<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: best practices to add VLAN interface in a cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132830#M19720</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Nothing special neither in gw nor in&amp;nbsp; console.&amp;nbsp; This behavior started after upgrade to R80.40 and the upgrade was right .&amp;nbsp; I'll continue to investigate this matter.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
    <pubDate>Thu, 28 Oct 2021 16:32:25 GMT</pubDate>
    <dc:creator>Maller</dc:creator>
    <dc:date>2021-10-28T16:32:25Z</dc:date>
    <item>
      <title>best practices to add VLAN interface in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132533#M19650</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;Usually&amp;nbsp; we have configured new DMZ adding it manually&amp;nbsp; "add interface etc..."&amp;nbsp; , to avoid issues using "get interfaces with topology " or "get interfaces without topology". In this way we have been working without issues in R80.10.&lt;/P&gt;&lt;P&gt;Now using this procedure ,we are facing an issue adding new vlan interfaces in a&amp;nbsp; R80.40 cluster . After install policy , new dmz VIP&amp;nbsp; are not configured . It does not appear in "cphaprob -a if "&amp;nbsp;&lt;/P&gt;&lt;P&gt;To solve this issue , we have to use "get interface without topology" .&amp;nbsp; I don't understand why manually process&amp;nbsp; is not working now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestion?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Manel&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 08:08:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132533#M19650</guid>
      <dc:creator>Maller</dc:creator>
      <dc:date>2021-10-25T08:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: best practices to add VLAN interface in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132536#M19652</link>
      <description>&lt;P&gt;Hi Manel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the DMZ VIP configured in the Cluster Topology? this should be manually configured after getting interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Yair&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 08:40:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132536#M19652</guid>
      <dc:creator>Yair_Shahar</dc:creator>
      <dc:date>2021-10-25T08:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: best practices to add VLAN interface in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132539#M19654</link>
      <description>&lt;P&gt;Hi Yair&lt;/P&gt;&lt;P&gt;yes , DMZ VIP is configured. What I don't understand is that&amp;nbsp; adding interfaces manually "&lt;SPAN&gt;actions -&amp;gt; new interface"&lt;/SPAN&gt; in FW object&amp;nbsp; ,&amp;nbsp; configuring VIP&amp;nbsp; and installing policy everything worked fine . This cluster has more than 70 DMZ&amp;nbsp; and all of them were configured in this way.&lt;/P&gt;&lt;P&gt;Now , since upgrade to R80.40&amp;nbsp; it seems that&amp;nbsp; manual way is not valid and we have to do it using "GET interfaces without topology " .&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 10:16:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132539#M19654</guid>
      <dc:creator>Maller</dc:creator>
      <dc:date>2021-10-25T10:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: best practices to add VLAN interface in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132603#M19663</link>
      <description>&lt;P&gt;Is it consistent? and happen on more than single interface?&lt;/P&gt;
&lt;P&gt;are all IPs and masks configured in Topology match the IPs and masks configured on Gaia?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried this on R81.10 and it does not seem to occur.&lt;/P&gt;
&lt;P&gt;I can try this with R80.40 later on - Which Jumbo Take are you using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yair&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 09:35:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132603#M19663</guid>
      <dc:creator>Yair_Shahar</dc:creator>
      <dc:date>2021-10-26T09:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: best practices to add VLAN interface in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132661#M19674</link>
      <description>&lt;P&gt;Hi Yair&lt;/P&gt;&lt;P&gt;Yes , it's consistent. All ip matches between topology and gaia.&amp;nbsp;&lt;/P&gt;&lt;P&gt;All new dmz are added to bond0.X interface.&lt;/P&gt;&lt;P&gt;This cluster is running r80.40 take 125.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a SR with support , and yes they said that the right&amp;nbsp; way to create new dmz is with get interface option . But I think that&amp;nbsp; option 'add interface' manually should work also and I don't understand why it doesn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With R80.10 always worked. Problems related to new interfaces creation&amp;nbsp; started with R80.40&amp;nbsp; .&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 20:05:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132661#M19674</guid>
      <dc:creator>Maller</dc:creator>
      <dc:date>2021-10-26T20:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: best practices to add VLAN interface in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132779#M19705</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have tried this on my lab with R80.40, I'm yet to see this issue occur.&lt;/P&gt;
&lt;P&gt;As mentioned - vlan, bond and ip configured on gaia, on cluster topology new interface created and configured manually (didn't use get-interfaces)&lt;/P&gt;
&lt;P&gt;after install policy new VIP added to cphaprob -a if - see below bond2..180&lt;/P&gt;
&lt;P&gt;Do I miss anything? is there any specific configuration you are using? on management or gateway side?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@cluster-member-83.27-R80.40-294:0]# cphaprob -a if&lt;/P&gt;
&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 5&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;
&lt;P&gt;eth0 UP &lt;BR /&gt;eth2 (S) UP &lt;BR /&gt;bond1 (HA) UP &lt;BR /&gt;bond2.9 (LS) UP &lt;BR /&gt;bond2.180 (LS) UP&lt;/P&gt;
&lt;P&gt;S - sync, LM - link monitor, HA/LS - bond type&lt;/P&gt;
&lt;P&gt;Virtual cluster interfaces: 55&lt;/P&gt;
&lt;P&gt;eth0 192.168.83.25 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond1 10.83.25.1 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.9 5.5.5.10 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.10 30.0.10.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.11 30.0.11.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.12 30.0.12.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.13 30.0.13.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.14 30.0.14.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.15 30.0.15.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.16 30.0.16.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.17 30.0.17.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.18 30.0.18.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.19 30.0.19.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.20 30.0.20.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.21 30.0.21.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.22 30.0.22.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.23 30.0.23.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.24 30.0.24.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.25 30.0.25.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.26 30.0.26.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.27 30.0.27.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.28 30.0.28.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.29 30.0.29.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.30 30.0.30.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.31 30.0.31.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.32 30.0.32.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.33 30.0.33.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.34 30.0.34.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.35 30.0.35.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.36 30.0.36.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.37 30.0.37.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.38 30.0.38.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.39 30.0.39.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.40 30.0.40.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.41 30.0.41.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.42 30.0.42.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.43 30.0.43.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.44 30.0.44.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.45 30.0.45.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.46 30.0.46.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.47 30.0.47.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.48 30.0.48.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.49 30.0.49.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.50 30.0.50.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.51 30.0.51.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.52 30.0.52.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.53 30.0.53.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.54 30.0.54.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.55 30.0.55.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.56 30.0.56.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.57 30.0.57.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.58 30.0.58.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.59 30.0.59.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;bond2.60 30.0.60.3 VMAC address: 00:1C:7F:00:4E:8E&lt;BR /&gt;&lt;STRONG&gt;bond2.180 60.60.60.60 VMAC address: 00:1C:7F:00:4E:8E&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 09:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132779#M19705</guid>
      <dc:creator>Yair_Shahar</dc:creator>
      <dc:date>2021-10-28T09:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: best practices to add VLAN interface in a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132830#M19720</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Nothing special neither in gw nor in&amp;nbsp; console.&amp;nbsp; This behavior started after upgrade to R80.40 and the upgrade was right .&amp;nbsp; I'll continue to investigate this matter.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 16:32:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practices-to-add-VLAN-interface-in-a-cluster/m-p/132830#M19720</guid>
      <dc:creator>Maller</dc:creator>
      <dc:date>2021-10-28T16:32:25Z</dc:date>
    </item>
  </channel>
</rss>

