<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove bond interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182023#M33341</link>
    <description>&lt;P&gt;If someone in the TAC suggested that order to me, I would request the call be transferred to somebody else.&lt;/P&gt;
&lt;P&gt;When adding an interface, you must add at the OS level first, then the application level.&lt;/P&gt;
&lt;P&gt;When removing an interface, you should tell the application to stop using the interface before you tell the OS to stop providing the interface to be used. While in most circumstances you&amp;nbsp;&lt;STRONG&gt;can&lt;/STRONG&gt; do it in the other order (remove from OS first, remove from application second), that leaves the application trying to use something which doesn't exist. The best case situation for that is cluster failovers when a monitored interface goes down. It could easily result in flapping or a hard outage if combined with other interface problems or cluster monitoring problems.&lt;/P&gt;
&lt;P&gt;It's like using a cable for cluster sync: technically supported, but a bad idea which &lt;STRONG&gt;will&lt;/STRONG&gt; cause problems sooner or later.&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 20:40:41 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2023-05-24T20:40:41Z</dc:date>
    <item>
      <title>Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181971#M33316</link>
      <description>&lt;P&gt;What precautions need to take before removing bond interface?&lt;/P&gt;&lt;P&gt;Remove bond interface from gateway and remove it from management server?&lt;/P&gt;&lt;P&gt;need to install the policy.&lt;/P&gt;&lt;P&gt;Any other steps need to take care?&lt;/P&gt;&lt;P&gt;Please suggest&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 16:39:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181971#M33316</guid>
      <dc:creator>Pradeep_Salunke</dc:creator>
      <dc:date>2023-05-24T16:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181973#M33317</link>
      <description>&lt;P&gt;Regardless of which interface, steps to take are:&lt;/P&gt;
&lt;P&gt;1) Remove from OS level (web UI or clish)&lt;/P&gt;
&lt;P&gt;2) Update topology in smart console gateway object&lt;/P&gt;
&lt;P&gt;3) Install policy&lt;/P&gt;
&lt;P&gt;4) Verify all still works&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 16:44:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181973#M33317</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-24T16:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181975#M33318</link>
      <description>&lt;P&gt;If we performed the get interface without topology thus affect anything?&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 16:50:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181975#M33318</guid>
      <dc:creator>Pradeep_Salunke</dc:creator>
      <dc:date>2023-05-24T16:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181977#M33319</link>
      <description>&lt;P&gt;Make sure to do get interfaces WITHOUT topology. If you do WITH, it will reset your current settings.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 16:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181977#M33319</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-24T16:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181980#M33321</link>
      <description>&lt;P&gt;Of note: removing the bond from the OS level requires removing the member interfaces from the bond. I would also do that step last. You &lt;EM&gt;really&lt;/EM&gt; should not delete an interface which the firewall software still knows about. It can cause all kinds of weird traffic problems.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Remove interface from topology table in SmartConsole&lt;/LI&gt;
&lt;LI&gt;Push policy&lt;/LI&gt;
&lt;LI&gt;Disable interfaces at the OS level (e.g, shutdown the attached switch ports)&lt;/LI&gt;
&lt;LI&gt;Test&lt;/LI&gt;
&lt;LI&gt;If everything tests good, remove the bond's member interfaces, then delete the bond&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 24 May 2023 17:17:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181980#M33321</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-05-24T17:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181981#M33322</link>
      <description>&lt;P&gt;Thats true, good point, it does require removing member interfaces, thank you for pointing that out. But, even TAC would suggest to remove it from OS level first, then topology...at least thats how they always did it in the past.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 17:26:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/181981#M33322</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-24T17:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182023#M33341</link>
      <description>&lt;P&gt;If someone in the TAC suggested that order to me, I would request the call be transferred to somebody else.&lt;/P&gt;
&lt;P&gt;When adding an interface, you must add at the OS level first, then the application level.&lt;/P&gt;
&lt;P&gt;When removing an interface, you should tell the application to stop using the interface before you tell the OS to stop providing the interface to be used. While in most circumstances you&amp;nbsp;&lt;STRONG&gt;can&lt;/STRONG&gt; do it in the other order (remove from OS first, remove from application second), that leaves the application trying to use something which doesn't exist. The best case situation for that is cluster failovers when a monitored interface goes down. It could easily result in flapping or a hard outage if combined with other interface problems or cluster monitoring problems.&lt;/P&gt;
&lt;P&gt;It's like using a cable for cluster sync: technically supported, but a bad idea which &lt;STRONG&gt;will&lt;/STRONG&gt; cause problems sooner or later.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 20:40:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182023#M33341</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-05-24T20:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182028#M33343</link>
      <description>&lt;P&gt;Respectfully, I would disagree. I had done it the way TAC suggested many times before and never had a problem. If you think about it, all smart console would do is really get information based on whats configured on OS level, so to me, makes total sense to do it same way when adding OR removing the interface.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 21:24:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182028#M33343</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-24T21:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182134#M33372</link>
      <description>&lt;P&gt;Think about it with VSX. If you remove the bond from the OS level first, then you try to remove it from your VSX object, provisioning will fail.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 14:46:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182134#M33372</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-05-25T14:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182135#M33373</link>
      <description>&lt;P&gt;Im sure you know VSX way better than I do, so Im positive thats correct. As far as regular gateways, I always done it how TAC suggests and never had a problem.&lt;/P&gt;
&lt;P&gt;Just my experience...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 14:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182135#M33373</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-25T14:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182152#M33382</link>
      <description>&lt;P&gt;I have removed the bond interface and performed the fetch without topology. after activity i can seen that topology is undefined.&lt;/P&gt;&lt;P&gt;So we need to manually edit the same. I have took screenshot before activity.?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 16:37:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182152#M33382</guid>
      <dc:creator>Pradeep_Salunke</dc:creator>
      <dc:date>2023-05-25T16:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182154#M33383</link>
      <description>&lt;P&gt;Yes, please send a screenshot indicating the settings.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 16:38:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182154#M33383</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-25T16:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182156#M33385</link>
      <description>&lt;P&gt;i don't have individual setting i.e. what is anti-spoofing settings.&lt;/P&gt;&lt;P&gt;Sorry to say that is not bond interface, that is VLAN interface under that bond 2.&lt;/P&gt;&lt;P&gt;I have removed the vlan interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 16:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182156#M33385</guid>
      <dc:creator>Pradeep_Salunke</dc:creator>
      <dc:date>2023-05-25T16:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remove bond interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182160#M33386</link>
      <description>&lt;P&gt;As long as interface is not part of OS, then topology should reflect that, for sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 16:49:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-bond-interface/m-p/182160#M33386</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-25T16:49:04Z</dc:date>
    </item>
  </channel>
</rss>

