Hi all
I need to replace our 5600 gateway cluster with a new 6600 cluster with as little downtime as possible [ideally we want established connections to remain, but if that is not possible we need at least one firewall available to handle new connections], so I followed the advice in Solved: Replace/Upgrade Cluster - Check Point CheckMates but I ran into a weird issue, as follows:
I disconnected the 5600-standby firewall and connected the new 6600-standby firewall in its place.
I established SIC and installed the policy on the cluster, and the policy installed fine.
I ran cphaprob stat on each gateway and the 5600 showed as "Active Attention" [due to the mismatch in CPU's], and the 6600 showed as "Standby". I checked the OSPF routes on the 6600 and it had learned all the correct routes, so I thought it was safe to proceed with the failover.
I ran "clusterXL_admin down" on the 5600 and the 6600 status went to "Active" and it initially appeared to be processing traffic fine, but I then noticed that all outbound traffic to the internet was all being dropped, and the logs showed these drops simply as "Rulebase internal error", with no other information. I had a Endpoint Security VPN connection from my laptop established before I did the failover, and this survived the failover and I was still able to connect to the internal network, but any new outbound connections to the internet where showing in the logs as "Rulebase internal error" and failing to connect.
As I had not come across this error before I failed back to the 5600 gateway and traffic went back to normal, and then I brought the 5600-standby back online.
Can anyone see where I went wrong with this, or offer any advice as to how I should troubleshoot it if it happens again?