<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.cpwiki.net/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.cpwiki.net/index.php?action=history&amp;feed=atom&amp;title=Check_point_state_sync_interface_problem</id>
		<title>Check point state sync interface problem - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://www.cpwiki.net/index.php?action=history&amp;feed=atom&amp;title=Check_point_state_sync_interface_problem"/>
		<link rel="alternate" type="text/html" href="http://www.cpwiki.net/index.php?title=Check_point_state_sync_interface_problem&amp;action=history"/>
		<updated>2026-04-29T09:45:48Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.21.10</generator>

	<entry>
		<id>http://www.cpwiki.net/index.php?title=Check_point_state_sync_interface_problem&amp;diff=25&amp;oldid=prev</id>
		<title>Nighthawk: Pushed from Themanclub.</title>
		<link rel="alternate" type="text/html" href="http://www.cpwiki.net/index.php?title=Check_point_state_sync_interface_problem&amp;diff=25&amp;oldid=prev"/>
				<updated>2013-02-26T00:21:14Z</updated>
		
		<summary type="html">&lt;p&gt;Pushed from Themanclub.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;'''Problem description'''&lt;br /&gt;
&lt;br /&gt;
State table sync was not working between firewall-1 and firewall-2 after upgrading from R65 to R70.1.  Fw ctl pstat showed sync packets sent, but zero received on both firewalls.  The aggregate link was setup properly in IPSO and the firewalls could ping each other’s sync interfaces.  The real problem symptom was that the firewall didn’t recognize any of its interfaces as being sync interfaces as seen below.  &lt;br /&gt;
&lt;br /&gt;
Also, the configuration of the firewalls was double checked by Mark Stapp and Check Point support.  All firewall configurations appeared to be correct.&lt;br /&gt;
&lt;br /&gt;
'''Symptoms'''&lt;br /&gt;
&lt;br /&gt;
1)	 Local cpha shows down&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
  firewall-1[admin]# '''cphaprob stat'''&lt;br /&gt;
  Cluster Mode:   Sync only (IPSO cluster)&lt;br /&gt;
  Number     Unique Address  Firewall State (*)&lt;br /&gt;
  2 (local)  none            Down&lt;br /&gt;
&lt;br /&gt;
2)	Cpha interface listing show no sync interfaces configured.  However; state sync is enabled properly on the firewall cluster object in the topology and 3rd party configuration options.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
  firewall-2[admin]# cphaprob -a if&lt;br /&gt;
  eth-s4p1c0      non sync(non secured)&lt;br /&gt;
  eth-s1p1c0      non sync(non secured)&lt;br /&gt;
  eth-s1p2c0      non sync(non secured)&lt;br /&gt;
  ae1c0           non sync(non secured)&amp;lt;br&amp;gt;&lt;br /&gt;
  Warning: Sync will not function since there aren't any sync(secured) interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
  Virtual cluster interfaces: 2&amp;lt;br&amp;gt;&lt;br /&gt;
  eth-s1p1c0      192.168.100.12&lt;br /&gt;
  eth-s1p2c0      192.168.254.11&lt;br /&gt;
&lt;br /&gt;
Solution:  Some of the steps from the SK39047 linked below were used.&lt;br /&gt;
&lt;br /&gt;
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39047&amp;amp;js_peid=P-114a7bc3b09-10006&amp;amp;partition=General&amp;amp;product=Security&lt;br /&gt;
&lt;br /&gt;
What I ended up doing  on firewall-1 was…&lt;br /&gt;
&lt;br /&gt;
 1)	 cpconfig &amp;gt; option 7 &amp;gt;  Disable cluster membership for this gateway&lt;br /&gt;
 2)	cpconfig &amp;gt; option 7 &amp;gt;  Enable cluster membership for this gateway&lt;br /&gt;
 3)	reboot&lt;br /&gt;
&lt;br /&gt;
Afterwards, I had a sync interface on firewall-1.  I plan to perform the same function on firewall-2.   However, a disruptive failover from firewall-2 to firewall-1 will be required.  Since state sync is broken, the failover will severe any statefull connections traversing the upper-rail.&lt;br /&gt;
&lt;br /&gt;
After the procedure above was run…&lt;br /&gt;
&lt;br /&gt;
 firewall-1[admin]# cphaprob -a if&lt;br /&gt;
&lt;br /&gt;
 eth-s1p1c0      non sync(non secured)&lt;br /&gt;
 eth-s1p2c0      non sync(non secured)&lt;br /&gt;
 eth-s4p1c0      non sync(non secured)&lt;br /&gt;
 ae1c0           sync(secured), multicast                     &amp;lt;&amp;lt;&amp;lt; hurray!!!&lt;br /&gt;
&lt;br /&gt;
 Virtual cluster interfaces: 2&lt;br /&gt;
&lt;br /&gt;
 eth-s1p1c0      192.168.100.12&lt;br /&gt;
 eth-s1p2c0      192.168.254.11&lt;br /&gt;
&lt;br /&gt;
 firewall-1[admin]# cphaprob stat&lt;br /&gt;
&lt;br /&gt;
 Cluster Mode:   Sync only (IPSO cluster)&lt;br /&gt;
&lt;br /&gt;
 Number     Unique Address  Firewall State (*)&lt;br /&gt;
&lt;br /&gt;
 1 (local)  1.1.1.1         Active                                     &amp;lt;&amp;lt;&amp;lt;&amp;lt; whoopee!!!&lt;br /&gt;
&lt;br /&gt;
[[category:check point]]&lt;/div&gt;</summary>
		<author><name>Nighthawk</name></author>	</entry>

	</feed>