- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have build a Full HA ClusterXL with Firewall Gateways on VM (OS GAIA R77.30).
To make sure that the cluster is working properly , I used cphaprob commands.
But with "cphaprob stat" I only see the member on which I am, as "Active" and with 100% Assigned Load.
Same issue for both members, primary or secondary.
Moreover I haven't this problem in SmartDashboard.
What is the probleme ?
My guess is that you didn't set the same Cluster Global ID on both members during the R77.30 post-installation wizard. This value must match on all members of the cluster or they will refuse to cluster up with each other. Run cphaconf cluster_id get to check this value on both members, if you need to reset the value on one of the members to match the other, use the cphaconf cluster_id set <CLUSTER_ID_VALUE> command.
R80.10 gateway clusters use a new feature called “Automatic MAC Magic” by default to automatically derive a unique Cluster Global ID, and prevent conflicts with other gateway clusters on the same network. The status of this new feature can be checked with the cphaprob mmagic command. This feature can also be monitored from a new ClusterXL-based screen of the cpview tool on a R80.10 gateway under Advanced...ClusterXL, and is backward compatible with gateways that had their Cluster IDs configured manually in earlier versions such as R77.30.
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
Thanks Tim for your response and your precision !
So I will check my Cluster Global ID and both members have the same.
Sync dedicated interface, Management dedicated interface, same cluster ID, synchronization OK... Except cphaprob stat command, all seemed clear.
And I didn't use R80 for the time being but I keep cphaprob mmagic command in my head for later.
if it's still urgent 🙂
in Hyper-V NICs, used for sync, should be allowed to do MAC spoofing
i've had the problem, described by the topic-starter,
yesterday i resolved it by switching on MAC spoofing in Hyper -v openserver NICs, then rebooted one by one and cphaprob stat started to show cluster info correctly. it seem like cluster members couldn't sync - so-called split brain. all other attributes on both cluster members are the same.
here is the explanation:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY