- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi There,
I have a pair of Quantum Spark 1590 configured as an HA pair and have noticed that policy and objects are not synchronised.
I am managing the pair via the web GUI and only have the pair with no management station, so these are locally managed. I login to the active firewall to manage but the policy and objects are only ever updated on of the active node. I am unable to edit objects and policies on the standby node via the GUI due to the reduced functionality presented.
Is there any way to keep the pair in sync with a pair of locally managed firewalls in HA apart from failing over to cause standby to become active and then making the same changes to the policy?
The concept of publishing the policy to the HA cluster object, as was/is the case with SmartConsole doesn't appear to be possible with the webGUI (unless I have missed the option somewhere).
Regards
Dek
Hi Derek,
The command we used was:
/pfrm2.0/bin/lua /pfrm2.0/bin/clusterResetSIC.lua
You can also refer to sk183116 (although there was no Spark Management in your case).
Thanks.
This is not a requirement outlined in the admin guide that I can see.
Which firmware version / build is used on each appliance?
Hi,
The policy and objects are expected to be synchronized between cluster nodes.
Which firmware version are you using? Was any of the cluster nodes ever connected to Spark Management?
Thanks.
Hi Sigal / Chris,
Thanks for your replies;
Both are running R81.10.17 (996004721)
Neither of the nodes have ever been connected to Spark Management, no
I would have expected them to be synched, especially, given the fact that you cannot edit the standby unit's policy via the GUI and no option to push a policy to both. The IPs and IPSEC sessions are failed over correctly, so I'dve expected that policy and objects to also.
Thanks again
Can you please share the output of:
cphaprob stat
from Expert shell on the Active cluster member?
Thanks.
Here is the output:
# cphaprob stat
Cluster Mode: High Availability (Active Up)
Sync Mode: Optimized Sync
ID Unique Address Assigned Load State
1 (local) 10.231.149.1 100% ACTIVE
2 10.231.149.2 0% STANDBY
Active PNOTEs: None
Last member state change event:
Event Code: CLUS-114704
State change: STANDBY -> ACTIVE
Reason for state change: No other ACTIVE members have been found in the cluster
Event time: Tue Jan 6 01:12:36 2026
Last cluster failover event:
Transition to new ACTIVE: Member 2 -> Member 1
Reason: USER DEFINED PNOTE
Event time: Tue Jan 6 01:12:36 2026
Cluster failover count:
Failover counter: 1
Time of counter reset: Tue Sep 30 18:53:15 2025 (reboot)
Please run on the Active member:
cprid_util getfile -local_file /logs/bl_tmp -remote_file /logs/boot_log -server 10.231.149.2
echo $?
And then on the Standby member:
cprid_util getfile -local_file /logs/bl_tmp -remote_file /logs/boot_log -server 10.231.149.1
echo $?
Send me the output of these commands.
Thanks.
Thanks Sigal
Here is the output requested
The active host:
# cprid_util getfile -local_file /logs/bl_tmp -remote_file /logs/boot_log -server 10.231.149.2
# echo $?
5
The standby server
# cprid_util getfile -local_file /logs/bl_tmp -remote_file /logs/boot_log -server 10.231.14
# echo $?
5
Regards
Dek
Hi,
Based on the data you shared, the SIC between cluster members is broken and this is the reason objects and policy do not synchronize. When SIC is properly set, return value of these commands should be 0.
The simplest way to recover is to:
1. Reset the cluster
2. Reboot both gateways
3. Re-establish the cluster
Please let me know if this is doable.
Thanks.
Thanks Sigal.
I will look at this further and see if I can organise a time to do this.
When you say 'reset the cluster' , what particular operation are you referring to specifically please?
Can you explain what the cprid_util is doing? Are there other commands which can show whether SIC is working or not?
Thanks again
regards
Dek
Reset the cluster: on High Availability page, click on Reset Cluster Configuration. After that, verify on both members that cluster indication on the left corner of the UI is gone.
The cprid_util command you ran is used for copying files between cluster members over SIC.
Hi Sigal,
I just wanted to confirm what you meant, This will blow away the configuration. I will not be in a position to do this as these units are remote to me . I could only do this whilst on site, I think just in case.
Is the alternative to push a common policy to both only if a Management Server or Smartconsole system is introduced (as it used to be when we had R71 ) ? Am I correct in assuming I'd also need a licence for a Management Server?
Thanks and Regards
Dek
If it is not possible to reset the cluster, please issue support ticket and send its number.
We will then schedule remote session in order to try and fix this issue without traffic interruption.
Hi Sigal,
I will indeed log a call with the provider in that case.
Many thanks for your time and help here.
I will be in touch once this has been done
Thanks
Dek
Hi Sigal,
I was able to open 6-0004484543 via the reseller
Not sure if you can see this
Regards
Dek
Thanks Very much for the help SIgal the command:
fw sic_test
Is helpful.
Could you remind me of the command to reestablish SIC please?
Thanks again
Regards
Derek
Hi Derek,
The command we used was:
/pfrm2.0/bin/lua /pfrm2.0/bin/clusterResetSIC.lua
You can also refer to sk183116 (although there was no Spark Management in your case).
Thanks.
Thank you very much Sigal
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY