- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I was attempting to replace a pair of old 5800's with a new pair of 9100's over the weekend but hit a strange problem (well 2 actually)
I had a fairly small windows to do this so ahead of time a built the 2 new gateways offline. Standard stuff, booted, installed, first time wizard, latest updates etc, then I configured each with their settings accordingly, these were an exact match for the current pair of gateways. Both gateways were fine, IP's all correct etc.
So, on the day, I shut down FW2, swapped the cabled to new FW2 (all but the LAN bod cables as the new one is 10Gb so different cables), opened management, changed cluster to 9100, established SIC to FW2, all good. Then I moved on to FW1, this time it was not shut down, the cables were swapped (again except LAN bond) and started it up. Initially I couldn't ping it, realised that both old and new connected with same IP, so shut down old then rebooted new via console connection, after which it would ping fine both in and out.
Back to management, and established SIC to FW1, again all good. Final step, get interfaces without topology, which it did without error but left the Sync interface topology column as "undefined" - See attached screenshot. Whilst I know the wasn't right I though i'd push the policy and look at this afterwards, however the policy failed to push, referring to a topology error on FW1 - see attached screenshot.
I know the interfaces were configured correctly, but to double check I went to Gaia on FW1 but it would not connect, error was connection refused. I know this was working a couple of weeks ago, so i'm not sure what could have happened to it. Tried to ssh to the box, again no response, yet from the console cli all looked good and it would ping in and out. Tried a reboot, but still the same.
Unfortunately I ran out of time and had to put the old boxes back online and roll back the snapshot on the management server, so I can't troubleshoot this as a whole, but I have console access to the new box and access to the management port, although I can't connect to the Gaia still at this point and I was wondering if anyone may be able to shed some light onto what may have happened here?
My gut feeling is to factory reset it and rebuild it, but i'd to try to find out what's happened for future reference. (I have some time before I can get another maintenance window)
I have console access to the new box and access to the management port, although I can't connect to the Gaia still at this point.
I have working cluster lab, so happy to do remote and see if I can help. Let me know.
Andy
Hi Andy,
That would be great thanks, I'd be interested to see if you can see any reason for the issue.
Let me see if I can get a session arranged, where are you time zone wise? (I'm in the UK on GMT)
Did you try "fw unloadlocal" on the affected node then fixing the topology and reinstall policy?
I did yes, but it didn't help
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY