sk182819 - VSX Cluster Members with VLAN interfaces change their cluster state to "Down" and "Active!" after installing a Jumbo Hotfix Accumulator
VSX Cluster Members with VLAN interfaces change their cluster state to "Down" and "Active!" after installing a Jumbo Hotfix Accumulator
Product: ClusterXL, VSX (Traditional)
Version: R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2024-11-25
Symptoms
In a VSX Cluster with VLAN interfaces, VSX Cluster Members may change their cluster state after installing one of these packages:
R81.20 Jumbo Hotfix Accumulator, Take 89
- R81.10 Jumbo Hotfix Accumulator, Take 170
- R81 Jumbo Hotfix Accumulator, Take 99
Problematic cluster states:
- The VSX Cluster Member with the new Jumbo Hotfix Accumulator Take changes its cluster state to "
Down"- The current Active VSX Cluster Member changes its cluster state to "
Active!"
- The current Active VSX Cluster Member changes its cluster state to "
- Output of the "
cphaprob -a -m if" command on the VSX Cluster Member with the new Jumbo Hotfix Accumulator Take might show the string "not configured" in the column "High VLAN" (meaning the highest configured VLAN is not monitored).
Cause
A temporary VLAN monitoring mismatch occurs during the installation of the Jumbo Hotfix Accumulator on the Standby VSX Cluster Member.
The Standby VSX Cluster Member starts monitoring only the lowest VLAN, while the Active VSX Cluster Member continues to monitor both the lowest VLAN and the highest VLAN (which is the default behavior).
This VLAN monitoring mismatch issue does not affect traffic flow or cluster failover functionality. The VSX Cluster Members continue to synchronize all connections.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 90
- Jumbo Hotfix Accumulator for R81.10 starting from Take 171
- Jumbo Hotfix Accumulator for R81 starting from Take 107
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Important Note -
If you installed:
- R81.20 Jumbo Hotfix Accumulator Take 89,
- R81.10 Jumbo Hotfix Accumulator Take 170,
- R81 Jumbo Hotfix Accumulator Take 99,
then the same issue will occur one more time during the installation of:
- R81.20 Jumbo Hotfix Accumulator Take 90,
- R81.10 Jumbo Hotfix Accumulator Take 171,
- R81 Jumbo Hotfix Accumulator Take 107.
Available options:
You can ignore the VLAN monitoring mismatch and proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members.
Perform a manual failover and then proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members:
- Connect to the command line on each VSX Cluster Member.
- Log in to Gaia Clish or the Expert mode.
- Examine the cluster state and the Critical Devices:
In Gaia Clish, run:
show cluster state
- In the Expert mode, run:
cphaprob state
If the row "Active PNOTEs" shows only "LPRB" or "IAC", then continue to the next step.
Otherwise, stop the workaround procedure - ignore the VLAN monitoring mismatch and proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members.
- Initiate a manual failover:
- If a VSX Cluster Member with the new Jumbo Hotfix Accumulator Take has the cluster state "
Down", then on the current Active VSX Cluster Member run the "cpstop" command.
- If a VSX Cluster Member with the new Jumbo Hotfix Accumulator Take has the cluster state "
- If a VSX Cluster Member with the new Jumbo Hotfix Accumulator Take has the cluster state "
Standby", then on the current Active VSX Cluster Member, run: - In Gaia Clish, run:
set cluster member admin down
- In the Expert mode, run:
clusterXL_admin down
5. Proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-11-06
Last Modified: 2024-11-25