<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX and Bond interfaces going down after few hours in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241007#M46750</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2401"&gt;@Dilian_Chernev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intersting, strange behaviour&lt;/P&gt;
&lt;P&gt;@churned:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk169760" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk169760&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;One of the peer's LACP (etherchannel) interfaces is suspended or is otherwise no longer active as an LACP interface.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;@Cisco side bond:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The bond ID is the same on the newly generated LACP and the existig one? Is there anything common on the existing switch config and the&amp;nbsp; new one?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2025 10:50:10 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-02-12T10:50:10Z</dc:date>
    <item>
      <title>VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241002#M46747</link>
      <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;I am fighting whit very strange issue -&amp;nbsp;Bond interfaces going down after few hours after reconfiguring interfaces on virtual machines.&lt;/P&gt;&lt;P&gt;There is a cluster of two 19200 (R81.20 JHF92) hosts in VSLS with bond interfaces to Cisco switches with LACP and VPC.&lt;BR /&gt;After configuring two VSs - configured interfaces, vlans, routes, blank policy with any-any-allow, everything is fine.&lt;BR /&gt;The only thing is that no vlan's are configured on the switches, becaus these VSs are prepared to replace existing plain devices that have same IPs. So to make sure everything is ok till the date of migration, there is no trafic on interfaces of VSs.&lt;/P&gt;&lt;P&gt;So after 4-6 hours, most of the bonds became down, Cisco switches are saying that ports are disabled and there is no way to bring them back up.&amp;nbsp;&lt;BR /&gt;On CP side, bonds are with different Aggregator IDs and interface are "churned" and the only way to bring them up is to reboot appliances.&lt;/P&gt;&lt;P&gt;This happens 3 times till now, every time several hours after reconfiguring interfaces of VSs.&lt;/P&gt;&lt;P&gt;Opened a ticket after first time, but nothing usefull came out - only&amp;nbsp;&lt;SPAN&gt;sk115516, but this not helping to prevent from happeing again.&lt;BR /&gt;There is nothing usefull in /var/log/messages&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does any one have simillar problems?&lt;BR /&gt;Any idea which log files to check or what debugs could be run? I am pretty sure this can reproduced.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dilian&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 09:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241002#M46747</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2025-02-12T09:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241007#M46750</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2401"&gt;@Dilian_Chernev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intersting, strange behaviour&lt;/P&gt;
&lt;P&gt;@churned:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk169760" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk169760&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;One of the peer's LACP (etherchannel) interfaces is suspended or is otherwise no longer active as an LACP interface.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;@Cisco side bond:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The bond ID is the same on the newly generated LACP and the existig one? Is there anything common on the existing switch config and the&amp;nbsp; new one?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 10:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241007#M46750</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-02-12T10:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241013#M46751</link>
      <description>&lt;UL&gt;
&lt;LI&gt;Is this a new bond implementation on your 19200?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Were the bonds ever stable?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;What is the interface speed and driver type of the physical interfaces (&lt;STRONG&gt;ethtool -i ethXX&lt;/STRONG&gt;).&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This issue sounds somewhat similar to a supposedly-fixed limitation of Lightspeed cards:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Bond may become unstable because of LACP packet losses (on the network or in the interface).&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Configure the LACP "&lt;CODE&gt;slow&lt;/CODE&gt;" rate for this Bond on each side&lt;/P&gt;
&lt;P&gt;Because you are on an Quantum Force appliance it will utilize UPPAK by default just like a Lightspeed appliance, so the above may apply to you.&amp;nbsp; If both sides set to slow rate doesn't help, the last thing to try would be to disable UPPAK via cpconfig to go back to KPPAK and see if that impacts the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 12:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241013#M46751</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-02-12T12:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241027#M46756</link>
      <description>&lt;P&gt;It is a new bond implementation, but it is configured almost 4 months ago.&lt;BR /&gt;It's stable, except these 3 moments when VSs interfaces changes was made.&lt;/P&gt;&lt;P&gt;Here is ethtool info, it is identical on all involved interfaces (10Gb SFP+)&lt;/P&gt;&lt;P&gt;[Expert@fw2:0]# ethtool -i eth1-04&lt;BR /&gt;driver: net_ice&lt;BR /&gt;version: DPDK 20.11.7.4.0 (29 Mar 24)&lt;BR /&gt;firmware-version: 4.20 0x800178e2 1.3346.0&lt;BR /&gt;expansion-rom-version:&lt;BR /&gt;bus-info: 0000:17:00.7&lt;BR /&gt;supports-statistics: yes&lt;BR /&gt;supports-test: no&lt;BR /&gt;supports-eeprom-access: no&lt;BR /&gt;supports-register-dump: no&lt;BR /&gt;supports-priv-flags: yes&lt;/P&gt;&lt;P&gt;From both sides lacp rate is slow/normal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw2:0&amp;gt; show bonding group 4&lt;BR /&gt;Bond Configuration&lt;BR /&gt;xmit-hash-policy layer2&lt;BR /&gt;down-delay 200&lt;BR /&gt;primary Not configured&lt;BR /&gt;lacp-rate slow&lt;BR /&gt;mode 8023AD&lt;BR /&gt;up-delay 200&lt;BR /&gt;mii-interval 100&lt;BR /&gt;min-links 0&lt;BR /&gt;Bond Interfaces&lt;BR /&gt;eth1-04&lt;BR /&gt;eth3-04&lt;/P&gt;&lt;P&gt;#### edit&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is something that just remember - bond in CP device is created with one port from&amp;nbsp;Line card 1 model: CPAC-8-1/10F-D and second port from: Line card 3 model: CPAC-4-10/25F-D&lt;BR /&gt;There is difference in firmware, but driver is the same:&lt;/P&gt;&lt;P&gt;[Expert@fw2:0]# ethtool -i eth1-03&lt;BR /&gt;driver: net_ice&lt;BR /&gt;version: DPDK 20.11.7.4.0 (29 Mar 24)&lt;BR /&gt;firmware-version: 4.20 0x800178e2 1.3346.0&lt;BR /&gt;expansion-rom-version:&lt;BR /&gt;bus-info: 0000:17:00.5&lt;BR /&gt;supports-statistics: yes&lt;BR /&gt;supports-test: no&lt;BR /&gt;supports-eeprom-access: no&lt;BR /&gt;supports-register-dump: no&lt;BR /&gt;supports-priv-flags: yes&lt;/P&gt;&lt;P&gt;[Expert@fw2:0]# ethtool -i eth3-04&lt;BR /&gt;driver: net_ice&lt;BR /&gt;version: DPDK 20.11.7.4.0 (29 Mar 24)&lt;BR /&gt;firmware-version: 4.30 0x8001b94f 1.3415.0&lt;BR /&gt;expansion-rom-version:&lt;BR /&gt;bus-info: 0000:b1:00.2&lt;BR /&gt;supports-statistics: yes&lt;BR /&gt;supports-test: no&lt;BR /&gt;supports-eeprom-access: no&lt;BR /&gt;supports-register-dump: no&lt;BR /&gt;supports-priv-flags: yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 14:04:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241027#M46756</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2025-02-12T14:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241028#M46757</link>
      <description>&lt;P&gt;Not sure how to respond on this &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; but after restarting appliances everything works fine.&lt;BR /&gt;Tomorrow will try to edit VS config to see if the issue will happen again.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 13:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241028#M46757</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2025-02-12T13:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241038#M46759</link>
      <description>&lt;P&gt;If it happens again I'd suggest disabling UPPAK from &lt;STRONG&gt;cpconfig&lt;/STRONG&gt; to see if it affects the issue.&amp;nbsp; UPPAK has its tendrils sunk pretty deeply into the network drivers via DPDK, and it being the cause of your bond issue is not outside the realm of possibility.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 14:29:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241038#M46759</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-02-12T14:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241042#M46761</link>
      <description>&lt;P&gt;Check the (very long) output of &lt;FONT face="andale mono,times"&gt;cat /proc/net/bonding/&amp;lt;bond name&amp;gt;&lt;/FONT&gt; &amp;nbsp;before and after the event occurs, in the section "&lt;SPAN&gt;&lt;FONT face="andale mono,times"&gt;details partner lacp pdu&lt;/FONT&gt;", in both sections for each interface, to see if the remote side changes its LACP information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;You mentioned the interface being "churned", so you likely already saw this, tho.&lt;/P&gt;
&lt;P&gt;On the Cisco side, if this is Nexus VPC, then check the status of the etherchannel to see if it has suspended the port-channel member interface. &amp;nbsp;You can run a "debug port-channel error" or "debug port-channel trace" to hopefully catch any switch-side errors.&lt;/P&gt;
&lt;P&gt;On IOS-XE, it's "debug etherchannel ..." for similar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 14:45:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/241042#M46761</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-02-12T14:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/243153#M47228</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;After disabling the UPPAK the issue is not happing again.&lt;/P&gt;&lt;P&gt;We have an open ticket with TAC and R&amp;amp;D involved to figured out what was the root cause for the problem.&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 09:29:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/243153#M47228</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2025-03-06T09:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: VSX and Bond interfaces going down after few hours</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/243162#M47231</link>
      <description>&lt;P&gt;Interesting that UPPAK was the cause, thanks for the follow-up.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 12:30:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-and-Bond-interfaces-going-down-after-few-hours/m-p/243162#M47231</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-06T12:30:36Z</dc:date>
    </item>
  </channel>
</rss>

