<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create a bond Interface without outage in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/160928#M28409</link>
    <description>&lt;P&gt;Hi Experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running a cluster on r80.40, and need to create a new bond interface as one of our interfaces is being overutilized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once new create the new bond interface using two new unused ports we move&amp;nbsp;&lt;SPAN&gt;the IP config of the used Interface to the new bond interface&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there a possibility how i could do this procedure without any downtime?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sijeel&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Nov 2022 15:27:41 GMT</pubDate>
    <dc:creator>Malik1</dc:creator>
    <dc:date>2022-11-01T15:27:41Z</dc:date>
    <item>
      <title>Create a bond Interface without outage</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/160928#M28409</link>
      <description>&lt;P&gt;Hi Experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running a cluster on r80.40, and need to create a new bond interface as one of our interfaces is being overutilized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once new create the new bond interface using two new unused ports we move&amp;nbsp;&lt;SPAN&gt;the IP config of the used Interface to the new bond interface&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there a possibility how i could do this procedure without any downtime?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sijeel&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 15:27:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/160928#M28409</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2022-11-01T15:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create a bond Interface without outage</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/160940#M28411</link>
      <description>&lt;P&gt;I dont think you can do it without outage. First, you are "moving" IP config, ports will be different, then you also have to "get topology..." in dashboard and push the policy.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 18:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/160940#M28411</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-01T18:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Create a bond Interface without outage</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/160947#M28414</link>
      <description>&lt;P&gt;Nope, not possible. Plan a service window.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 19:37:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/160947#M28414</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-01T19:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Create a bond Interface without outage</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/161044#M28467</link>
      <description>&lt;P&gt;Thanks val.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more question do we break the clustering during the change to avoid any unwanted failover, we are using VRRP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/161044#M28467</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2022-11-02T15:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Create a bond Interface without outage</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/161078#M28477</link>
      <description>&lt;P&gt;No, you have to plan the downtime for this activity.&lt;/P&gt;
&lt;P&gt;But you can minimize the duration of the downtime.&lt;/P&gt;
&lt;P&gt;Some steps before migration itself:&lt;/P&gt;
&lt;P&gt;1. Make sure newly created bond can see Partner's MAC and LACP is working fine.&lt;/P&gt;
&lt;P&gt;2. Make sure the needed VLANs (if used) are correctly created/tagged on the relevant switch(s).&lt;/P&gt;
&lt;P&gt;3. Have all the config and steps prepared in advance (including rollback situation)&lt;/P&gt;
&lt;P&gt;4. Perform backup and snapshot on both cluster members&lt;/P&gt;
&lt;P&gt;One of the scenario during migration itself:&lt;/P&gt;
&lt;P&gt;1. Change the topology information in SmartConsole (name of interface) and push the policy. The firewall will not change the VIP since the IPs are assigned to the current interface.&lt;/P&gt;
&lt;P&gt;2. Bring standby member down (clusterXL_admin down)&lt;/P&gt;
&lt;P&gt;3. On down member, change the IP config over CLI (remove IP from single interface and assign to the bond)&lt;/P&gt;
&lt;P&gt;4. Push the policy once again&lt;/P&gt;
&lt;P&gt;5. Down member should have VIP assigned to the bond, while active member on single current interface&lt;/P&gt;
&lt;P&gt;6. Cluster_XL admin up on down member. That may cause the failover to the node which already has info about bond interface.&lt;/P&gt;
&lt;P&gt;7. If the member is still down, try to shutdown some interface on active node or perform cpstop on active node in order to force the failover&lt;/P&gt;
&lt;P&gt;8. Perform IP config change on former active node&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 05:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-a-bond-Interface-without-outage/m-p/161078#M28477</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2022-11-03T05:05:40Z</dc:date>
    </item>
  </channel>
</rss>

