Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CyberBreaker
Contributor

VSX ClusterXL Not Forming

Hi, I would like to seek for some ideas or solutions about my issue in VSX as my cluster is not forming. When I do "cphaprob state" in both of my FWs, it states that "Sync down" but the Sync is not really down in fact, I can reach FW1 to FW2 via the HA IP address and vice versa.

By the way, the configuration of my HA link is that I bonded Sync and eth1 then configured the IP address in the bond interface. These interfaces are connected via switch via VLAN separated from the data VLANs (it is not direct back-to-back connection).

Thank you so much for the help in advance.

1 Reply
HeikoAnkenbrand
Champion Champion
Champion

Hi @CyberBreaker 

If Layer 2 and Layer 3 work correctly, it can be an implied rule. 

Create a rule in VS0 that allows from gateway one to gateway two everything on the sync interface. If it works, you can restrict CCP  (port 8116).

More to ports and ClusterXL CCP read here:

R80.x - Ports Used for Communication by Various Check Point Modules

R80.x - cheat sheet - ClusterXL

 

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events