<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switch configuration for ClusterXL using OSPF in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Switch-configuration-for-ClusterXL-using-OSPF/m-p/249433#M48718</link>
    <description>&lt;P&gt;The network should see the cluster as a single logical router (same router-id).&lt;/P&gt;
&lt;P&gt;Actually the interface active check typically has little to do with routing/ospf more L2 communication e.g. reachability between the cluster members across the intermediate network fabric/vlan(s).&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2025 04:32:14 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-05-21T04:32:14Z</dc:date>
    <item>
      <title>Switch configuration for ClusterXL using OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Switch-configuration-for-ClusterXL-using-OSPF/m-p/249411#M48710</link>
      <description>&lt;P&gt;I have this deployment of 9100 gateways in HA using OSPF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the output of cphaprob is Active Down.&lt;/P&gt;&lt;P&gt;when I checked on the down member for &lt;EM&gt;cphaprob -ia list&lt;/EM&gt;, all the interfaces are down except for sync and mgmt and interface active check is in problem state.&lt;/P&gt;&lt;P&gt;After further troubleshooting, I realised that it's only the active member that has connectivity per time irrespective of which appliance is active.&lt;/P&gt;&lt;P&gt;When I do show route on each member, each of them has thesame dynamic route populated but only the active member is able to reach learned routes&lt;/P&gt;&lt;P&gt;when I do show ospf neighbour on each member, only the active member has neighbors populated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I worked with TAC and the conclusion is to look at the switches and router&lt;/P&gt;&lt;P&gt;how do I advice the network team, to configure the switch and routers to treat the appliances independently.&lt;/P&gt;&lt;P&gt;so that the connected interfaces of the gateways will be up irrespective&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 18:11:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Switch-configuration-for-ClusterXL-using-OSPF/m-p/249411#M48710</guid>
      <dc:creator>Samuel_EKUNDAR1</dc:creator>
      <dc:date>2025-05-20T18:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Switch configuration for ClusterXL using OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Switch-configuration-for-ClusterXL-using-OSPF/m-p/249433#M48718</link>
      <description>&lt;P&gt;The network should see the cluster as a single logical router (same router-id).&lt;/P&gt;
&lt;P&gt;Actually the interface active check typically has little to do with routing/ospf more L2 communication e.g. reachability between the cluster members across the intermediate network fabric/vlan(s).&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 04:32:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Switch-configuration-for-ClusterXL-using-OSPF/m-p/249433#M48718</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-05-21T04:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Switch configuration for ClusterXL using OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Switch-configuration-for-ClusterXL-using-OSPF/m-p/249553#M48742</link>
      <description>&lt;P&gt;Chris is correct - our cluster only peers to/from the active member. The cluster will synchronize the routing table so that it can re-establish peering and not lose connectivity during a failover. The network team should only need the (1) peer configured.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 01:02:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Switch-configuration-for-ClusterXL-using-OSPF/m-p/249553#M48742</guid>
      <dc:creator>Joseph_Audet</dc:creator>
      <dc:date>2025-05-22T01:02:11Z</dc:date>
    </item>
  </channel>
</rss>

