<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VLAN subinterface not participating in HA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126958#M18373</link>
    <description>&lt;P&gt;Okay, thanks.&amp;nbsp; &amp;nbsp;This makes total sense now.&amp;nbsp; &amp;nbsp;I did see a discussion on this elsewhere on here, but I didn't understand that was applying to me in this case.&amp;nbsp; &amp;nbsp;Appreciate the explanation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 18:25:23 GMT</pubDate>
    <dc:creator>Quentin_Antrim</dc:creator>
    <dc:date>2021-08-13T18:25:23Z</dc:date>
    <item>
      <title>VLAN subinterface not participating in HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126948#M18371</link>
      <description>&lt;P&gt;Have an issue with VLAN subinterfaces not participating in HA.&lt;/P&gt;&lt;P&gt;R80.10, HW 6500 qty 2 running in active/active&lt;/P&gt;&lt;P&gt;I've got 3 VLAN subinterfaces on eth1-04:&amp;nbsp;&lt;/P&gt;&lt;P&gt;eth1-04.200&lt;/P&gt;&lt;P&gt;eth1-04.300&lt;/P&gt;&lt;P&gt;eth1-04.500&lt;/P&gt;&lt;P&gt;Prior to yesterday, eth1-04.200 and eth1-04.300 were the only existing subinterfaces and they both were participating in HA.&amp;nbsp; &amp;nbsp;Yesterday, I set up new VLAN subinterface eth1-04.500 in Gaia and as a Cluster interfaces in FW gateway object, etc.&lt;/P&gt;&lt;P&gt;Afterwards, eth1-04.500 was not showing up in HA at either command line or in SmartConsole "Gateways &amp;amp; Servers".&amp;nbsp;&lt;/P&gt;&lt;P&gt;Decided to go ahead and individually reboot the two enforcement points as a hopefully simple way to clear that up, and they had been up for a long time so wanted to refresh anyway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Afterwards, eth1-04.500 did begin to show up in HA, but then eth1-04.300 stopped showing up in HA.&amp;nbsp; Further reboot and policy pushes do not change this.&lt;/P&gt;&lt;P&gt;Here is cphaprob -a if from one gateway:&lt;/P&gt;&lt;P&gt;[Expert@chw_pbx_bbfw1:0]# cphaprob -a if&lt;/P&gt;&lt;P&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), multicast&lt;BR /&gt;bond41 UP non sync(non secured), multicast, bond Load Sharing&lt;BR /&gt;eth1-04 UP non sync(non secured), multicast (eth1-04.500)&lt;BR /&gt;eth1-04 UP non sync(non secured), multicast (eth1-04.200)&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 4&lt;/P&gt;&lt;P&gt;bond41 10.150.2.188&lt;BR /&gt;eth1-04.500 10.5.1.21&lt;BR /&gt;eth1-04.200 10.2.0.1&lt;BR /&gt;eth1-04.300 10.3.6.49&lt;/P&gt;&lt;P&gt;Any idea what happened?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Q (Quentin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 15:34:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126948#M18371</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2021-08-13T15:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN subinterface not participating in HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126953#M18372</link>
      <description>&lt;P&gt;By default, Check Point only monitors the highest VLAN ID and the lowest VLAN ID on each interface. The other interfaces still get cluster VIPs, as you can see in your 'cphaprob -a if' output, but they don't get CCP heartbeats. After all, the infrastructure between the firewalls on all of those interfaces is all but guaranteed to be the same, so more CCP would just waste more of the interface's time slots. Imagine the overhead of sending heartbeats on each of 500 VLAN IDs on a given interface.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 16:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126953#M18372</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-08-13T16:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN subinterface not participating in HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126958#M18373</link>
      <description>&lt;P&gt;Okay, thanks.&amp;nbsp; &amp;nbsp;This makes total sense now.&amp;nbsp; &amp;nbsp;I did see a discussion on this elsewhere on here, but I didn't understand that was applying to me in this case.&amp;nbsp; &amp;nbsp;Appreciate the explanation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 18:25:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126958#M18373</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2021-08-13T18:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN subinterface not participating in HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126994#M18386</link>
      <description>&lt;P&gt;I appreciate the low/high vlan heartbeat design - But if you are in a company like hours, we see from time to time a vlan is missing in our infrastructure, so 4 months later, the cluster does a failover and all traffic is blackholed.&lt;/P&gt;&lt;P&gt;Just something to be aware of. The CCP heartbeat behaviour can be changed if you wish.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Henrik&lt;/P&gt;</description>
      <pubDate>Sun, 15 Aug 2021 12:47:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VLAN-subinterface-not-participating-in-HA/m-p/126994#M18386</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2021-08-15T12:47:28Z</dc:date>
    </item>
  </channel>
</rss>

