<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating interface behind bond in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-interface-behind-bond/m-p/183918#M33747</link>
    <description>&lt;P&gt;ClusterXL requires ALL members to be configured identically to work (including interface configuration).&lt;BR /&gt;This activity inherently breaks that assumption and clustering won't work until the differences are corrected.&lt;BR /&gt;Which means failover won't be possible in the current state.&lt;BR /&gt;Further, I don't see how disabling monitoring on eth1 will help since you'll have the same issue when bond0.xx comes online.&lt;/P&gt;
&lt;P&gt;Bottom line: this activity must be done in a maintenance window.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 18:51:02 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-13T18:51:02Z</dc:date>
    <item>
      <title>Migrating interface behind bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-interface-behind-bond/m-p/183905#M33743</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Although I found lots of posts around same or similar task, but I seem to struggle. I want to migrate one vlan (eth1) behind already existing bond.&lt;/P&gt;
&lt;P&gt;R80.40 ClusterXL active/standby.&lt;/P&gt;
&lt;P&gt;Interfaces:&lt;/P&gt;
&lt;P&gt;eth1&lt;/P&gt;
&lt;P&gt;bond0.10&lt;/P&gt;
&lt;P&gt;bond0.20&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Standby -&amp;nbsp;clusterXL_admin down&lt;/P&gt;
&lt;P&gt;- Standby - remove IP from eth1&lt;/P&gt;
&lt;P&gt;- Standby - add new vlan with IP behind bond (bond0.5)&lt;/P&gt;
&lt;P&gt;- Smartconsole - update cluster object so that new interface is reflected in configuration&lt;/P&gt;
&lt;P&gt;- Smartconsole - Push policy&lt;/P&gt;
&lt;P&gt;- Standby - clusterXL_admin up&amp;nbsp; &amp;nbsp;&amp;lt;&amp;lt;------ keeps down with following error:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;Setting member to normal operation ...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Member current state is DOWN&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Operation failed: member is still down, please run 'show cluster members pnotes problem' in clish or 'cphaprob list' in expert mode for further details&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now the problem seems to be the difference between the number of monitored interfaces.&lt;/P&gt;
&lt;P&gt;Standby tells "Required interfaces 3" and I have following in the list: bond0.10; bond0.20; sync&lt;/P&gt;
&lt;P&gt;Active tells "Required interfaces 4" and I have following in the list: eth1;&amp;nbsp;bond0.10;&amp;nbsp;bond0.20;&amp;nbsp;sync&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I know about&amp;nbsp;sk92826, but this would only affect the number of vlans monitored behind bond.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How do I failover when standby doesn't join the cluster? Is there a way to temporarily disable monitoring for eth1?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 17:31:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-interface-behind-bond/m-p/183905#M33743</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2023-06-13T17:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating interface behind bond</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-interface-behind-bond/m-p/183918#M33747</link>
      <description>&lt;P&gt;ClusterXL requires ALL members to be configured identically to work (including interface configuration).&lt;BR /&gt;This activity inherently breaks that assumption and clustering won't work until the differences are corrected.&lt;BR /&gt;Which means failover won't be possible in the current state.&lt;BR /&gt;Further, I don't see how disabling monitoring on eth1 will help since you'll have the same issue when bond0.xx comes online.&lt;/P&gt;
&lt;P&gt;Bottom line: this activity must be done in a maintenance window.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 18:51:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-interface-behind-bond/m-p/183918#M33747</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-13T18:51:02Z</dc:date>
    </item>
  </channel>
</rss>

