- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Following a recent replacement of the firewall cluster hardware and re‑IP of the cluster members, the standby member is reporting as Normal in SmartConsole, while the active member is displaying a “Lost” status.
Both members are reachable via SSH, and cphaprob stat indicates that the cluster members are powered on and appear healthy from the command line. ClusterXL traffic between members is also confirmed to be flowing normally, suggesting that synchronization is occurring.
However, logs from other connected systems began reporting anti‑spoofing drops shortly after the change.
Will test SIC re-establishment and fw unloadlocal next. Also users report successful traffic.
The new member pulled a default local license during setup. That local license was generated against its default interface IP (192.168.1.1).
Solution:
Re‑generating the license with the new IP which seems to have resolved the issue
SIC is not working with the active member. This is not related to clustering. You have to check why SIC is not working. This is the communication between mgmt and fw. If you see spoofing drops maybe this SIC traffic is also dropped. Start with a quick drop check: fw ctl zdebug + drop | grep IP mgmt on the fw-a when you press SIC test in Smart Console.
Resolved the issue
The new members pulled a default local license during setup 192.168.1.1
re-attached the correct license and all seems normal now!
Thank you for replying so quickly
What doies cphaprob -a if show on that member?
Andy
All interfaces are up and running but looks like the new members pulled a default local license during setup. Updated the correct license information and all seems to be running correctly now.
Thank you for the quick response!
Hey @Fatalis
If you are allowed to do remote, happy to assist. Im busy with large project converting from Fortigate to CP, but since Im way ahead of schedule, have time to spare. Let me know.
Andy
The new member pulled a default local license during setup. That local license was generated against its default interface IP (192.168.1.1).
Solution:
Re‑generating the license with the new IP which seems to have resolved the issue
Corresponding issue for anti-spoofing:
An Interface was duplicated from an existing setup.
Re-configured interface with correct network.
Excellent job!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY