- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello,
I have set up a HA cluster (2 gw + 1 mgmt) running 81.10 and everything is working fine. This is running on an ESXi server. When I set up the same cluster but in version 80.30, the sync interface never comes up. The HA cluster actually runs in split brain, as they cannot communicate since the sync interface never comes up. I have tested different configuration settings, but the ClusterXL is always failing to be established.
- I have a /30 subnet on the sync interface, making it a unique sync network (and it is the lowest vlan).
- On Gaia all interfaces are up, I can ping between them just fine to any interface, also the sync interface.
- Access policy contains just 1 rule to allow anything.
- I have the all-in-one evaluation license on all servers.
- In the logs I cannot see anything but the fact that the sync interface is down on both sides.
- Via cpconfig I removed each member (option 6) and joined again after reboot.
- I recreated the sic trust, changed every possible setting for anti-spoofing.
- I removed the cluster object and recreated it again, no effect.
- I used vmxnet3 and E1000 interfaces on the virtual machines.
- I used different subnets and IP addresses, but same result.
- Changed CCP mode to broadcast, unicast, auto, all same result (now it is again auto/unicast).
- ClusterXL is installed on the gateways.
- I used the wizard to create the cluster.
- I reinstalled the servers to be sure but the same result is noticed.
The only way to get the interfaces in an UP state, is when I set the first mgmt interface to cluster+sync. When I do this the interfaces come up (sometimes), but there is still no traffic between them to establish a proper HA cluster.
I am new to Checkpoint and cannot find any other info to troubleshoot further. I've taken a look at the log files, but cannot find a log file about the sync interface and the HA mechanism (not in fwd.elg or messages or any other file). Is there a log file where you can see the servers trying to establish the cluster or why the sync interfaces don't come up for HA? These interfaces are up and working, they just don't do HA.
Is there something obvious I am missing on the 80.30 that is different from the 81.10?
Thank you!
Wouter
R80.40 and above is less strict on the requirements...
Do you have all the following in place: sk101214
Double check that your clusterID on R80.30 is set to the same number on both cluster members.
Thanks, great pointing out the clusterid, makes sense if there is a mismatch 2 different clusters will be formed. I don't know how to get this id. Do you know an easy way to verify this on 80.30?
[Expert@FW1:0]# cphaconf cluster_id get
cphaconf cluster_id set\get is not supported in this version.
For more details, please refer to sk25977.
from clish:
show cluster mmagic
So what is the clusterID in there?
FW1> show cluster mmagic
Configuration mode: Automatic
Configuration phase: Stable
MAC magic: 1
MAC forward magic: 254
Used MAC magic values: None.
R80.40 and above is less strict on the requirements...
Do you have all the following in place: sk101214
Thank you. When browsing the SKs and forum, I didn't stumble upon this. I verified and most of the 3 settings were rejected. I have reconfigured the sync interface with a port group that has these settings enabled. Immediately, the interfaces came up, the cluster formed and I have a working active/standby setup on 80.30. I was hoping it was not CP related.
That was fast! Thank you! Saves me at least some hours.
@woee great to hear. you can ignore ClusterID then 🙂
Yes, but now I need to know. 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY