<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sync Redundancy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187890#M34641</link>
    <description>&lt;OL&gt;
&lt;LI&gt;Create the bond at the OS level with only the second interface in it. Use a different network from your current sync network.&lt;/LI&gt;
&lt;LI&gt;Change the cluster object's configuration on the management server to use the bond for sync. Remove the old sync interface from the cluster object's topology table.&lt;/LI&gt;
&lt;LI&gt;Push policy.&lt;/LI&gt;
&lt;LI&gt;Remove the IP from your old sync interface at the OS level.&lt;/LI&gt;
&lt;LI&gt;Add the old sync interface to the bond.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This process should not cause a failover, as you have working sync at all times. Still, assume there will be an outage at some point.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 15:00:07 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2023-07-27T15:00:07Z</dc:date>
    <item>
      <title>Sync Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187777#M34619</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I have two Gaia fw in one&amp;nbsp;Cluster （HA model），one&amp;nbsp;cable between the two firewalls for synchronization。&lt;/P&gt;&lt;P&gt;Now I need to redundant the sync network，so i added one more cable to make a bond interface，When doing bond, I need to delete the IP address of the&amp;nbsp; interface that i was using to&amp;nbsp; sync.i think that will&amp;nbsp;occurs cluster failover .&lt;/P&gt;&lt;P&gt;so my question is the configuring a bond Interface&amp;nbsp;will cause problems ?cluster failover or access .....&lt;/P&gt;&lt;P&gt;After deleting the IP address, it seems that the policy installation&amp;nbsp;button turns gray and cannot be used&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 02:23:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187777#M34619</guid>
      <dc:creator>lol2</dc:creator>
      <dc:date>2023-07-27T02:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187835#M34635</link>
      <description>&lt;P&gt;Any changes to interfaces in a ClusterXL cluster should be made in a maintenance window since it can affect production traffic.&lt;BR /&gt;I believe you should make the underlying changes in the OS before attempting changes in SmartConsole.&lt;BR /&gt;Also, there’s a note here about adding the slave interfaces for the bond in the same order on both members:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk92804" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk92804&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:21:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187835#M34635</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-27T12:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187860#M34640</link>
      <description>&lt;P&gt;If you are adding/removing interfaces in ClusterXL, the way to avoid a spurious failover due to interface "failure" is to &lt;STRONG&gt;cphastop&lt;/STRONG&gt; the standby, complete all your changes on both cluster members and the SmartConsole, install policy to both members, then &lt;STRONG&gt;cphastart&lt;/STRONG&gt; the standby.&amp;nbsp; See this rather old SK for the detailed failover-free procedure:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk57100" target="_blank" rel="noopener"&gt;sk57100:&amp;nbsp;Adding&amp;nbsp;or removing an&amp;nbsp;interface&amp;nbsp;in&amp;nbsp;ClusterXL&amp;nbsp;High Availability topology might cause fail-over&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Since you will be modifying the sync interface, as an additional precaution you may want to uncheck "drop of out state TCP" in the Global Properties ahead of time and reinstall policy, on the off-chance an unexpected failover occurs when state sync is not working.&amp;nbsp; Having this box unchecked will blunt the unwanted effects of a non-stateful failover; just don't forget to recheck it when the work is complete and tested!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:01:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187860#M34640</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-27T13:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187890#M34641</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Create the bond at the OS level with only the second interface in it. Use a different network from your current sync network.&lt;/LI&gt;
&lt;LI&gt;Change the cluster object's configuration on the management server to use the bond for sync. Remove the old sync interface from the cluster object's topology table.&lt;/LI&gt;
&lt;LI&gt;Push policy.&lt;/LI&gt;
&lt;LI&gt;Remove the IP from your old sync interface at the OS level.&lt;/LI&gt;
&lt;LI&gt;Add the old sync interface to the bond.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This process should not cause a failover, as you have working sync at all times. Still, assume there will be an outage at some point.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 15:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187890#M34641</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-07-27T15:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sync Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187907#M34646</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Sync-Redundancy.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Sync-Redundancy.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 18:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sync-Redundancy/m-p/187907#M34646</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-27T18:11:24Z</dc:date>
    </item>
  </channel>
</rss>

