sk182819 - VSX Cluster Members with VLAN interfaces change their cluster state to "Down" and "Active!" after installing a Jumbo Hotfix Accumulator

VSX Cluster Members with VLAN interfaces change their cluster state to "Down" and "Active!" after installing a Jumbo Hotfix Accumulator

Product: ClusterXL, VSX (Traditional)

Version: R81 (EOS), R81.10 (EOS), R81.20

OS: Gaia

Last Modified: 2024-11-25

Symptoms

Problematic cluster states:

Cause

A temporary VLAN monitoring mismatch occurs during the installation of the Jumbo Hotfix Accumulator on the Standby VSX Cluster Member.

The Standby VSX Cluster Member starts monitoring only the lowest VLAN, while the Active VSX Cluster Member continues to monitor both the lowest VLAN and the highest VLAN (which is the default behavior).

This VLAN monitoring mismatch issue does not affect traffic flow or cluster failover functionality. The VSX Cluster Members continue to synchronize all connections.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Important Note -

If you installed:

then the same issue will occur one more time during the installation of:

Available options:

show cluster state

cphaprob state

If the row "Active PNOTEs" shows only "LPRB" or "IAC", then continue to the next step.

Otherwise, stop the workaround procedure - ignore the VLAN monitoring mismatch and proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members.

  1. Initiate a manual failover:
    • If a VSX Cluster Member with the new Jumbo Hotfix Accumulator Take has the cluster state "Down", then on the current Active VSX Cluster Member run the "cpstop" command.

set cluster member admin down

clusterXL_admin down 5. Proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2024-11-06

Last Modified: 2024-11-25