<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Notice regarding clusterXL, failover and Cisco Meraki... in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108626#M14681</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Thought this could be good knowledge to publish as this will no doubt, if not already, resulted in many calls to TAC.&lt;/P&gt;&lt;P&gt;I was working on a cluster for a customer recently - upgrading hardware and software.&lt;/P&gt;&lt;P&gt;Failover between the firewalls were taking 5 minutes during a simulated and unplanned outage. All the usual CXL and failover troubleshooting was done. Check Point side, it was solid. No problems with state sync.&lt;/P&gt;&lt;P&gt;I decided to enable vMAC which brought the whole network to life. Failover instant with no packet loss at all.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;vMAC is literally designed for reasons like this, but it looks like Meraki doesn’t ‘support’ G-ARP.&lt;/P&gt;&lt;P&gt;A Citrix ADC user fell into the same issue here.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.meraki.com/t5/Switching/Meraki-MS-switching-and-Gratuitous-ARP-with-Citrix-ADC-Netscaler/td-p/93078" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.meraki.com/t5/Switching/Meraki-MS-switching-and-Gratuitous-ARP-with-Citrix-ADC-Net...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I think it would be useful for Check Point to publish this in order to assist customer first hand as the issue on first glance looks like the Check Points themselves.&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jan 2021 01:15:35 GMT</pubDate>
    <dc:creator>JackPrendergast</dc:creator>
    <dc:date>2021-01-24T01:15:35Z</dc:date>
    <item>
      <title>Notice regarding clusterXL, failover and Cisco Meraki...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108626#M14681</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Thought this could be good knowledge to publish as this will no doubt, if not already, resulted in many calls to TAC.&lt;/P&gt;&lt;P&gt;I was working on a cluster for a customer recently - upgrading hardware and software.&lt;/P&gt;&lt;P&gt;Failover between the firewalls were taking 5 minutes during a simulated and unplanned outage. All the usual CXL and failover troubleshooting was done. Check Point side, it was solid. No problems with state sync.&lt;/P&gt;&lt;P&gt;I decided to enable vMAC which brought the whole network to life. Failover instant with no packet loss at all.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;vMAC is literally designed for reasons like this, but it looks like Meraki doesn’t ‘support’ G-ARP.&lt;/P&gt;&lt;P&gt;A Citrix ADC user fell into the same issue here.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.meraki.com/t5/Switching/Meraki-MS-switching-and-Gratuitous-ARP-with-Citrix-ADC-Netscaler/td-p/93078" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.meraki.com/t5/Switching/Meraki-MS-switching-and-Gratuitous-ARP-with-Citrix-ADC-Net...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I think it would be useful for Check Point to publish this in order to assist customer first hand as the issue on first glance looks like the Check Points themselves.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 01:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108626#M14681</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-01-24T01:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: Notice regarding clusterXL, failover and Cisco Meraki...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108627#M14682</link>
      <description>&lt;P&gt;Useful tip, thanks for sharing.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 01:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108627#M14682</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-24T01:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Notice regarding clusterXL, failover and Cisco Meraki...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108629#M14684</link>
      <description>&lt;P&gt;Great tip.&amp;nbsp; I mentioned this effect in my Max Power 2020 book and called it a "slow" failover, also mentioning the fact that some devices don't accept gratuitous ARPs because they track "state" for ARP and will reject an ARP Reply that they did not explicitly request.&amp;nbsp; Generally leaving "Enable VMAC" UNchecked is recommended unless a slow failover is encountered, as the default Gratuitous ARP mechanism does the job on most networks; VMAC mode can cause additional issues in some cases if portfast is not set on the switchports the firewall is attached to.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 02:44:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108629#M14684</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-01-24T02:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Notice regarding clusterXL, failover and Cisco Meraki...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108654#M14699</link>
      <description>&lt;P&gt;Well, that’s exactly what I referred to when I was stood staring at the screen looking confused! I remembered something in your book and went to have a look.&lt;/P&gt;&lt;P&gt;I don’t ever use vMAC for any deployment but it’s a great remedy. Thanks Tim&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 10:25:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Notice-regarding-clusterXL-failover-and-Cisco-Meraki/m-p/108654#M14699</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-01-24T10:25:00Z</dc:date>
    </item>
  </channel>
</rss>

