Hello all.
My second question here. Hopefully I will supply all the necessary information.
My organisation has a ClusterXL HA pair of 5900 appliances running R80.20 Jumbo HF take 118. I have noticed on SmartConsole Gateways & Servers that the standby node is showing an error. Looking at the Device Status of the node, the IPS, Anti-Bot & Anti-Virus blades are displaying 'Error: Update failed. Contract entitlement check failed. Could not reach"updates.checkpoint.com". Check DNS and Proxy configuration on the gateway'.
I have connected via SSH to both nodes in the cluster and verified that I can ping external and internal endpoints from both nodes. I entered Expert mode on both nodes and ran dig against a known internal and external domain name. This was successful on the active node but failed on the problematic standby node with 'connection timed out; no servers could be reached'.
I power cycled the standby node this morning. I am now seeing Connection Alerts in the SmartConsole log for DNS queries originating from the problematic gateway. The reason is 'Firewall - Domain resolving error. Check DNS configuration on the gateway (0)'. We are not using domain objects.
Both HA nodes have identical NAT and policy.
I have reviewed DNS Error Message but it does not appear relevant.
It may be unrelated, but there is a noticeable delay between entering the username and the password prompt appearing when accessing the problematic node via ssh.
I'm wondering what else I can test before pushing the issue out to TAC.
Thanks,
Andy