<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Full mesh redundancy HA cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165411#M29654</link>
    <description>&lt;P&gt;In my 15 years dealing with CP, I had never seen that before. Not saying its not possible, but cant really find any documentation about it either.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Dec 2022 13:26:39 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-12-16T13:26:39Z</dc:date>
    <item>
      <title>Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165264#M29626</link>
      <description>&lt;P&gt;Im trying to make a full mesh redundancy on my HA cluster. I have read the admin guide but it says nothing on how to configure a full mesh redundancy. I created bond interfaces(802.3ad) which has two sub interfaces on each of the gateways. I have two core switches and configured LACP on it. The network is up but i am not able to ping the secondary gateway and i can see that the bond interface on the 2nd gateway is down while the bond interface on the primary is up.&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Nima&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 10:45:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165264#M29626</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2022-12-15T10:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165265#M29627</link>
      <description>&lt;P&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;I have read the admin guide but it says nothing on how to configure a full mesh redundancy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/Bond-HA-in-Cluster-Fully-Meshed-Redundancy.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/Bond-HA-in-Cluster-Fully-Meshed-Redundancy.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 11:01:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165265#M29627</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-15T11:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165268#M29628</link>
      <description>&lt;P&gt;Hi Albrecht,&lt;/P&gt;&lt;P&gt;I didnt see a topic on how i could configure the bond&amp;nbsp; interfaces in a full mesh redundancy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Nima&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 11:14:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165268#M29628</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2022-12-15T11:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165271#M29629</link>
      <description>&lt;P&gt;Here it states:&amp;nbsp;&lt;SPAN&gt;Bonding provides &lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ha variable"&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt; of NICs. If one fails, the other can function in its place. But just read further:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="mc-main-content" role="main"&gt;
&lt;H1&gt;&lt;FONT size="4"&gt;Configuring a Bond Interface in &lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ha variable"&gt;High Availability&lt;/SPAN&gt; Mode&lt;/FONT&gt;&lt;/H1&gt;
&lt;P&gt;On each &lt;SPAN class="mc-variable Vars_BladesFeatures.tp_clmb variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/Configuring-Bond-in-ClusterXL.htm?tocpath=Advanced%20Features%20and%20Procedures%7CWorking%20with%20Bond%20Interfaces%20in%20Cluster%7CBond%20High%20Availability%20Mode%20in%20Cluster%7C_____4#" target="_blank" rel="noopener" data-mc-state="closed" data-aria-describedby="5080ddf6-5812-402a-8171-c3bbb717e161"&gt;Cluster Member&lt;/A&gt;&lt;/SPAN&gt;, follow the instructions in the &lt;EM&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Default.htm" target="_blank" rel="noopener"&gt;R81 Gaia Administration Guide&lt;/A&gt;&lt;/EM&gt; - Chapter &lt;EM&gt;Network Management&lt;/EM&gt; - Section &lt;EM&gt;Network Interfaces&lt;/EM&gt; - Section &lt;EM&gt;Bond Interfaces (&lt;SPAN class="mc-variable Vars_Other.tp_la variable"&gt;Link Aggregation&lt;/SPAN&gt;)&lt;/EM&gt;.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Dec 2022 11:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165271#M29629</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-15T11:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165272#M29630</link>
      <description>&lt;P&gt;It still doesnt tell me on how to configure a full mesh redundancy .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Nima&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 12:11:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165272#M29630</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2022-12-15T12:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165286#M29636</link>
      <description>&lt;P&gt;Did you study all relevant topics from start of the ClusterXL Admin Guide ?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 13:06:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165286#M29636</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-15T13:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165292#M29637</link>
      <description>&lt;P&gt;K, lets start with basics...if you say those interfaces are down on backup member, can you send output of below in clish:&lt;/P&gt;
&lt;P&gt;Lets assume interface name is bond007&lt;/P&gt;
&lt;P&gt;show interface bond007&lt;/P&gt;
&lt;P&gt;Then from expert mode run below:&lt;/P&gt;
&lt;P&gt;cpstat fw -f interfaces&lt;/P&gt;
&lt;P&gt;cpstat fw -f all&lt;/P&gt;
&lt;P&gt;Please send output of everything (please blour out any sensitive info).&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 13:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165292#M29637</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-15T13:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165319#M29639</link>
      <description>&lt;P&gt;You keep saying "full mesh redundancy". Could you define exactly what you mean by that for us? That term isn't meaningful on its own without further information. A diagram may be helpful.&lt;/P&gt;
&lt;P&gt;What sorts of faults are you trying to defend against?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 16:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165319#M29639</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-12-15T16:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165358#M29641</link>
      <description>&lt;P&gt;By Full mesh redundancy i mean something like this..&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="fullmeshredundancy.png" style="width: 744px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18812i660C6A0708F2895D/image-size/large?v=v2&amp;amp;px=999" role="button" title="fullmeshredundancy.png" alt="fullmeshredundancy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;When i run the command cphaconf show_bond bond1 all the slave interfaces are shown as active on both the checkpoint gateways but the status of the bond interface is shown as down on the gateway which is currently on standby and UP on the gateway which is currently taking the network load.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 04:01:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165358#M29641</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2022-12-16T04:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165378#M29647</link>
      <description>&lt;P&gt;On the switches, have you configured two separate LACP bonds (one per gateway with two interfaces each) or one big one with all four interfaces?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 07:03:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165378#M29647</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2022-12-16T07:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165409#M29653</link>
      <description>&lt;P&gt;On the switch i have configured one lacp interface with four slave interfaces.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 12:58:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165409#M29653</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2022-12-16T12:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165411#M29654</link>
      <description>&lt;P&gt;In my 15 years dealing with CP, I had never seen that before. Not saying its not possible, but cant really find any documentation about it either.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 13:26:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165411#M29654</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-16T13:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165421#M29656</link>
      <description>&lt;P&gt;So 4 and 5 are two physically separate switches capable of multi-chassis link aggregation (Cisco MEC, vPC, or similar)?&lt;/P&gt;
&lt;P&gt;There is no way to have a single aggregate link with members on multiple Check Point servers.&lt;/P&gt;
&lt;P&gt;Separately, I cannot advise more strongly against using multi-chassis link aggregation technologies. They lead to bad availability design elsewhere, which causes outages to be both more frequent and &lt;EM&gt;&lt;STRONG&gt;much more severe&lt;/STRONG&gt;&lt;/EM&gt; than they would have been. I say this from direct personal experience.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 14:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165421#M29656</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-12-16T14:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165559#M29705</link>
      <description>&lt;P&gt;Why would you do it as shown? I also second what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;said, this looks like a bad design.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 11:05:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165559#M29705</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-12-19T11:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165567#M29708</link>
      <description>&lt;P&gt;Look:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/Bond-HA-in-Cluster-Fully-Meshed-Redundancy.htm" target="_blank" rel="noopener noreferrer"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/B...&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 11:32:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165567#M29708</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-19T11:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165570#M29710</link>
      <description>&lt;P&gt;Sorry, you are right &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Removed my previous comment. This is... interesting&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 11:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165570#M29710</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-12-19T11:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165594#M29714</link>
      <description>&lt;P&gt;I don't think I've seen that documentation before. Interesting.&lt;/P&gt;
&lt;P&gt;It's talking about active/backup transmit link selection (e.g,&amp;nbsp;&lt;SPAN&gt;set bonding group 0 mode active-backup&lt;/SPAN&gt;). This topology can't be achieved with LACP. The switches should not be aware of the link aggregation. As far as they are concerned, the ports leading to the firewalls are plain access or tagged ports.&lt;/P&gt;
&lt;P&gt;While that would be functional, it has some complicated availability implications. Active/backup bonds receive on all members, but only transmit on one. Only loss of layer 2 link would cause the firewall to switch to the alternate interface. If something failed past the immediately-connected switches causing traffic through only one to work, the firewalls are unlikely to be able to tell. It might be possible for ClusterXL to tell as long as fw1 was using switch 4 primarily and fw2 was using switch 5 primarily. Then, if a link between the switches failed, the cluster heartbeats on that interface would fail, which could cause a failover of the firewall cluster. To maintain this pathing, you would need to specify a primary link for the bond (e.g,&amp;nbsp;&lt;SPAN&gt;set bonding group 0 primary eth2).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would test this &lt;EM&gt;&lt;STRONG&gt;extensively&lt;/STRONG&gt;&lt;/EM&gt; before depending on it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edit&lt;/STRONG&gt;: No, wait. If each switch is operating correctly in isolation, but one of them has no access to the broader network, the cluster heartbeats wouldn't fail. fw1 would transmit to switch 4, which is still able to get to fw2. fw2 would transmit to switch 5, which is still able to get to fw1.&lt;/P&gt;
&lt;P&gt;I'm not sure there's a good way to get this topology to tolerate failures which cut one of the switches off from the broader network.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 15:51:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165594#M29714</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-12-19T15:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165603#M29717</link>
      <description>&lt;P&gt;I honestly never seen that part of doc before, I guess my "searching" skills are not as good as yours Guenther : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 22:40:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165603#M29717</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-19T22:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165621#M29720</link>
      <description>&lt;P&gt;Yeah, theres no proper documentation on how we can achieve a full mesh redundancy... it only says we can do it.. I have read countless documentation at this point and i stumbled on R81.10 clusterXL documentation which tells us about group bonding. dont know if that will work on r80.10..&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 04:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165621#M29720</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2022-12-20T04:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Full mesh redundancy HA cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165622#M29721</link>
      <description>&lt;P&gt;4 and 5 are two physically separate servers and the switch is using ciscos stackwise virtual domain&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 04:28:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-mesh-redundancy-HA-cluster/m-p/165622#M29721</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2022-12-20T04:28:24Z</dc:date>
    </item>
  </channel>
</rss>

