The information you are about to copy is INTERNAL!
DO NOT share it with anyone outside Check Point.
On cluster, Drop templates are disabled on reboot
Technical Level
Solution ID
sk153412
Technical Level
Product
SecureXL
Version
R80.10, R80.20, R80.30
OS
Gaia
Platform / Model
All
Date Created
14-May-2019
Last Modified
05-Jul-2020
Symptoms
On cluster member, Drop templates are disabled in reboot or cpstop ; cpstart. The status is shown as: "disabled by firewall".
Example:
[Expert@Hostname:0]# fwaccel stat
Accept Templates : enabled
Drop Templates : disabled by Firewall
NAT Templates : enabled
Pushing policy manually solves the issue.
Cause
While initializing drop templates, SecureXL is checking if clustering is up. Due to an issue with mistiming of SecureXL and cluster initialization drop templates are being disabled.