Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Adam276
Contributor

Change cluster interface to private and required interfaces count didn't change

I changed a cluster interface from cluster to private (non-monitored) after years of being used as a cluster, The number of required interfaces from the output of 'cphaprob -a if' didn't get reduced.  All the interfaces show the correct status as UP or non-monitored but the required interfaces in the 'cphaprob -a if' command still has the old count so the cluster is Primary ACTIVE attention and secondary is DOWN.  The interfaces were already in DOWN state before the Smartdashboard change to change it to private and policy install was done.

According to checkpoint docs, if the number doesn't decrease, you should reboot the firewalls (standby first).  It appears the firewalls keep a running total of expected number of interfaces since it was rebooted and doesn't seem to recheck the count with policy.

My question is can you just do a clusterXL_admin down and up to reset that count or does it really require a reboot of the gateways?  I suspect it requires a reboot but was hoping someone knows.

0 Kudos
1 Reply
the_rock
Legend
Legend

I dont believe reboot is needed. I always used to do cphastop; cphastart in that case and was fine after.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events