sk182660 - ClusterXL Standby member stays down because of the Critical Device "Fullsync"

ClusterXL Standby member stays down because of the Critical Device "Fullsync"

Product: ClusterXL
Version: R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2025-12-18

Symptoms

FULLSYNC: Server Starting sync on FW IPV4 instance #0 FULLSYNC: Server Finished sync on FW IPV4 instance #0 FULLSYNC: Policy changed during fullsync, stopping fullsync)

FULLSYNC: Finished full-sync for FW instance 0. LD data = XXX Kib, time for this instance = XX.XX Seconds. FULLSYNC: Starting full-sync for FW instance number 1. FULLSYNC: Failed to retrieve information form the kernel (fwfullsynctabinfo ioctl) FULLSYNC: Stopping on error 13

Cause

The CoreXL Firewall instances have different policy.

Solution

This problem was fixed. The fix is included starting from:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Workaround:

Important - Schedule a maintenance window because the procedure below can cause a traffic outage.

  1. Connect to the command line on the ClusterXL Active member.
  2. Log in.
  3. Stop the Check Point services: cpstop
  4. This triggers a ClusterXL failover.
  5. Start the Check Point services: cpstart
  6. Install policy on the cluster.

Policy installation must be successful on current ClusterXL Standby member.

Also, for cluster members, check the date of the policy installed with #fw stat; if there is a difference in policy date then reinstalling the policy helps to resolve the issue as well.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2024-09-16
Last Modified: 2025-12-18