- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
After I enabled ipv6, I rebooted. After the reboot I could NOT connect to the gateway at all. The box lost its cluster status. I also lost SIC. New day, new issue. 🙂
Here is my question. When you do this and reboot, what does fw stat show? If its initial policy, just run fw unloadlocal, test SIC, if green, try policy.
Andy
Really? Thats odd...is it R81.20, R82? I had ipv6 enabled on both versions in the lab, never had an issue.
Andy
R81.20. Yeah, it's a new one for me too.
I disabled ipv6 and everything is fine again.
Tried it again - same issue...
What was the process you followed? I just tested on abother lab gw with set ipv6-state on and save config, rebooted, no issues. R81.20 jumbo 111
Andy
I tried it with set ipv6-state on as well as in the web ui same issue. JHF105
Here is my question. When you do this and reboot, what does fw stat show? If its initial policy, just run fw unloadlocal, test SIC, if green, try policy.
Andy
ytmnd
Since I did not google that abbreviation, no clue what it means, but glad we can help lol
Andy
Who knew there is dedicated page to that abbreviation 🤣
Andy
I now have the Check Point ClusterXL for Bridge Active/Standby in cpconfig set to enable for one cluster and not in another. Is it recommended or not? I'm using a dedicated SYNC interface as well.
I would make sure they match. Just verified in my clusterxl lab and they are same on both.
Andy
So, they do match per cluster. I have it enabled in this new cluster. Not in an older one.
Personally, as long as cluster is used and processing traffic, I would ensure those settings are the same on both members.
Andy
Agreed, just wondering if there was a preference. This is the first I'm running it on bridge mode.
I can tell you that even if certain things do not match 100%, cluster will still work, but me personally, to keep it consistent, I always recommend double checking settings do indeed match. Last thing you want if there is a failover is to find out the hard way something was missing.
Andy
Yes, both member of the cluster have the same settings.
Then, all I have to say is...
ytmnd : - )
Andy
Funny enough, just tested on R82 standalone and same happened. But then since it showed initial policy, I did fw unloadlocal, was able to log into smart console and install policy that was there before.
Rebooted again, still fine with ipv6 on
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
3 | |
3 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY