- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
We had an issue today where our Internet access was weird. A lot of sites would timeout and work eventually.
For example on the active gateway I could ping 8.8.8.8 it would work most of the time but regularly we’d get 100% packet loss.
Looking at it with fw monitor we could always see that traffic was getting out.
About 3 weeks ago we changed our cluster gateways hardware (OpenServer on HP Proliant).
We also went to R81.20 JHF take14
As a test we tried forcing a failover to make sure there wasn’t an issue with the active gateway. It didn’t make a difference.
We then rebooted the now standby gateway and triggered another failover to make it active again. After that everything was working smoothly again.
Was it something else and a coincidence that everything started working again I don’t know.
Is there anything that can be looked at and investigated to find what was going on with the gateway?
If the issue starts again what can we look at that could explain a behavior like that?
Thanks
Francis
Hey Francis,
Personally, I would investigate any relevant logs from that time period, as well as run cpview and then check history. Example...run cpview -t from expert, then press letter t and choose time frame. That would also give you some details.
Andy
Did you check out whether anything else is using the same IP as the firewall or VIP? That sounds suspiciously like an ARP clash... What else besides the firewall is in the switch/VLAN that uplinks to the ISP router?
no duplicate IP. I'll check with the network guys if there is something else on that VLAN but there shouldn't be.
Long shot but did you check your duplex settings on the open servers just in case you have a duplex mismatch issue which could be cause the packet loss?
Was worth checking but duplex settings are all matching
Were you able to get any more details from the logs at all?
Andy
No not seeing anything that stands out to me.
I have another suggestion...run below commands on both members and check the time when this issue happened...maybe you will get more details:
grep -i /var/log/messages* DOWN
grep -i /var/log/messages* CLUSTER
Andy
Sorry, this is right syntax
Andy
grep -i DOWN /var/log/messages*
grep -i CLUSTER /var/log/messages*
grep -i PNOTE /var/log/messages*
don't see anything at time of issue. Everything has been fine since. Not even 100% sure the firewall was the cause. Hopefully it doesn't happen again
What about connections table limit, again long shot but lets get these out of the way.
Thats a very good point, you never know...
Not sure on this one (how to see the limit). I have the maximum limit for concurrent connections set to Automatically.
Thats good, leave it as such, thats better option anyway, as gateway calculates on its own as far as number of connections, based on cpu/memory load. Btw, Im just slightly concerned (though I want to be positive) that you may have cluster issues, considering problem went away when you failed over.
Just to be sure, can you run below commands on both members, just to make sure all is good?
Andy
cphaprob state
cphaprob roles
cphaprob -a if
cphaprob list
cphaprob syncstat
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
9 | |
6 | |
5 | |
4 | |
4 | |
3 | |
2 | |
2 | |
2 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY