- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
hi,
I have created a small environment in which to test gaia, I am still in the beginning, I have not learned much, yet.
this environment consists of two physical machines (open servers) with two gaia 80.40 installations as gateway and one virtual machine as management
I am stuck with a gateway cluster problem, in device status I only see "ClusterXL inactive or machine is down", I have read about it but I have not found anything that can help me.
can you help me out of this situation? I leave some screens so that my situation can be clearer.
(since it is a test environment I cannot reach the internet. it is a closed environment. I cannot ping the two gateways while the management does. despite not being able to ping them, I can reach the web interface without problems)
thank you very much
In the topology page on the GW, make sure your interfaces and topology for those are correctly defined. External interface is one where default GW is set. The rest are internal. Make sure the first policy you apply is ANY-ANY-ANY-ACCEPT.
On your fw gws, to on ssh/console and run "fw unloadlocal". After you did, on MGMT check SIC is working. If it is, fetch interfaces with policy, then push policy as described above.
Best, look into Check Point for Beginners series, we discuss setting up GWs there in the Network security section. I have provided you the links already.
Did you push policy on them yet?
What are the parameters of your GW VMs? RAM and HDD size? How many CPUs?
i have both fisical GW with 1 CPU Intel Xeon E5-2665 2.40GHz, 32 gb ram, 900 gb HDD and 2 network card. 1 is connected to the switch and the other is connected to the other gw for the HA.
the management WM have 2 cpu with 2 core per socket (4 core), 8 gb ram, 80 gb HDD and 1 network adapter.
@fabiofabio One of the most common issues when playing on VMware is not setting enough HW power on your VMs. Look here and make sure your virtual machines have at least required minimum, as mentioned in the article: https://community.checkpoint.com/t5/Check-Point-for-Beginners-2-0/Part-2-Preparing-the-Lab/ba-p/8805...
From the policy installation failure screen, click the "V" symbol next to the first "Failed" to expand the actual failure error message, and post a screenshot of that. It is also possible that clustering has not been enabled from cpconfig on one or both of the cluster members, and as Val said the cluster state will report "problem" until policy is successfully installed.
I have enabled both GWs for clustering while installing gaia but for safety I have now checked by cli and it is enabled.
thanks for the tip of the "V", I leave attached the screen, I have already tried to reinstall the SIC on both GWs, restarted the GWs and re-established the communication of the cluster members. what can i still do?
You need to provision a third interface on both your gateways, connect them, and set it to be the cluster sync network.
Read my prior post again. You need a third NIC interface provisioned in Gaia on both cluster members, then define that third interface as 1st Sync in the cluster topology.
I did it but the same error remained, so I tried to disable the antispoofing and it allowed me to install the policies. at that point the cluster was ok but I can no longer reach the web interface of the gateways. if now I try to re-enable antispoofing it does not allow me to install the policies with the same error as before (asking to install a second cable for the cluster, although there are already one for the cluster and one for the sync)
Which points to the topology misconfiguration. Fix it, and all will work
i looked for the solution but i can't get out of it for now. looking for the error i came across sk138132 but it didn't solve the problem and i didn't find anything else about it. any suggestions? 🙂
In the topology page on the GW, make sure your interfaces and topology for those are correctly defined. External interface is one where default GW is set. The rest are internal. Make sure the first policy you apply is ANY-ANY-ANY-ACCEPT.
On your fw gws, to on ssh/console and run "fw unloadlocal". After you did, on MGMT check SIC is working. If it is, fetch interfaces with policy, then push policy as described above.
Best, look into Check Point for Beginners series, we discuss setting up GWs there in the Network security section. I have provided you the links already.
thank you very much, I finally succeeded. the problem was the main gw interface set to private. setting it in cluster, setting the virtual ip and putting it in external I succeeded. it's not something to do in a production environment but oh well, it's just a laboratory. but now I have no idea what I did, the cluster communicates with the management but the gw are no longer reachable from the web interface or even via ssh. I must also say that the gw have never been able to ping them. any idea?
@_Val_ sorry, my fault. now everything works. thanks again for the support!
No need to be sorry, we are here to help everybody out, @fabiofabio
If you use cli to bring up cluster member, what does it say?
Are the cable connected properly for the sync interface?
He will not be able to bring cluster up before policy is installed. He cannot install policy, let him figure out this part first :-), before anything else.
the GWs are already part of the cluster members.
thanks for the sync cable tip, it wasn't. now I have configured the IP on the network cards of both WGs from the web interface and then I have configured the interfaces from the cluster. I leave a screen attached because I'm not sure I have configured it well.
now every time I exit the cluster settings I get this screen that I leave attached and I do not understand what it is.
Can you run below commands on both members from ssh and send us the output?
cphaprob state
cphaprob -a if
cphaprob list
cphaprob syncstat
no need, @the_rock he is struggling to push policy.
Yes, correct, sorry.
Maybe sharing a screenshot of your topology would help (you can blur out public IP addresses, thats fine).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
23 | |
16 | |
12 | |
9 | |
9 | |
8 | |
7 | |
7 | |
7 | |
5 |
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 02:00 PM (EDT)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY