- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi All,
i have HA Checkpoint 16000 using VSX mode. i found this difference file fwkern.conf is exist on active device but not on standby device. this is mandatory by design or not?
any some one else same this issue?
[Expert@Active_Device-03:0]# cat /opt/CPsuite-R80.30/fw1/boot/modules/fwkern.conf
fwha_enable_state_machine_by_vs=0
[Expert@Active_Device-03:0]#
[Expert@Standby_Device-03:0]# less /opt/CPsuite-R80.30/fw1/boot/modules/fwkern.conf
/opt/CPsuite-R80.30/fw1/boot/modules/fwkern.conf: No such file or directory
thanks.
This file is created/modified manually. This does not exist after clean-installation. All kernel values have to be set on both nodes.
So just create it on second node and add the same values as already given in node 1
According to sk26202, fwkern.conf does not exist - it has to be created manually if used. Kernel parameter fwha_enable_state_machine_by_vs can not be found in any documentation / sk, so i assume you would need CP to know why it was used here at all, and only on one cluster node...
thanks for your reply.
do you know function fwkern.conf? any document explain it?
Rochim,
Fwkern.conf is a file created manually. In your case, just create the file on missing cluster member.
More details you can see on: Changing the kernel global parameters for Check Point Security Gateway
Regards,
Alisson Lima
hi
thanks for your reply, i want to know what function fwker and what means attribute "fwha_enable_state_machine_by_vs=0"
@firewall1-gx wrote:...Fwkern.conf is a file created manually...
That is not completely true. To my knowledge the file could be created by cpconfig.
fwha_enable_state_machine_by_vs indicates if VSLS is enabled or not which is a property controllable by cpconfig.
Could it be something linked to the 16K series though? I operate some in VSX (R80.40) and fwkern.conf exists with fwha_enable_state_machine_by_vs set to 1.
Edit: might be a Kernel 3.10 or something linked to some HFA thing. I checked another cluster of high-end VSX appliances running up-to-date R80.30 and the file is also there with the value set to 1.
hi,
the file existing on both device? i only missing on standby device.
@Alex- Just had a look on a 23k device on our side running R80.10 and this value is present here as well. Don't have the function of this value in mind as well.
When kernel values to be set, file has to exist on both nodes to be effective as well when failover node gets active.
I would assume this to be about machine state - active or standby - being different per VS, a feature that sounds more like VSLS, not HA VSX...
Yes, agree. The key message was just to have it not just on one side 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY