- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
HI Checkmates
Today i have seen new issue on cluster XL.
Environment: Distribution architecture
Version : R81.20
Hotfix : 84
Cluster members : 2 checkpoint appliances
When i do a cluster failover, secondary member takes at least 10 minutes to process the traffic. That time our all the services are goes down, after 10 minutes everything works fine. i did not observe any drops on log (smart console).
but the cluster state show active/standby states correctly. no delay on this part.
Kindly help me to sort out the new problem.
Thanks
Rajkumar T
Can you please send outputs of below when this happens?
Andy
**********************
cphaprob roles
cphaprob state
cphaprob -a if
cphaprob -i list
cphaprob -l list
cphaprob syncstat
********************************
Personally, never seen such an issue myself, even back in R55.
Is there any dynamic routing involved or are there issues with stale ARP entries?
Do the issue occur regardless of which member is active or standby?
HI Chris
There is no dynamic routing.
Have you run any tcpdumps and/or traffic captures to see if the packets are reaching the gateway during the outage period?
Sounds like a Gratuitous ARP issue (which is the default setting), do you have VMAC set on the cluster object? That should help but if you still experience a 10-12 second delay upon failover even after setting VMAC you'll need to set portfast (NOT disable STP) on the switch ports the firewalls are connected to.
If everything is working properly, upon failover you should see the following traffic behavior:
Catastrophic Failover (active completely dies/crashes): Outage of up to 2.5 seconds
Non-Catastrophic Failover (active interface failure, clusterXL_admin down, etc.): Outage of up to 300 milliseconds
Actually, @Timothy_Hall makes super valid point. Can you see if below is enabled or not?
Andy
Dear Timothy
Thanks i will try this.
Thanks
Rajkumar T
Try to toggle that option and install policy and then do a failover test and see what happens. If no change, naybe open TAC case to further investigate.
Andy
share fw tab -t connections -s from both members at the same time.
This will show if the connections are synced.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY