I have several clusters from R55 to R62 and have not had that problem so far:
Code:
# cphaprob state
Cluster Mode: Sync only (IPSO cluster))
Number Unique Address Firewall State (*)
1 (local) gateway1.ip down (during cluster upgrade)
2 gateway2.ip active
(*) In IP Clustering/VRRP FW-1 also monitors the cluster status
This happened to cluster after I had upgraded it from R55 to R62. The way I do upgrade is that first I remove all R55 packages and then install R62 packages.
The problem is that now I can't enable FW monitoring in IPSO cluster. if I do, the cluster dissolves and all stops working. So far the VPN works, but i guess the cluster cannot switch automatically because of disabled monitoring.
The question is, how to get the cluster into active-active state again? I have tried restarting, deleting and creating IPSO cluster, reloading policys and even reinstalling CP R62 packages. Nothing seems to work.
Only reference that I found from the web is:
http://lists.virus.org/fw1-0607/msg00046.html I read the CheckPoint_NGX_UpgradeGuide.pdf and it was not helpful, my current problem is not mentioned anywhere either.