<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMAC disadvantages in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109178#M14799</link>
    <description>&lt;P&gt;Part (1) Overview explains why it can be usefull to enable it - but most times it is just not needed and therefore not on by default.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 13:03:15 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-01-28T13:03:15Z</dc:date>
    <item>
      <title>VMAC disadvantages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109171#M14796</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The manual says that:&lt;BR /&gt;VMAC minimizes possible traffic outages,&amp;nbsp;during a failover. In addition, G-ARPs for NAT’d IP addresses are no longer needed.&lt;BR /&gt;VMAC failover time is shorter than a failover that involves a physical MAC address.&lt;/P&gt;&lt;P&gt;If it's so good, why disabled by default?&lt;BR /&gt;What are the disadvantages of VMAC?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 11:32:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109171#M14796</guid>
      <dc:creator>Boriska</dc:creator>
      <dc:date>2021-01-28T11:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: VMAC disadvantages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109172#M14797</link>
      <description>&lt;P&gt;Did you read the explanations here already: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk50840&amp;amp;partition=Basic&amp;amp;product=ClusterXL," target="_blank"&gt;sk50840: How to enable ClusterXL Virtual MAC (&lt;STRONG&gt;VMAC&lt;/STRONG&gt;) mode&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 11:42:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109172#M14797</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-28T11:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: VMAC disadvantages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109175#M14798</link>
      <description>&lt;P&gt;Yes, but didn't find there answer for my question, about&amp;nbsp;disadvantages.&lt;BR /&gt;Should I enable VMAC on every R80 ClusterXL HA? Or why I shouldn't?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 11:58:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109175#M14798</guid>
      <dc:creator>Boriska</dc:creator>
      <dc:date>2021-01-28T11:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: VMAC disadvantages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109178#M14799</link>
      <description>&lt;P&gt;Part (1) Overview explains why it can be usefull to enable it - but most times it is just not needed and therefore not on by default.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 13:03:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109178#M14799</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-28T13:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: VMAC disadvantages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109181#M14800</link>
      <description>&lt;P&gt;I understand your questions and I'm also not aware of any disadavantages. Yes, its not enabled by default, but we enable it on any Cluster XL HA Cluster.&lt;/P&gt;&lt;P&gt;Does anyone here knows disadavantages?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 13:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109181#M14800</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-01-28T13:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: VMAC disadvantages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109184#M14801</link>
      <description>&lt;P&gt;This is covered in my book.&amp;nbsp; If you don't have portfast enabled on all switchports where the clustered firewalls are attached, use of a VMAC can sometimes cause STP issues where upon failover STP blocks the ports for 10-12 seconds back into Listening &amp;amp; Learning mode.&amp;nbsp; &amp;nbsp;This is due to the same unicast MAC address briefly appearing on two switchports at the same time, which can be perceived by STP as a bridging loop.&amp;nbsp; This causes what I term a "slow" failover where all traffic comes to a screeching halt for about 10 seconds upon failover then suddenly starts working through the newly-active member.&amp;nbsp; On Cisco devices the involved switchports will glow amber during the "screech".&amp;nbsp; &amp;nbsp;Portfast is NOT the same as disabling STP completely which you should NEVER do.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bottom line: Use the default G-ARP unless you experience slow or incomplete failovers (especially for plucked NAT addresses), then try VMAC but be sure to set portfast.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 14:29:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VMAC-disadvantages/m-p/109184#M14801</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-01-28T14:29:03Z</dc:date>
    </item>
  </channel>
</rss>

