<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Query on Configuring interface to be not monitored in cluster but part of cluster. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Query-on-Configuring-interface-to-be-not-monitored-in-cluster/m-p/125918#M18280</link>
    <description>&lt;P&gt;Hi Team ,&lt;/P&gt;&lt;P&gt;Would like to know if we remove the Monitored interface from the cluster and make it has Private does it loose the VIP and the interface doesn't participate in the cluster anymore ?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Setup details :&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Checkpoint R80.20 in Cluster setup.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 6&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ClusterXL VLAN monitoring per interface:&lt;BR /&gt;&lt;BR /&gt;Interface | Low VLAN | High VLAN&lt;BR /&gt;&lt;BR /&gt;eth2-03 | 3XX | 6XX&lt;BR /&gt;eth1-01 | 3XX | not configured&lt;/P&gt;&lt;P&gt;Interface Name: Status:&lt;BR /&gt;eth1-01.XXX UP&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Security GW: Lowest and highest VLANs are monitored per interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial black,avant garde" color="#003366"&gt;Updated&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;-------------------------&lt;/P&gt;&lt;P class="xxxxxmsonormal"&gt;&lt;SPAN&gt;Like Cisco ASA (#no monitor-interface commands) we can disable monitoring from cluster.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxxxxmsonormal"&gt;&lt;SPAN&gt;But if we configure the Checkpoint with the network type private we cannot assign virtual IP address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Also&amp;nbsp;&lt;SPAN&gt;If we configure interface as Private, &lt;U&gt;&lt;STRONG&gt;can we enable RIP/DHCP without issue&lt;/STRONG&gt;&lt;/U&gt; and &lt;U&gt;&lt;STRONG&gt;what would be the gateway for downstream device if device get failover ?&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxxxxmsonormal"&gt;&lt;SPAN&gt;Also confirm are we going to lose VIP if we select network type as Private.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxmsonormal"&gt;&lt;SPAN&gt;If interface is part of cluster and we do not want to monitor that interface, like Cisco ASA is possible and there might have option in checkpoint as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxmsonormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any response on the above query.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Aug 2021 15:16:35 GMT</pubDate>
    <dc:creator>bookman</dc:creator>
    <dc:date>2021-08-17T15:16:35Z</dc:date>
    <item>
      <title>Query on Configuring interface to be not monitored in cluster but part of cluster.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Query-on-Configuring-interface-to-be-not-monitored-in-cluster/m-p/125918#M18280</link>
      <description>&lt;P&gt;Hi Team ,&lt;/P&gt;&lt;P&gt;Would like to know if we remove the Monitored interface from the cluster and make it has Private does it loose the VIP and the interface doesn't participate in the cluster anymore ?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Setup details :&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Checkpoint R80.20 in Cluster setup.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 6&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ClusterXL VLAN monitoring per interface:&lt;BR /&gt;&lt;BR /&gt;Interface | Low VLAN | High VLAN&lt;BR /&gt;&lt;BR /&gt;eth2-03 | 3XX | 6XX&lt;BR /&gt;eth1-01 | 3XX | not configured&lt;/P&gt;&lt;P&gt;Interface Name: Status:&lt;BR /&gt;eth1-01.XXX UP&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Security GW: Lowest and highest VLANs are monitored per interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial black,avant garde" color="#003366"&gt;Updated&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;-------------------------&lt;/P&gt;&lt;P class="xxxxxmsonormal"&gt;&lt;SPAN&gt;Like Cisco ASA (#no monitor-interface commands) we can disable monitoring from cluster.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxxxxmsonormal"&gt;&lt;SPAN&gt;But if we configure the Checkpoint with the network type private we cannot assign virtual IP address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Also&amp;nbsp;&lt;SPAN&gt;If we configure interface as Private, &lt;U&gt;&lt;STRONG&gt;can we enable RIP/DHCP without issue&lt;/STRONG&gt;&lt;/U&gt; and &lt;U&gt;&lt;STRONG&gt;what would be the gateway for downstream device if device get failover ?&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxxxxmsonormal"&gt;&lt;SPAN&gt;Also confirm are we going to lose VIP if we select network type as Private.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxmsonormal"&gt;&lt;SPAN&gt;If interface is part of cluster and we do not want to monitor that interface, like Cisco ASA is possible and there might have option in checkpoint as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xxmsonormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any response on the above query.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 15:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Query-on-Configuring-interface-to-be-not-monitored-in-cluster/m-p/125918#M18280</guid>
      <dc:creator>bookman</dc:creator>
      <dc:date>2021-08-17T15:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Query on Configuring interface to be not monitored in cluster but part of cluster.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Query-on-Configuring-interface-to-be-not-monitored-in-cluster/m-p/125923#M18282</link>
      <description>&lt;P&gt;Dynamic routing is currently not supported on cluster member private interfaces per&amp;nbsp;&lt;SPAN&gt;sk116815.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 14:21:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Query-on-Configuring-interface-to-be-not-monitored-in-cluster/m-p/125923#M18282</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-08-07T14:21:36Z</dc:date>
    </item>
  </channel>
</rss>

