<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to configure my switch for cluster xl in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167960#M30352</link>
    <description>&lt;P&gt;[Expert@xyz-cp01:0]# cphaprob roles&lt;/P&gt;
&lt;P&gt;ID Role&lt;/P&gt;
&lt;P&gt;1 (local) Non-Master&lt;BR /&gt;2 Master&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob state&lt;/P&gt;
&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;
&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;
&lt;P&gt;1 (local) 10.222.222.1 0% DOWN xyz-cp01&lt;BR /&gt;2 10.222.222.2 100% ACTIVE xyz-cp02&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: LPRB, IAC&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-110800&lt;BR /&gt;State change: STANDBY -&amp;gt; DOWN&lt;BR /&gt;Reason for state change: Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)&lt;BR /&gt;Event time: Mon Jan 16 11:25:28 2023&lt;/P&gt;
&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: Interface is down (Cluster Control Protocol packets are not received)&lt;BR /&gt;Event time: Mon Jan 16 11:19:29 2023&lt;/P&gt;
&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 15&lt;BR /&gt;Time of counter reset: Sat Jan 14 10:07:58 2023 (reboot)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob -i list&lt;/P&gt;
&lt;P&gt;Built-in Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem&lt;/P&gt;
&lt;P&gt;Registered Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 2882.3 sec&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob syncstat&lt;/P&gt;
&lt;P&gt;Delta Sync Statistics&lt;/P&gt;
&lt;P&gt;Sync status: OK&lt;/P&gt;
&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;
&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;
&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 666662&lt;BR /&gt;Sent retransmission requests................. 0&lt;BR /&gt;Sent retransmission updates.................. 0&lt;BR /&gt;Peak fragments per update.................... 2&lt;/P&gt;
&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 84545&lt;BR /&gt;Received retransmission requests............. 0&lt;/P&gt;
&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... Sync&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 10400 [Bps]&lt;BR /&gt;Peak rate.................................... 10400 [Bps]&lt;BR /&gt;Link usage................................... 0%&lt;BR /&gt;Total........................................ 1745 [MB]&lt;/P&gt;
&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;
&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;
&lt;P&gt;Reset on Sat Jan 14 15:48:22 2023 (triggered by fullsync).&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob -a if&lt;/P&gt;
&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;
&lt;P&gt;eth1 UP&lt;BR /&gt;Sync (S) UP&lt;BR /&gt;Mgmt Non-Monitored&lt;BR /&gt;eth6.30 (P) DOWN (2262.7 secs)&lt;/P&gt;
&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;
&lt;P&gt;Virtual cluster interfaces: 2&lt;/P&gt;
&lt;P&gt;eth1 X.X.X.X&lt;BR /&gt;eth6.30 10.54.1.1&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]#&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2023 18:15:21 GMT</pubDate>
    <dc:creator>nflnetwork29</dc:creator>
    <dc:date>2023-01-16T18:15:21Z</dc:date>
    <item>
      <title>how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167957#M30350</link>
      <description>&lt;P&gt;I have 2 checkpoint 6200's (CLuster XL) and 1 HPE 5710 switch (stacked)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am connecting cp1-eth6 to switch 1 and cp2-eth6 to switch 2.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do i configure my switch ports?&lt;/P&gt;
&lt;P&gt;when i run cphaprob stat it shows that one of my interfaces is down&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do we have any sample configuration i can reference?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as the HP switch is my route to LAN i would like these to be trunk ports. I have created SVI on checkpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any help is appreciated.,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 17:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167957#M30350</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-01-16T17:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167959#M30351</link>
      <description>&lt;P&gt;Not sure if below may apply to you, as its not HPE switch, but rather Cisco:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44898" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44898&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;By the way, which interface shows as down? Can you send output of below commands please?&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -i list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:03:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167959#M30351</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-16T18:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167960#M30352</link>
      <description>&lt;P&gt;[Expert@xyz-cp01:0]# cphaprob roles&lt;/P&gt;
&lt;P&gt;ID Role&lt;/P&gt;
&lt;P&gt;1 (local) Non-Master&lt;BR /&gt;2 Master&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob state&lt;/P&gt;
&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;
&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;
&lt;P&gt;1 (local) 10.222.222.1 0% DOWN xyz-cp01&lt;BR /&gt;2 10.222.222.2 100% ACTIVE xyz-cp02&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: LPRB, IAC&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-110800&lt;BR /&gt;State change: STANDBY -&amp;gt; DOWN&lt;BR /&gt;Reason for state change: Incorrect configuration - Local cluster member has fewer cluster interfaces configured compared to other cluster member(s)&lt;BR /&gt;Event time: Mon Jan 16 11:25:28 2023&lt;/P&gt;
&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: Interface is down (Cluster Control Protocol packets are not received)&lt;BR /&gt;Event time: Mon Jan 16 11:19:29 2023&lt;/P&gt;
&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 15&lt;BR /&gt;Time of counter reset: Sat Jan 14 10:07:58 2023 (reboot)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob -i list&lt;/P&gt;
&lt;P&gt;Built-in Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Interface Active Check&lt;BR /&gt;Current state: problem&lt;/P&gt;
&lt;P&gt;Registered Devices:&lt;/P&gt;
&lt;P&gt;Device Name: Local Probing&lt;BR /&gt;Registration number: 8&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 2882.3 sec&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob syncstat&lt;/P&gt;
&lt;P&gt;Delta Sync Statistics&lt;/P&gt;
&lt;P&gt;Sync status: OK&lt;/P&gt;
&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;
&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;
&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 666662&lt;BR /&gt;Sent retransmission requests................. 0&lt;BR /&gt;Sent retransmission updates.................. 0&lt;BR /&gt;Peak fragments per update.................... 2&lt;/P&gt;
&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 84545&lt;BR /&gt;Received retransmission requests............. 0&lt;/P&gt;
&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... Sync&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 10400 [Bps]&lt;BR /&gt;Peak rate.................................... 10400 [Bps]&lt;BR /&gt;Link usage................................... 0%&lt;BR /&gt;Total........................................ 1745 [MB]&lt;/P&gt;
&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;
&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;
&lt;P&gt;Reset on Sat Jan 14 15:48:22 2023 (triggered by fullsync).&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]# cphaprob -a if&lt;/P&gt;
&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;
&lt;P&gt;eth1 UP&lt;BR /&gt;Sync (S) UP&lt;BR /&gt;Mgmt Non-Monitored&lt;BR /&gt;eth6.30 (P) DOWN (2262.7 secs)&lt;/P&gt;
&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;
&lt;P&gt;Virtual cluster interfaces: 2&lt;/P&gt;
&lt;P&gt;eth1 X.X.X.X&lt;BR /&gt;eth6.30 10.54.1.1&lt;/P&gt;
&lt;P&gt;[Expert@xyz-cp01:0]#&lt;BR /&gt;[Expert@xyz-cp01:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167960#M30352</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-01-16T18:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167961#M30353</link>
      <description>&lt;P&gt;so i have 2 ports on my switch -- Do people typically configure these with LACP? How does the switch not detect a loop?&lt;/P&gt;
&lt;P&gt;Does anyone have a sample config? I'm doing active /standby cluster xl if that helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:38:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167961#M30353</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-01-16T18:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167962#M30354</link>
      <description>&lt;P&gt;I have call with customer shortly and they use clusterXL (HA), so will ask the. I assume eth6.30 is whats connected to your switch? Have you tried bouncing the status or tried another cable just to make sure that can be ruled out?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:47:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167962#M30354</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-16T18:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167963#M30355</link>
      <description>&lt;P&gt;By the way, I found an issue another client had back in May 2022 and issue was misconfigured vlan on the switch side. Not implying by any means thats your issue, but might be worth checking.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:49:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167963#M30355</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-16T18:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167964#M30356</link>
      <description>&lt;P&gt;i removed the LACP configuration and it seems to be working now . still curious how the switch knows where to route the traffic. ie. where the VIP is located (checkpoint 1 or 2)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 18:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167964#M30356</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-01-16T18:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167966#M30357</link>
      <description>&lt;P&gt;It would know, because VIP is ALWAYS tied to whichever member is master.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 19:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/167966#M30357</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-16T19:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/168154#M30404</link>
      <description>&lt;P&gt;Check Point ClusterXL clusters are not multi-chassis when it comes to things like bonding etc, so the switch should not use LACP when configuring a single interface on each cluster member. If you were to create an LACP bond on each cluster member, you would then create two corresponding LACP bonds on the switches, not a single one.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switches know which gateway is holding the VIP because the active gateway will be the one that responds to ARP requests from network devices looking for the VIP.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 02:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/168154#M30404</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2023-01-18T02:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: how to configure my switch for cluster xl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/168267#M30438</link>
      <description>&lt;P&gt;thank you - i was using single LACP on my switch - that was my error .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 18:30:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-configure-my-switch-for-cluster-xl/m-p/168267#M30438</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-01-18T18:30:18Z</dc:date>
    </item>
  </channel>
</rss>

