- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- IPS Blade fails to update on the Standby member
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS Blade fails to update on the Standby member
Hello community
After upgrading a VSX VSLS cluster with 3 members from r80.30 to r81.10 take 66 we get the below error from Virtual Systems with the IPS Blade that fails to update on the Standby member with IPS Update description:
- Update failed. Contract entitlement check failed. Gateway can not access internet Check connectivity and proxy settings.
Any ideas?
We have found sk167205 that seems to match on our case.
Any ideas about the impact if we change of the below parameter?
Solution
Make sure to change the following parameter on the fly, and wait a few minutes for the issue to be resolved. Run:
# fw ctl set int fwha_silent_standby_mode 1
BR,
Kostas
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That parameter is described here; https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Allows the secondary member to communicate via primary member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did:
fwha_cluster_hide_active_only=0
ccl_force_use_ccp=1
fwha_silent_standby_mode=1
and antispoofing in Detect mode on Sync interface
