- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
we have a centrally managed 1550 Cluster XL running R80.20.15 - Build 682
when i try to install policy it always fails on the active member and installs on the standby no issues.
The message is indicating a memory error but the boxes do not seem to be running out of memory.
[Expert@GW1]# free -m
total used free shared buffers cached
Mem: 2000884 1677392 323492 46460 12196 516604
-/+ buffers/cache: 1148592 852292
Swap: 0 0 0
I've had a ticket open with TAC for about 10 days with still no resolution . Though I would check in the forums for any ideas?
[Expert@GW2]# free -m
total used free shared buffers cached
Mem: 2000884 1738000 262884 56924 8056 560276
-/+ buffers/cache: 1169668 831216
Swap: 0 0 0
This post should be in SMB ! What happens if you do a policy pull on the active node ? What happens after a failover ?
I've manually forced a failover and tried that as well. again it will ONLY fail on the active member of the ClusterXL.
I've only tried pushing policy from the MDS
Connect using SSH to each node and issue
# fetch policy mgmt-ipv4-address <sms IP>
same message on both :
HQ-FW2> fetch policy mgmt-ipv4-address x.x.x.x
Fetching policy from x.x.x.x
Fetching Security Policy from 'x.x.x.x'
Local Security Policy is Up-To-Date.
Installing Security Policy...
IPS package: Compiled OK.
Installing Security Policy Succeeded.
Done.
sfw_mac_filtering_config: ioctl SFW_MAC_FILTERING failed.
ioctl 43 to the sim device failed (ppak_id=0, rc=-1, errno=22)
sim_arp_spoofing: ioctl to the SecureXL device failed -1
Unable to configure anti ARP spoofing
sk167416 - "sfw_mac_filtering_config: ioctl SFW_MAC_FILTERING failed" message when pushing policy on a 1500 device
Both nodes have the current policy - alter the policy, install and try on the failing node again.
install via fetch or via sms push?
What version/JHF are you pushing from?
Also, has TAC asked you to debug the policy installation process yet?
Send the SR number in a PM.
80.40 take 89
yes they have taken a debug during policy push and nothing has been resolved yet.
i will send the SR in a PM
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY