- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Let's discuss!
Whenever a cluster member needs to be stopped from working within a cluster for some time the question is how to perform this properly.
Check Point's official Best Practice: cpstop
I didn't find an explanation yet, why cpstop was elected to be best practice with so many documented caveats (see below).
Other alternatives are (excerpt):
So let's have a closer look at each of the options.
Option 1: cpstop
What it does:
Caveats:
Rationale: Only use cpstop for internal Check Point clusters. For clusters with network interfaces leading to the internet additional security actions are required!
Option 2: cpstop -fwflag [-default, -proc, -driver]
What it does:
Caveats:
Rationale: Only use cpstop with flags/parameters if Check Point advises you to do so.
Option 3: cphastop
What it does:
Caveats:
Rationale: Use cphastop whenever you need to stop a cluster member.
Option 4: system shutdown
What it does:
Caveats:
Rationale: Valid option to stop a cluster member if turning on the system is easily possible afterwards.
Option 5: network disconnect
What it does:
Caveats:
Rationale: Valid option to stop a cluster member if re-connecting the network is easily possible later on.
May want to mention that Option 3 is what happens when one does a "Stop Cluster Member" from ye old school SmartView Monitor, which is quite different from clusterXL_admin down.
Excellent explanation @Danny 👍
Why reinvent the wheel, if we already have it as an SK (some options you missed :-)): Best Practices - Manual fail-over in ClusterXL?
@_Val_ : This thread is about stopping a cluster member and not handling a fail-over.
Then options 3 and 5 are not exactly to the task 🙂
Option 3 is exactly to the point and option 5 is mentioned for completion as Check Point mentions it here as well.
I agree 100% @Danny . I always use cphastop myself.
i always used cphastop as it is a lot faster than cpstop. when you have to make that leap of faith that your 'ready'-status cluster node is going to go active, theoretically it would be a lot faster to 'cphastart' and get a cluster node active again. i cannot say i ever had to use cphastart though so not sure it would work as expected during a problematic upgrade.
I definitely used it in the past with various versions and never had a problem.
I've personally always used cpstop, mostly because CP themselves say to do so rather than use cphastop as you've mentioned.
"Best Practice - To stop a Cluster Member, use the "cpstop" command." from the ClusterXL admin guide:
I assume they have their reasons 🙂 But would also like to learn them too.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 15 | |
| 13 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY