Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CheckCheckM
Participant

HA is swing without any changes (Quantum Spark 1800) (R81.10.05)

Dear all,

im facing a issue HA cluster is failover secondary device without any changes but i see "cphaprob state" ate primary device as below. It is saying "Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)".  

Actually, no interfaces were down. all are up state. but checkpoint is knowing these interfaces are down state. So, ha is failover to secondary. 

Anyone experienced it?

Thanks much.

 

 

 

0 Kudos
11 Replies
G_W_Albrecht
Legend Legend
Legend

Did it ever work ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
CheckCheckM
Participant

sure, it works previously.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Do you have "cphaprob -a if" output from the time of the issue or equivalent logs/messages?

CCSM R77/R80/ELITE
0 Kudos
CheckCheckM
Participant

here is it. it says interface are down. I have HA cluster for two devices, i assign x.x.x.1 for primary device and x.x.x.2 for seondary device and x.x.x.3 for cluster ip. i can ping to x.x.x.1 for all interfaces exception from mgmt address.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

On the interfaces reporting as down, what do you see if monitoring with tcpdump or similar?

On those specific VLANs is there much traffic and many hosts to begin with?

CCSM R77/R80/ELITE
0 Kudos
CheckCheckM
Participant

actually, my topology is like this. all respective vlan have at switch, all is up like fw02. But fw01 is knowing interface down state. i have no idea, what's wrong with it. How should i check it, pls kindly suggest it. thanks.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

As above what do you see when monitoring with tcpdump on that gw/interface?

How about the switchport config, all the necessary VLANs allowed on the trunk port?

CCSM R77/R80/ELITE
0 Kudos
CheckCheckM
Participant

when i did tcpdump at gw/interface, please check the attached screenshot.

I have done configured all necessary vlan at trunk port of switch also. Thanks.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

If you change / remove the host filter do you see anything other than unanswered ARP requests?

CCSM R77/R80/ELITE
0 Kudos
CheckCheckM
Participant

i cannot see any unanswered arp requests as attaches. thanks.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

To clarify if you perform "arp -a | grep 10.20.30."  what do you see?

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events