<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint 6500 channel-group to Cisco Nexus 9Ks VPC in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57637#M4320</link>
    <description>I'd be curious if you ever got a reply to this. We are seeing something similar in another environment</description>
    <pubDate>Sun, 07 Jul 2019 08:16:22 GMT</pubDate>
    <dc:creator>Peter_Lyndley</dc:creator>
    <dc:date>2019-07-07T08:16:22Z</dc:date>
    <item>
      <title>CheckPoint 6500 channel-group to Cisco Nexus 9Ks VPC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/54158#M4105</link>
      <description>&lt;P&gt;&lt;BR /&gt;I have a pair of CheckPoint 6500 appliances, GAIA R80.10. Each appliance is connected to a pair of Cisco Nexus 9k switches using a VPC port-channel. Thus I have a channel-group on each firewall consisting of two slave interfaces with the IP address on the bond interface. I am using 802.3ad (LACP) and jumbo frames (9216).&lt;/P&gt;&lt;P&gt;Essentially, the bond interface is DOWN on the appliances, but UP on the Cisco N9ks.&lt;/P&gt;&lt;P&gt;Cisco:&lt;/P&gt;&lt;P&gt;chw_srvrm_dcswt1# sh vp brief&lt;BR /&gt;Legend:&lt;BR /&gt;(*) - local vPC is down, forwarding via vPC peer-link&lt;/P&gt;&lt;P&gt;vPC domain id : 1&lt;BR /&gt;Peer status : peer adjacency formed ok&lt;BR /&gt;vPC keep-alive status : peer is alive&lt;BR /&gt;Configuration consistency status : success&lt;BR /&gt;Per-vlan consistency status : success&lt;BR /&gt;Type-2 consistency status : success&lt;BR /&gt;vPC role : primary&lt;BR /&gt;Number of vPCs configured : 4&lt;BR /&gt;Peer Gateway : Enabled&lt;BR /&gt;Dual-active excluded VLANs : -&lt;BR /&gt;Graceful Consistency Check : Enabled&lt;BR /&gt;Auto-recovery status : Disabled&lt;BR /&gt;Delay-restore status : Timer is off.(timeout = 30s)&lt;BR /&gt;Delay-restore SVI status : Timer is off.(timeout = 10s)&lt;BR /&gt;Operational Layer3 Peer-router : Enabled&lt;/P&gt;&lt;P&gt;vPC status&lt;BR /&gt;----------------------------------------------------------------------------&lt;BR /&gt;Id Port Status Consistency Reason Active vlans&lt;BR /&gt;-- ------------ ------ ----------- ------ ---------------&lt;BR /&gt;41 Po41 up success success 503&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;chw_srvrm_dcswt1# sh port-channel summ&lt;BR /&gt;Flags: D - Down P - Up in port-channel (members)&lt;BR /&gt;S - Switched R - Routed&lt;BR /&gt;U - Up (port-channel)&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Group Port- Type Protocol Member Ports&lt;BR /&gt;Channel&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;41 Po41(SU) Eth LACP Eth1/17(P)&lt;/P&gt;&lt;P&gt;chw_srvrm_dcswt1# sh run int e1/17&lt;/P&gt;&lt;P&gt;interface Ethernet1/17&lt;BR /&gt;description OOB FW&lt;BR /&gt;switchport access vlan 503&lt;BR /&gt;mtu 9216&lt;BR /&gt;channel-group 41 mode active&lt;/P&gt;&lt;P&gt;chw_srvrm_dcswt1# sh run int port-channel 41&lt;/P&gt;&lt;P&gt;interface port-channel41&lt;BR /&gt;description OOB Port-Channel 41&lt;BR /&gt;switchport access vlan 503&lt;BR /&gt;mtu 9216&lt;BR /&gt;vpc 41&lt;/P&gt;&lt;P&gt;This is the same on both Cisco Nexus 9k switches.&lt;/P&gt;&lt;P&gt;CheckPoint&lt;/P&gt;&lt;P&gt;[Expert@chw_pbx_bbfw1:0]# cat /proc/net/bonding/bond41&lt;BR /&gt;Ethernet Channel Bonding Driver: v3.2.4 (January 28, 2008)&lt;/P&gt;&lt;P&gt;Bonding Mode: IEEE 802.3ad Dynamic link aggregation&lt;BR /&gt;Transmit Hash Policy: layer3+4 (1)&lt;BR /&gt;MII Status: up&lt;BR /&gt;MII Polling Interval (ms): 100&lt;BR /&gt;Up Delay (ms): 200&lt;BR /&gt;Down Delay (ms): 200&lt;/P&gt;&lt;P&gt;802.3ad info&lt;BR /&gt;LACP rate: slow&lt;BR /&gt;Active Aggregator Info:&lt;BR /&gt;Aggregator ID: 2&lt;BR /&gt;Number of ports: 2&lt;BR /&gt;Actor Key: 17&lt;BR /&gt;Partner Key: 32809&lt;BR /&gt;Partner Mac Address: 00:23:04:ee:be:01&lt;/P&gt;&lt;P&gt;Slave Interface: eth1-01&lt;BR /&gt;MII Status: up&lt;BR /&gt;Link Failure Count: 1&lt;BR /&gt;Permanent HW addr: 00:1c:7f:67:2e:5c&lt;BR /&gt;Aggregator ID: 2&lt;/P&gt;&lt;P&gt;Slave Interface: eth1-02&lt;BR /&gt;MII Status: up&lt;BR /&gt;Link Failure Count: 5&lt;BR /&gt;Permanent HW addr: 00:1c:7f:67:2e:5d&lt;BR /&gt;Aggregator ID: 2&lt;/P&gt;&lt;P&gt;[Expert@chw_pbx_bbfw1:0]# cphaconf show_bond bond41&lt;/P&gt;&lt;P&gt;Bond name: bond41&lt;BR /&gt;Bond mode: Load Sharing&lt;BR /&gt;Bond status: DOWN&lt;BR /&gt;Balancing mode: 802.3ad Layer3+4 Load Balancing&lt;BR /&gt;Configured slave interfaces: 2&lt;BR /&gt;In use slave interfaces: 2&lt;BR /&gt;Required slave interfaces: 1&lt;/P&gt;&lt;P&gt;Slave name | Status | Link&lt;BR /&gt;----------------+-----------------+-------&lt;BR /&gt;eth1-01 | Active | Yes&lt;BR /&gt;eth1-02 | Active | Yes&lt;/P&gt;&lt;P&gt;As you can see, the Cisco port-channel is UP,&amp;nbsp; but the CheckPoint bond interface is DOWN.&amp;nbsp; I have tried both the L2 and L3+4 transmit hash policy setting, MTU 1500, and both LACP rate of fast and slow with no difference.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should really be very simple and there should be no reason why this bond interface should be down, but I'm looking for any suggestions on what the problem could be and what I'm missing.&lt;/P&gt;&lt;P&gt;By the way, I do have a ticket open with CheckPoint tech support, but with no solution so far.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Quentin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 23:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/54158#M4105</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2019-05-22T23:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 6500 channel-group to Cisco Nexus 9Ks VPC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57637#M4320</link>
      <description>I'd be curious if you ever got a reply to this. We are seeing something similar in another environment</description>
      <pubDate>Sun, 07 Jul 2019 08:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57637#M4320</guid>
      <dc:creator>Peter_Lyndley</dc:creator>
      <dc:date>2019-07-07T08:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 6500 channel-group to Cisco Nexus 9Ks VPC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57704#M4321</link>
      <description>&lt;P&gt;We had a similar issue after upgrading CP 15600 two member cluster running r77.30 to r80.20&lt;/P&gt;&lt;P&gt;In our case the bond interface was flapping due to CCP packets not being received on the bond interfaces.&lt;/P&gt;&lt;P&gt;The issue could be resolved by changing the cluster from multicast mode to unicast mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was not an option for our three member clusters where multicast was required so, with no resolution to the issue, we elected to break the bond and use a single interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 13:57:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57704#M4321</guid>
      <dc:creator>Matt_Killeen</dc:creator>
      <dc:date>2019-07-08T13:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 6500 channel-group to Cisco Nexus 9Ks VPC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57719#M4322</link>
      <description>&lt;P&gt;Did you see this &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105697&amp;amp;partition=General&amp;amp;product=ClusterXL%22" target="_self"&gt;sk?&lt;/A&gt;&amp;nbsp;Seems like there may be a known Cisco bug.&lt;/P&gt;
&lt;P&gt;It seems the workaround is to change the cluster mode to broadcast.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 16:16:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57719#M4322</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2019-07-08T16:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 6500 channel-group to Cisco Nexus 9Ks VPC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57720#M4323</link>
      <description>&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7436"&gt;@Daniel_Taney&lt;/a&gt; - yes, thanks but seen that one. Unfortunately, we're running Cisco OTV across geographical sites so broadcast mode can't be implemented in our infrastructure.</description>
      <pubDate>Mon, 08 Jul 2019 16:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57720#M4323</guid>
      <dc:creator>Matt_Killeen</dc:creator>
      <dc:date>2019-07-08T16:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 6500 channel-group to Cisco Nexus 9Ks VPC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57776#M4327</link>
      <description>Try to upgrade to R80.20 and set cluster mode to unicast</description>
      <pubDate>Tue, 09 Jul 2019 08:00:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-6500-channel-group-to-Cisco-Nexus-9Ks-VPC/m-p/57776#M4327</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2019-07-09T08:00:48Z</dc:date>
    </item>
  </channel>
</rss>

