- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
After updating our Security gateway from 80.40 to 81.10 it shows "HA module not started" when querying for cphaprob state.
Gaia is also not available anymore.
Cphastart, reboot, ... does not seem to fix the issue.
When you do a version upgrade on a gateway, the relevant object must be changed to the target version and the policy installed after the upgrade completes.
This is documented in the Install and Upgrade Guide and is a mandatory step.
Without doing it, you will experience exactly what you're seeing since the previously installed policy is no longer valid.
In this case, the DefaultFilter loads and the gateway will be generally inaccessible over the network until the policy is installed again.
You are looking to the wrong part of the upgrade guide. Look into the Cluster Upgrade chapter: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Gui...
You need to install policy to the new upgraded Cluster Member, it can only be done after updating the cluster object version on the management side.
When you do a version upgrade on a gateway, the relevant object must be changed to the target version and the policy installed after the upgrade completes.
This is documented in the Install and Upgrade Guide and is a mandatory step.
Without doing it, you will experience exactly what you're seeing since the previously installed policy is no longer valid.
In this case, the DefaultFilter loads and the gateway will be generally inaccessible over the network until the policy is installed again.
Thank you for your reply.
I've followed the white page "Upgrade Options and Prerequisites" and "Upgrade of Security Gateways and Clusters".
I didn't see any mention of updating the cluster object.
Now I have a gateway on R81.10 and 1 on R80.40 with the R80.40 the only one working at this moment.
So I have to set the Cluster Object to R81.10 and the R81.10 gateway will work again?
Here I have found that you only need to update the object version after updating the secondary server (step 9). https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Gui...
You are looking to the wrong part of the upgrade guide. Look into the Cluster Upgrade chapter: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Gui...
You need to install policy to the new upgraded Cluster Member, it can only be done after updating the cluster object version on the management side.
You do have to put the cluster object in SmartConsole in R81.10. And install policy in the cluster unchecking the box of installing in all members or not install. (In fact the installation will fail in the member still in R80.40, it´s normal).
After installing the policy you will see the member in the cluster with cphaprob stat (it will be in ready state because of another member with older version).
If the policy installation fails in the R81.10 member use the fw unloadlocal and retry
Make sure as @PhoneBoy said to confirm that cluster object is indeed set to R81.10 on smart console for the cluster. If you can ssh into the appliance, verify the policy by running fw stat.
IF it shows initial policy, that should let person at least ssh into the box AND also web UI, but only on port 443, nothing else. If you use a different port for web UI, then you can just run fw unloadlocal and access it,
However, if fw stat shows defaultfilter, you have no choice but to run fw unloadlocal, as defaultfilter blocks everything.
Hope that helps.
Andy
What does your tail -f $FWDIR/log/cpconf.elg log says? and cphamcset.elg?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 10 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY