- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026
Inception is On!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello, I'm rebuilding my Check Point Lab on the latest version of the XCP-ng xen hypervisor. It was great on R81.20 and ClusterXL. New challenge is R82 and ElasticXL.
First issue using ElasticXL with the second gateway not showing up as a pending gateway. Solution was to patch the exl_detectiond.py as noted in the previous thread https://community.checkpoint.com/t5/Security-Gateways/R82-elasticXL-lab/td-p/219343 (deals with open servers, looks like a bug)
Second issue is adding the second gateway fails due to failed cloning process.
/var/log/lightshot.log shows "Lightshot Partition is out of space".
Reviewing the script I ran these commands to confirm:
PS: Please add a Label for ElasticXL
Hi @nadmin,
The lightshot partition size should dynamically adjust based on your image size on the SMO.
Since you’re working with an unsupported hypervisor/VM (as you have a GA take installed), this mechanism might not function as expected.
To resolve this, you can manually increase the partition size from the new member’s CLISH using the following command:
set lightshot-partition size <size in GB>
Regards,
Shai.
Hi @nadmin,
The lightshot partition size should dynamically adjust based on your image size on the SMO.
Since you’re working with an unsupported hypervisor/VM (as you have a GA take installed), this mechanism might not function as expected.
To resolve this, you can manually increase the partition size from the new member’s CLISH using the following command:
set lightshot-partition size <size in GB>
Regards,
Shai.
Just tried it in the lab as well, worked great 👍
Just do exactly what @ShaiF had said. I had to do that once in eve-ng lab.
Glad we can help.
Just to be on a safe side, BEFORE doing anything, I would generate backup and also config file (here is an example)
from expert -> clish -c "show configuration" > /var/log/filename.txt (file name I usually give it hostname and date, so say if your hostname was fw01 and date is November 10th 2025, you could do fw01-Nov10-2025.txt).
Hope that helps.
Notes from testing:
Cannot set lightshot partition size on the new gateway to be added in initial state. Only after it has been added to the cluster.
I tried setting the first gateway lightshot partition size:
set lightshot-partition size 20
save config
reboot
When I added the second gateway, it still had 14GB and ran out of space.
At this point I was able to set the snapshot size on the new gateway
set lightshot-partition size 20
reboot
But there is no real way to restart the cloning; reboots didn't help. Removing the second member using WebGUI and rebooting second gateway did not show it as a pending gateway. The new cluster member appeared to be corrupted somehow so I rebuilt it and tried again. `show cluster` on it exploded with components not found.
I will keep testing different iterations.
Let me try it in the lab tomorrow and see.
In the other thread about EXL in the lab there was a command to reenable EXL detection - make sure you run that on both/all cluster members after the reboot.
Thank you @emmap I didn't see that. Is that after adding the cluster member is successful?
Good news, after leaving it overnight, it showed as pending and I was able to successfully add it. I will re-enable exl detection and test some.
I will try to repeat the process again and share any learnings in case anyone else runs into this.
Edit to add: huh I left the first gateway at download & verify overnight, and it failed validation. I will test applying JHF before I burn it down and rebuild.
Great job!
I have a repeatable process that I need to simplify.
The secret sauce is going away from an hour while waiting for the status to change from JOINING_CLUSTER back to REQUEST_TO_JOIN.
I tested in the lab on R82 jumbo 44 and worked well.
The detection needs to be running before the member is added, to ensure that it shows up as an available cluster member. Once it's added there's no need for it. Sounds like though yours just needed more time, so all good there. Sometimes the main tool we need for these things is patience, and to go make a nice cup of tea.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 17 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY