<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VRRP not enabled: R81.20 ClusterXL with VRRP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241119#M46783</link>
    <description>&lt;P&gt;I could be mistaken, but I believe its similar to VIP in clusterXL.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2025 12:30:31 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-02-13T12:30:31Z</dc:date>
    <item>
      <title>VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241019#M46755</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to test ClusterXL with VRRP as High Availability method.&lt;/P&gt;&lt;P&gt;I read some documents which says all I have to do in order to set it up is just to make ClusterXL cluster in a normal way, except for High Availability mode; VRRP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already had one of cluster with ClusterXL in my lab, so I changed HA mode into VRRP just after I configured Advanced VRRP in GAiA Portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my coworkers told me that I can make sure HA mode by looking at the output of "cphaprob state".&lt;/P&gt;&lt;P&gt;I can clearly confirm the output changes before and after the configuration above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yet, #show vrrp returns me "VRRP not enabled".&lt;/P&gt;&lt;P&gt;Is this expected output in this occasion?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both GW are managed by one SMS.&lt;/P&gt;&lt;P&gt;R81.20 without any JHF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did the following, which I believe it is how you configure VRRP in GAiA Portal:&lt;/P&gt;&lt;P&gt;1. In Advanced VRRP section, check Monitor Firewall State&lt;/P&gt;&lt;P&gt;2. Add Virtual Routers as follows&lt;/P&gt;&lt;P&gt;VRID: 1&amp;nbsp; Interface: eth0&amp;nbsp; VRRP Mode: VRRP&amp;nbsp; Priority: 100&amp;nbsp; Hello Interval: 1&amp;nbsp; Preempt:&amp;nbsp; Yes&lt;/P&gt;&lt;P&gt;Auto-deactivation: No&amp;nbsp; Backup Addresses: None&amp;nbsp; Monitored Interfaces:&amp;nbsp; eth1 (delta: 10)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Priority of vRouter in standby VM is set to 99.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any comments would be more than welcome!&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 12:22:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241019#M46755</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-02-12T12:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241059#M46762</link>
      <description>&lt;P&gt;What steps you have followed?&lt;/P&gt;
&lt;P&gt;This one?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk92061" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk92061&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And why VRRP if I may ask? See for limitations&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105170" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105170&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;All clusters I manage are ClusterXL and soon will be ElasticXL&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 20:04:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241059#M46762</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-12T20:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241061#M46763</link>
      <description>&lt;P&gt;Im with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;on this one, those SKs are definitely relevantt in your case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 20:41:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241061#M46763</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-12T20:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241092#M46779</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;&lt;P&gt;I followed the steps below.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/VRRP-Advanced.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/VRRP-Advanced.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing, I did not add backup address because I thought this is optional.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to try ClusterXL over VRRP. That is why.&lt;/P&gt;&lt;P&gt;Yet, I still have confusing idea on this.&lt;/P&gt;&lt;P&gt;I thought they are the methods for making network redundant, one is universal and the other CP-exclusive, and&lt;/P&gt;&lt;P&gt;do not understand why you want to use them both...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 05:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241092#M46779</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-02-13T05:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241093#M46780</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciated for your comment.&lt;/P&gt;&lt;P&gt;I thought I configured VRRP rightly, judging from the fact below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When only ClusterXL enabled, #cphaprob state&amp;nbsp; returns the following.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cluster Mode: New High Availability (Primary Up)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;with IGMP Membership&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Unique Address&amp;nbsp;&amp;nbsp;Assigned Load&amp;nbsp;&amp;nbsp;&amp;nbsp;State&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1 (local)&amp;nbsp;&amp;nbsp;192.168.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;100%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Active&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;192.168.0.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Standby&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then I changed HA mode to VRRP with Advanced VRRP settings done in GAiA Portal, the output changes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cluster Mode: Sync only (OPSEC) with IGMP Membership&lt;BR /&gt;&lt;BR /&gt;Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Unique Address&amp;nbsp;&amp;nbsp;Firewall State (*)&lt;BR /&gt;&lt;BR /&gt;1 (local)&amp;nbsp;&amp;nbsp;192.168.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Active&lt;BR /&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;192.168.0.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Active&lt;BR /&gt;&lt;BR /&gt;(*) FW-1 monitors only the sync operation and the security policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Use OPSEC's monitoring tool to get the cluster status&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Considering the outputs, I thought it is safe to say VRRP is enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However #show vrrp says VRRP not enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not very persuasive...&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 06:22:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241093#M46780</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-02-13T06:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241095#M46781</link>
      <description>&lt;P&gt;I took routed trace on questioning cluster, and then I noticed they actually were communicating with each other, yet some necessary config might be missing.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 850px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29600iA42AF185177342F3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 06:30:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241095#M46781</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-02-13T06:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241097#M46782</link>
      <description>&lt;P&gt;I solved this by adding backup address as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ClusterXL VIP for eth0: 10.31.10.113&lt;/P&gt;&lt;P&gt;vRouter 1 backup address: 10.31.10.113&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then #show vrrp returns VRRP state!&lt;/P&gt;&lt;P&gt;What is this "backup address" ? no idea what this address is used in VRRP function.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 08:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241097#M46782</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-02-13T08:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP not enabled: R81.20 ClusterXL with VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241119#M46783</link>
      <description>&lt;P&gt;I could be mistaken, but I believe its similar to VIP in clusterXL.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 12:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-not-enabled-R81-20-ClusterXL-with-VRRP/m-p/241119#M46783</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-13T12:30:31Z</dc:date>
    </item>
  </channel>
</rss>

