- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026
Inception is On!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hey guys,
I really want to run something by here, as I have my doubts about TAC claiming this is totally normal. So, customer and I added 2 new VLANS of eth1-01 interface and set them up as clustered with VIPand all, but they dont show up when running cphaprob -a if. The existing vlans of that interface (2 of them, vlan 20 and 500) show up, but new ones (vlans 762 and 764) do NOT, though they show up in virtual cluster interface section from cphaprob -a if, just NOT under required interfaces.
To me, this makes no sense, as I had never ever seen this before. Yes, traffic works, so it could be just cosmetic, but TAC guy said sometimes reboot is needed for this to show up properly (in my 15 years dealing with CP, I never had to reboot firewall when doing this for cluster, not once, so I dont believe for a second that reboot is required).
Any idea what we can do to make those 2 new clustered vlans show up in cphaprob -a if? Version is R81.10 jumbo 81.
Btw, failover works fine, no issues.
Cheers and thanks for the help as always!
Newly added VLAN interfaces (in case you added a new highest or lowest VLAN) should be added to the ClusterXL kernel module. Those are initialized during reboot or cpstop/cpstart.
I dont know if this is indeed needed, but TAC sent us below and it appears cpstop and cpstart is needed to fix it. Not sure if someone could confirm this 100%, but if thats the case, customer wont bother, if its only cosmetic.
ClusterXL VLAN monitoring (checkpoint.com)
Newly added VLAN interfaces (in case you added a new highest or lowest VLAN) should be added to the ClusterXL kernel module. Those are initialized during reboot or cpstop/cpstart.
I tested this in my R81.10 clusterxl lab and did not need reboot, any kernel parameter change, reboot at all. All I did was added vlans 999 and 1000, got interfaces without topology, pushed the policy and both vlans came up as clustered under cphaprob -a if.
It is not about how they show in cphaprob. It is about which VLAN is monitored with CCP packets. By default, it is the lowest and highest VLANs, but if you add one with a higher/lower number, you need to reload cluster modules to change probing.
You did refer to an SK about it yourself.
Ok, I think I see what you are saying. So, in customer's scenario, there are 4 vlans, ...20.500, 762 and 764 and ONLY 20 and 764 show up, which makes sense, since those are lowest and highest. Question, so is only cpstop; cpstart needed or any kernel parameter change? Its not 100% clear from the sk.
Only if you want one kernel parameter from sk92826 to be set differently from its default value !
K, good now thanks! Tested with vlans 999, 1000 and 1500 and when added vlan 1500, vlan 1000 did NOT show up in cphaprob -a if, but after doing cpstop/cpstart, it did.
Thanks a lot @_Val_ abd @G_W_Albrecht , appreciate the clarification.
Hmm really strange. I do not remember for need of reboot or cpstart/cpstop for this during my whole experience with Check Point. Could you please share some output as well?
I will test this today in my R81.10 clusterxl lab and see what happens. Will add say 2 new VLANS, 900 and 950 and see if those interfaces show up when I cluster them via cphaprob -a if.
If they dont, will do cpstop; cpstart without making any kernel parameters changes from sk TAC gave.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 17 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY