minor Version: 9
SVN Foundation Service Pack: 7
SVN Foundation Version String: R81.20
SVN Foundation Build Number: 997000125
SVN Foundation Status code: 0
SVN Foundation Status short: OK
SVN Foundation Status long: OK
OS Name: Gaia
OS Major Version: 3
OS Minor Version: 10
OS Build Number: -
OS SP Major: -
OS SP Minor: -
OS Version Level:
Appliance SN:
Appliance Name: Standard PC (i440FX + PIIX, 1996)
Appliance Manufacturer: Other
Interface configuration table
-------------------------------------------------------------------------------
|Name|Address |Mask |MTU |State|Mac Address |Description |
-------------------------------------------------------------------------------
|lo | 127.0.0.1| 255.0.0.0|65536| 1| |Not supported|
|eth0| 172.16.10.248|255.255.255.0| 1500| 1|50-01-00-04-00-00|Not supported|
|eth1|192.168.10.248|255.255.255.0| 1500| 1|50-01-00-04-00-01|Not supported|
|eth2| 172.31.10.248|255.255.255.0| 1500| 1|50-01-00-04-00-02|Not supported|
|eth3| 169.254.0.248|255.255.255.0| 1500| 1|50-01-00-04-00-03|Not supported|
-------------------------------------------------------------------------------
Routing table
--------------------------------------------------
|Destination |Mask |GateWay |Interface|
--------------------------------------------------
| 0.0.0.0| 0.0.0.0|172.16.10.1|eth0 |
| 169.254.0.0|255.255.255.0| 0.0.0.0|eth3 |
| 172.16.10.0|255.255.255.0| 0.0.0.0|eth0 |
| 172.31.10.0|255.255.255.0| 0.0.0.0|eth2 |
|192.168.10.0|255.255.255.0| 0.0.0.0|eth1 |
--------------------------------------------------
Total Virtual Memory (Bytes): 24758296576
Active Virtual Memory (Bytes): 5565702144
Total Real Memory (Bytes): 16168366080
Active Real Memory (Bytes): 5565702144
Free Real Memory (Bytes): 10602663936
Memory Swaps/Sec: -
Memory To Disk Transfers/Sec: -
CPU User Time (%): 10
CPU System Time (%): 4
CPU Idle Time (%): 86
CPU Usage (%): 14
CPU Queue Length: -
CPU Interrupts/Sec: 837
CPUs Number: 8
Disk Servicing Read\Write Requests Time: -
Disk Requests Queue: -
Disk Free Space (%): 65
Disk Total Free Space (Bytes): 28208582656
Disk Available Free Space (Bytes): 28208582656
Disk Total Space (Bytes): 42939187200
Processors load
---------------------------------------------------------------------------------
|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|
---------------------------------------------------------------------------------
| 1| 0| 0| 0| 0| ?| 104114|
| 2| 0| 0| 0| 0| ?| 104114|
| 3| 0| 0| 0| 0| ?| 104114|
| 4| 0| 0| 0| 0| ?| 104114|
| 5| 0| 0| 100| 0| ?| 104113|
| 6| 0| 0| 0| 0| ?| 104113|
| 7| 0| 0| 0| 0| ?| 104113|
| 8| 0| 0| 100| 0| ?| 104113|
---------------------------------------------------------------------------------
Partitions space
-----------------------------------------------------------------------------------------------------------------
|Partition|Size (bytes)|Used (bytes)|Free total (bytes)|Free total (%)|Free available (bytes)|Free available (%)|
-----------------------------------------------------------------------------------------------------------------
|/ | 42939187200| 14730604544| 28208582656| 65| 28208582656| 65|
|/boot | 304624640| 46370816| 258253824| 84| 242525184| 79|
|/var/log | 53664546816| 18010083328| 35654463488| 66| 35654463488| 66|
-----------------------------------------------------------------------------------------------------------------
System Time: 1768853143
System Start Time: 1767799768
---- cpstat os -f sensors (if supported)
$ cpstat os -f sensors
Temperature Sensors
-----------------------------
|Name|Value|Unit|Type|Status|
-----------------------------
-----------------------------
Fan Speed Sensors
-----------------------------
|Name|Value|Unit|Type|Status|
-----------------------------
-----------------------------
Voltage Sensors
-----------------------------
|Name|Value|Unit|Type|Status|
-----------------------------
-----------------------------
---- cpstat fw -f policy (if supported)
$ cpstat fw -f policy || cpstat fw -f all || true
Product name: Firewall
Policy name: LAB-POLICY-Andy
Policy install time: Mon Jan 19 09:19:27 2026
Num. connections: 44
Peak num. connections: 805
Connections capacity limit: 0
Total accepted packets: 23149436
Total dropped packets: 33633
Total rejected packets: 0
Total accepted bytes: 6366719632
Total dropped bytes: 7286869
Total rejected bytes: 0
Total logged: 11013
Interface table
------------------------------------
|Name|Dir|Accept |Drop|Reject|Log |
------------------------------------
|eth0|in | 7610356| 33| 0|2656|
|eth0|out|10186500| 0| 0|2627|
|eth1|in | 754985| 0| 0| 356|
|eth1|out| 0| 0| 0| 0|
|eth2|in | 754985| 0| 0| 356|
|eth2|out| 0| 0| 0| 0|
|eth3|in | 4121634| 0| 0|1983|
|eth3|out| 0| 0| 0| 0|
------------------------------------
| | |23428460| 33| 0|7978|
------------------------------------
Interface table (64-bit)
------------------------------------
|Name|Dir|Accept |Drop|Reject|Log |
------------------------------------
|eth0|in | 7610356| 33| 0|2656|
|eth0|out|10186500| 0| 0|2627|
|eth1|in | 754985| 0| 0| 356|
|eth1|out| 0| 0| 0| 0|
|eth2|in | 754985| 0| 0| 356|
|eth2|out| 0| 0| 0| 0|
|eth3|in | 4121634| 0| 0|1983|
|eth3|out| 0| 0| 0| 0|
------------------------------------
| | |23428460| 33| 0|7978|
------------------------------------
===================================================================
7) Kernel / Acceleration context (helpful for HA investigations)
===================================================================
---- fw ver
$ fw ver
This is Check Point's software version R81.20 - Build 059
---- fwaccel stat
$ fwaccel stat
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+---------------------------------------------------------------------------------+
|0 |KPPAK |enabled |eth0,eth1,eth2,eth3 |Acceleration,Cryptography |
| | | | | |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+---------------------------------------------------------------------------------+
Accept Templates : enabled
Drop Templates : enabled
NAT Templates : enabled
LightSpeed Accel : disabled
---- fw ctl iflist (fallback)
$ fw ctl iflist
1 : eth0
2 : eth1
3 : eth2
4 : eth3
---- fw ctl pstat (tail, fallback)
$ fw ctl pstat | tail -n 60
Virtual System Capacity Summary:
Physical memory used: 21% (2765 MB out of 13106 MB) - below watermark
Kernel memory used: 3% (508 MB out of 13106 MB) - below watermark
Virtual memory used: 16% (2214 MB out of 13106 MB) - below watermark
Used: 2214 MB by FW, 1152 MB by zeco
Concurrent Connections: 47 (Unlimited)
Aggressive Aging is enabled, not active
Kernel memory (kmem) statistics:
Total memory bytes used: 1248837277 peak: 1710662726
Allocations: 1470661164 alloc, 0 failed alloc
1468970716 free, 0 failed free
Cookies:
1124080856 total, 0 alloc, 0 free,
12 dup, 2944151813 get, 689139992 put,
2515261096 len, 692097519 cached len, 0 chain alloc,
0 chain free
Connections:
370248 total, 278394 TCP, 91822 UDP, 24 ICMP,
8 other, 0 anticipated, 1 recovered, 47 concurrent,
805 peak concurrent
Fragments:
0 fragments, 0 packets, 0 expired, 0 short,
0 large, 0 duplicates, 0 failures
NAT:
341060881/0 forw, 342851406/0 bckw, 684573463 tcpudp,
2010 icmp, 619276-351351 alloc
Sync: Run "cphaprob syncstat" for cluster sync statistics.
===================================================================
8) Routing / Interface inventory
===================================================================
---- ip addr
$ ip addr show
1: lo: <LOOPBACK,MULTICAST,NOARP,AUTOMEDIA,PORTSEL,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether 50:01:00:04:00:00 brd ff:ff:ff:ff:ff:ff
inet 172.16.10.248/24 brd 172.16.10.255 scope global eth0
valid_lft forever preferred_lft forever
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether 50:01:00:04:00:01 brd ff:ff:ff:ff:ff:ff
inet 192.168.10.248/24 brd 192.168.10.255 scope global eth1
valid_lft forever preferred_lft forever
4: eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether 50:01:00:04:00:02 brd ff:ff:ff:ff:ff:ff
inet 172.31.10.248/24 brd 172.31.10.255 scope global eth2
valid_lft forever preferred_lft forever
5: eth3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether 50:01:00:04:00:03 brd ff:ff:ff:ff:ff:ff
inet 169.254.0.248/24 brd 169.254.0.255 scope global eth3
valid_lft forever preferred_lft forever
6: gre0@NONE: <NOARP> mtu 1476 qdisc noop state DOWN qlen 1000
link/gre 0.0.0.0 brd 0.0.0.0
7: gretap0@NONE: <BROADCAST,MULTICAST> mtu 1462 qdisc noop state DOWN qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff
---- ip route
$ ip route show
default via 172.16.10.1 dev eth0 proto 7
169.254.0.0/24 dev eth3 proto kernel scope link src 169.254.0.248
172.16.10.0/24 dev eth0 proto kernel scope link src 172.16.10.248
172.31.10.0/24 dev eth2 proto kernel scope link src 172.31.10.248
192.168.10.0/24 dev eth1 proto kernel scope link src 192.168.10.248
---- arp table
$ ip neigh show || arp -an || true
192.168.10.247 dev eth1 lladdr 50:01:00:05:00:01 STALE
172.16.10.188 dev eth0 lladdr 50:00:00:02:00:00 STALE
172.16.10.177 dev eth0 lladdr 50:01:00:03:00:00 STALE
169.254.0.247 dev eth3 lladdr 50:01:00:05:00:03 STALE
172.16.10.247 dev eth0 lladdr 50:01:00:05:00:00 STALE
172.31.10.247 dev eth2 lladdr 50:01:00:05:00:02 STALE
172.16.10.1 dev eth0 lladdr 48:3a:02:96:47:2d REACHABLE
172.16.10.252 dev eth0 lladdr 50:01:00:0f:00:00 REACHABLE
===================================================================
9) Completion
===================================================================
Report complete.
Saved to: /var/log/ha_cluster_report/CP-FW-01_ha_report_20260119_150540.txt
[Expert@CP-FW-01:0]#
Best,
Andy