<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>HA cluster problem</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/136117/ha-cluster-problem</link><description>Hi, 
 we have a HA cluster that is in standalone/faulty state. The faulty device (standby) is still reachable through SSH over the HA link but as far as I can see it has the same IP configured on the LAN interface and so I cannot reach it through the</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: HA cluster problem</title><link>https://community.sophos.com/thread/504413?ContentTypeID=1</link><pubDate>Wed, 31 Aug 2022 15:23:21 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:08d487a5-794f-4438-b76d-c7119c7147cc</guid><dc:creator>kerobra</dc:creator><description>&lt;p&gt;OK, we can cut it off here...&lt;br /&gt;I requested the customer to take a picture of both firewalls and you imagine what? Port1 had no link.&lt;/p&gt;
&lt;p&gt;They seem to have found the issue since both nodes are available and synced now and the peer admin IP is reachable, too.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: HA cluster problem</title><link>https://community.sophos.com/thread/504409?ContentTypeID=1</link><pubDate>Wed, 31 Aug 2022 14:22:09 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cb86d93f-5ac5-4264-8bfc-050e61acf2f4</guid><dc:creator>Bharat J</dc:creator><description>&lt;p&gt;From SSH, Go to option 4 and share the status of the logs :&amp;nbsp;&lt;/p&gt;
&lt;p&gt;console&amp;gt;system ha show details&lt;/p&gt;
&lt;p&gt;&lt;span&gt;console&amp;gt;system ha show logs lines 10000&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Also, share the status under CONFIGURE --&amp;gt;System Services ---&amp;gt;High Availability and Device Access status under System-&amp;gt;Administration&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Regards&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: HA cluster problem</title><link>https://community.sophos.com/thread/504407?ContentTypeID=1</link><pubDate>Wed, 31 Aug 2022 14:12:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:989542f6-2703-4e72-9e6a-94cbbd771885</guid><dc:creator>kerobra</dc:creator><description>&lt;p&gt;But that is the device concole, not advanced shell. I can only use advanced shell/SSH through the dedicated HA link.&lt;br /&gt;As I said, physical access is not possible because the devices are located in romania and we are located in germany, which makes it a bit difficult to plug cables.&lt;br /&gt;&lt;br /&gt;If I had physical access I would have reinitiated the HA services meanwhile and could also check the device cabling. But I am forced to remote assistance only, that is my problem.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: HA cluster problem</title><link>https://community.sophos.com/thread/504406?ContentTypeID=1</link><pubDate>Wed, 31 Aug 2022 13:51:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a498cf2e-76d4-46e1-9049-ea41adf2ad96</guid><dc:creator>Bharat J</dc:creator><description>[quote userid="39954" url="~/sophos-xg-firewall/f/discussions/136117/ha-cluster-problem"]Is there any way to disable/enable HA through SSH so I can bring back the HA cluster?[/quote]
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1661953581007v1.png" /&gt;&lt;/p&gt;
&lt;p&gt;console&amp;gt;system ha disable&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The above command will disable HA&lt;/p&gt;
&lt;p&gt;Make sure to take regular backups of the existing configuration.&lt;/p&gt;
&lt;p&gt;Please run the command before you try to disable HA from SSH as well as from console with serial cable from Both the Appliance.&lt;/p&gt;
&lt;p&gt;console&amp;gt;system ha show details&lt;/p&gt;
&lt;p&gt;&lt;span&gt;console&amp;gt;system ha show logs lines 10000&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If you want to enable HA back that is done from GUI only as per the link&amp;nbsp;&lt;a href="https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosFirewall/Pocket-Guides/Active-Passive-HA-Configuration.pdf"&gt;https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosFirewall/Pocket-Guides/Active-Passive-HA-Configuration.pdf&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Please share the output&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: HA cluster problem</title><link>https://community.sophos.com/thread/504402?ContentTypeID=1</link><pubDate>Wed, 31 Aug 2022 13:28:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9eacb98c-3f76-471b-8f14-3ea8eb49c678</guid><dc:creator>kerobra</dc:creator><description>&lt;p&gt;Should the port status in dmesg, executed on the backup device through the SSH-connection of the HA-interface show all interfaces up?&lt;br /&gt;Here is the output for Port1 (LAN):&lt;br /&gt;&lt;pre class="ui-code" data-mode="less"&gt;[    8.470997] igb_nm 0000:02:00.0 Port1: renamed from eth0
[   62.745131] 505.242015 [2311] netmap_do_regif           vale0:Port1: lut ffffaa2a41fb1000 bufs 33792 size 2048
[   62.745135] 505.242021 [2334] netmap_do_regif           vale0:Port1: mtu 1500 rx_buf_maxsize 2048 netmap_buf_size 2048
[   63.423428] vfp info: vale_ports_map_table_init:326: Adding LIF for Port1 index 0
[   63.423445] vfp info: vale_ports_map_table_init:377:   Port   0:  &amp;quot;vale0:Port1&amp;quot;, Phys port 0. &amp;lt;=&amp;gt; Vale Stack 1, vale0:Port1^
[   63.423446] vfp info: vale_ports_map_table_init:382:   Port   1:  &amp;quot;vale0:Port1^&amp;quot;, Stack port. &amp;lt;=&amp;gt; Vale Phys 0, vale0:Port1
[   63.423457] vfp info: vale_ports_map_table_init:394:   Phys 0 &amp;lt;-&amp;gt; Vale 0 (vale0:Port1)
[   66.934095] IPv6: ADDRCONF(NETDEV_UP): Port1: link is not ready
[   66.934097] 8021q: adding VLAN 0 to HW filter on device Port1
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;and here for Port2 (WAN):&lt;br /&gt;&lt;pre class="ui-code" data-mode="less"&gt;[    8.492227] igb_nm 0000:03:00.0 Port2: renamed from eth1
[   62.828708] 505.325592 [2311] netmap_do_regif           vale0:Port2: lut ffffaa2a41fb1000 bufs 33792 size 2048
[   62.828711] 505.325597 [2334] netmap_do_regif           vale0:Port2: mtu 1500 rx_buf_maxsize 2048 netmap_buf_size 2048
[   63.423431] vfp info: vale_ports_map_table_init:326: Adding LIF for Port2 index 1
[   63.423447] vfp info: vale_ports_map_table_init:377:   Port   2:  &amp;quot;vale0:Port2&amp;quot;, Phys port 1. &amp;lt;=&amp;gt; Vale Stack 3, vale0:Port2^
[   63.423447] vfp info: vale_ports_map_table_init:382:   Port   3:  &amp;quot;vale0:Port2^&amp;quot;, Stack port. &amp;lt;=&amp;gt; Vale Phys 2, vale0:Port2
[   63.423457] vfp info: vale_ports_map_table_init:394:   Phys 1 &amp;lt;-&amp;gt; Vale 2 (vale0:Port2)
[   68.303971] IPv6: ADDRCONF(NETDEV_UP): Port2: link is not ready
[   68.303973] 8021q: adding VLAN 0 to HW filter on device Port2
[   72.656850] igb_nm 0000:03:00.0 Port2: igb: Port2 NIC Link is Up 1000 Mbps Full Duplex, Flow Control: None
[   72.657097] IPv6: ADDRCONF(NETDEV_CHANGE): Port2: link becomes ready&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;With my very basic linux skills I would say that the backup appliance is not connected with all interfaces it should be, well the customer onsite says all links are up. And therefore I cannot reach the faulty appliance through the designated peer admin interface (LAN) from a server inside the LAN.&lt;/p&gt;
&lt;p&gt;Would you agree with my suggestion of a failed link?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: HA cluster problem</title><link>https://community.sophos.com/thread/503901?ContentTypeID=1</link><pubDate>Fri, 26 Aug 2022 15:37:12 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8af6f365-20dc-4173-bf30-c9504b8b1790</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Ifconfig will always show the IP of the Primary. HA does not work with Ifconfig in this scenario. Instead it will tag a alias as the peer Administration ip. So you do not see the alias. There is a known limitation, you cannot access the peer administration IP through the primary (for example like a IPsec tunnel). So you need a device on site to access the peer adminstration.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;BTW: If you break the HA, you would be able to access the peer administration remotely.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If you can access via SSH, check the applogs of both appliances to see the reason for the failure in the first place, before starting to break the HA.&lt;/p&gt;
&lt;p&gt;You can do #grep ha: applog.log | less&amp;nbsp; &amp;nbsp; &amp;nbsp; for more insight on both appliances.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: HA cluster problem</title><link>https://community.sophos.com/thread/503878?ContentTypeID=1</link><pubDate>Fri, 26 Aug 2022 13:01:49 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d7f2ce67-a83c-4ce6-b914-039f3580f921</guid><dc:creator>Bharat J</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;span&gt;&lt;a href="/members/kerobra"&gt;kerobra&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Please follow&amp;nbsp;&lt;span&gt;How to troubleshoot HA issues link as below share your finding on logs :&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/HighAvailablityStartupGuide/HATroubleshooting/index.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/HighAvailablityStartupGuide/HATroubleshooting/index.html&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks and Regards&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>