<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: loopback interface as Router ID in a Cluster XL configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169528#M30702</link>
    <description>&lt;P&gt;Hello Phoneboy,&lt;/P&gt;
&lt;P&gt;starting from 81.10 it seems that is possible to configure loopback:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117794" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117794&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;that procedure looks very bad to me because of any new "Get interfaces with/without topology" will invalidate/delete the manually added Loopback interface in Cluster object under network management.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i've submitted a feedback to sk.&lt;/P&gt;
&lt;P&gt;any idea on your side?&lt;/P&gt;</description>
    <pubDate>Sun, 29 Jan 2023 16:32:12 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2023-01-29T16:32:12Z</dc:date>
    <item>
      <title>loopback interface as Router ID in a Cluster XL configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/16158#M1184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mates!&lt;/P&gt;&lt;P&gt;CP recommends when configuring OSPF, set a loopback interface different from 127.0.0.1 ... If we have a ClusterXL, we can set the same @ip in a new loopback interface on both firewalls and set this ip as Router ID or we must maintain the default configuration? Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2018 19:22:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/16158#M1184</guid>
      <dc:creator>Jose_Luis_Calle</dc:creator>
      <dc:date>2018-11-13T19:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: loopback interface as Router ID in a Cluster XL configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/16159#M1185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Router ID should be configured to one of the cluster IP addresses.&lt;/P&gt;&lt;P&gt;It should be configured this way on all cluster members.&lt;/P&gt;&lt;P&gt;This is explicitly stated here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95968" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95968"&gt;OSPF on Gaia&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 19:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/16159#M1185</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-16T19:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: loopback interface as Router ID in a Cluster XL configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169528#M30702</link>
      <description>&lt;P&gt;Hello Phoneboy,&lt;/P&gt;
&lt;P&gt;starting from 81.10 it seems that is possible to configure loopback:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117794" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117794&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;that procedure looks very bad to me because of any new "Get interfaces with/without topology" will invalidate/delete the manually added Loopback interface in Cluster object under network management.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i've submitted a feedback to sk.&lt;/P&gt;
&lt;P&gt;any idea on your side?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 16:32:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169528#M30702</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-01-29T16:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: loopback interface as Router ID in a Cluster XL configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169535#M30705</link>
      <description>&lt;P&gt;Why would you make a loopback for this? The router ID is not an IP address. It's just a number. All members of a cluster must use the same number, but it doesn't need to have any relation to any interface. You can use router IDs like 0.0.0.1 which are not valid IP addresses.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 21:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169535#M30705</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-01-29T21:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: loopback interface as Router ID in a Cluster XL configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169537#M30707</link>
      <description>&lt;P&gt;I agree with you but i've simply followed admin guide....&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/OSPF-Configuring-Router-ID.htm?Highlight=Router%20id" target="_blank" rel="noopener noreferrer"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminG...&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Use an address on a loopback interface that is not the loopback IPv4 address 127.0.0.1&lt;/P&gt;
&lt;P&gt;Important:&lt;/P&gt;
&lt;P&gt;In a cluster, you must configure the Router ID to one of the Cluster Virtual IP addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So where is the truth?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;but it doesn't need to have any relation to any interface."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This statement seems to be very far compared to documentation/admin guide/SKs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 22:28:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169537#M30707</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-01-29T22:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: loopback interface as Router ID in a Cluster XL configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169547#M30715</link>
      <description>&lt;P&gt;I have customers that do each method successfully (Loopbacks or bonds - not VSX).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Traditional network folk like Loopbacks because they should never go down, historically differing vendor implementations could do odd things when ID values are tied to physical interfaces so habits were formed to avoid gotchas.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 01:29:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/loopback-interface-as-Router-ID-in-a-Cluster-XL-configuration/m-p/169547#M30715</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-13T01:29:15Z</dc:date>
    </item>
  </channel>
</rss>

