<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vlan over Bond in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119547#M16906</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 15600 appliances with ClusterXL (active/standby)&lt;/P&gt;&lt;P&gt;Each of the nodes configured with 2 physical interfaces as an bond1 interface.&lt;/P&gt;&lt;P&gt;Operation Mode: 802.3ad&lt;/P&gt;&lt;P&gt;Transmit Hash Policy: Layer2 and LACP Rate: Slow&lt;/P&gt;&lt;P&gt;On top of the bond1 interface we configured 2 vlan's.&lt;/P&gt;&lt;P&gt;Link status in Gaia portal of the bond interface and vlan interfaces are Up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cphaprob -a if shows me:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;bond1 DOWN (88312 secs) non sync(non secured), unicast, bond Load Sharing (bond1.150)&lt;BR /&gt;bond1 DOWN (88312 secs) non sync(non secured), unicast, bond Load Sharing (bond1.151)&lt;/P&gt;&lt;P&gt;My questions is, must I also configure a static IP address on the bond1 interface or only on the bond1 vlan id's?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 May 2021 09:28:09 GMT</pubDate>
    <dc:creator>RayP</dc:creator>
    <dc:date>2021-05-27T09:28:09Z</dc:date>
    <item>
      <title>Vlan over Bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119547#M16906</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 15600 appliances with ClusterXL (active/standby)&lt;/P&gt;&lt;P&gt;Each of the nodes configured with 2 physical interfaces as an bond1 interface.&lt;/P&gt;&lt;P&gt;Operation Mode: 802.3ad&lt;/P&gt;&lt;P&gt;Transmit Hash Policy: Layer2 and LACP Rate: Slow&lt;/P&gt;&lt;P&gt;On top of the bond1 interface we configured 2 vlan's.&lt;/P&gt;&lt;P&gt;Link status in Gaia portal of the bond interface and vlan interfaces are Up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cphaprob -a if shows me:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;bond1 DOWN (88312 secs) non sync(non secured), unicast, bond Load Sharing (bond1.150)&lt;BR /&gt;bond1 DOWN (88312 secs) non sync(non secured), unicast, bond Load Sharing (bond1.151)&lt;/P&gt;&lt;P&gt;My questions is, must I also configure a static IP address on the bond1 interface or only on the bond1 vlan id's?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 09:28:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119547#M16906</guid>
      <dc:creator>RayP</dc:creator>
      <dc:date>2021-05-27T09:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan over Bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119558#M16908</link>
      <description>&lt;P&gt;You should only configure IP's on the VLAN interfaces, not on bond1 itself.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 10:33:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119558#M16908</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2021-05-27T10:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan over Bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119657#M16930</link>
      <description>&lt;P&gt;Thnx for the information Maarten.&lt;/P&gt;&lt;P&gt;What could be the reason that the physical interfaces and the bond is Up, but the bond vlan's are still down.&lt;/P&gt;&lt;P&gt;Are there some bond/vlan interfacing troubleshooting cli's.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 07:13:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119657#M16930</guid>
      <dc:creator>RayP</dc:creator>
      <dc:date>2021-05-28T07:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan over Bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119736#M16944</link>
      <description>&lt;P&gt;One of the most common problems is, that when you have multiple switches, the VLAN itself is not in the VLAN database of the switch that your gateway is connected to. Or there is allowed VLAn list on the port and it is not allowed.&lt;/P&gt;
&lt;P&gt;It boiles down to the point that the 2 gateways just do not see each other on the VLAN's.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 21:15:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119736#M16944</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2021-05-28T21:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan over Bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119756#M16950</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36329"&gt;@RayP&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;On an interface, a CCP (Cluster Conection Protocol) packet is sent every 100ms on the highest and lowest VLAN in both directions.&amp;nbsp; ClusterXL detects whether the neighboring interface can be reached. After four lost CCP packets (400ms) the cluster status goes into error mode (interface error) .&lt;BR /&gt;&lt;BR /&gt;If the interface is shown as down with "cphaprob -a if ", the two VLANs do not see each other gateway interface on the network. I think you have a layer 2 (ethernet or VLAN) problem between the two gateways on the switch. The same can be said for a LACP Bond.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 07:37:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119756#M16950</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-05-29T07:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan over Bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119842#M16958</link>
      <description>&lt;P&gt;Has this every worked?&lt;/P&gt;
&lt;P&gt;What is the switch make?&lt;/P&gt;
&lt;P&gt;What is the switchport configuration?&lt;/P&gt;
&lt;P&gt;Did you do a topology update and then push the configuration? (could be CCP issue)&lt;/P&gt;
&lt;P&gt;May be worth taking a look at&amp;nbsp;&lt;SPAN&gt;sk106776/sk92826 &amp;amp; sk121337&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What version of Checkpoint are you running (it should not really matter but its worth stating version of Checkpoint and What Jumbo your running).&lt;/P&gt;
&lt;P&gt;I have a pair of 15600s and bonded interface running a number of vlans, and as mentioned in this threat, any L3 configuration should only be made on the logical interface, and not on the bond.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 08:09:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vlan-over-Bond/m-p/119842#M16958</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-06-03T08:09:46Z</dc:date>
    </item>
  </channel>
</rss>

