<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to Build a Cluster Interface OSPF in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256758#M50291</link>
    <description>&lt;P&gt;HW&lt;/P&gt;&lt;P&gt;Old: 5600&lt;BR /&gt;New: 9100&lt;/P&gt;</description>
    <pubDate>Mon, 08 Sep 2025 12:46:02 GMT</pubDate>
    <dc:creator>Herr_O</dc:creator>
    <dc:date>2025-09-08T12:46:02Z</dc:date>
    <item>
      <title>Failed to Build a Cluster Interface OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256737#M50286</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@ all,&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I'm having a strange configuration issue during a hardware refresh. When I tried to set up a cluster interface, it was detected twice, namely in the following format: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;eth1.123 VIP:10.20.20.121, Node1:10.20.20.119, &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Node2:noIP&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;eth1.123 VIP:noIP, Node1:noIP , Node2:10.20.20.119&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;So I deleted the second one and corrected the first one to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;eth1.123 VIP:10.20.20.121, Node1:10.20.20.119, Node2:10.20.20.120 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Afterward, the cluster crashed due to ARP problems.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; Upon closer inspection, I discovered that (for some reason) OSPF was installed on the eth1.123 interfaces in the cluster.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Node1:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;add interface eth1 vlan 123&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;set interface eth1.123 state on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set interface eth1.123 ipv4-address 10.20.20.119 mask-length 28&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set ospf instance default&lt;BR /&gt;interface eth1.123 area 0.0.0.51 on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set ospf instance default interface eth1.123 priority 1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set ospf instance default interface eth1.123 authtype cryptographic key 1 algorithm md5 secret .....&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Node2:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;add interface eth1 vlan 123&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set interface eth1.123 state on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set interface eth1.123 ipv4-address 10.20.20.120 mask-length 28&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set ospf instance default interface eth1.123 area 0.0.0.51 on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;set ospf instance default interface&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;eth1.123 priority 1&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;No key&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;OSPF is not configured on the opposite switch!!!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Maybe someone can explain to me&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;-why the configuration didn't cause any problems during operation (I assume the OSPF configuration was added after the cluster was build) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;-eth1.123 was not recognized as a cluster interface. The OSPF configuration shouldn't have affected this?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Thank you very much for your effort,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Herr_O&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 09:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256737#M50286</guid>
      <dc:creator>Herr_O</dc:creator>
      <dc:date>2025-09-08T09:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to Build a Cluster Interface OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256739#M50287</link>
      <description>&lt;P&gt;SW and HW details? What are you replacing? how did you configure the new appliances? Or do you still work with the older appliances?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 09:40:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256739#M50287</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-08T09:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to Build a Cluster Interface OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256752#M50290</link>
      <description>&lt;P&gt;Sorry Val!&amp;nbsp;&lt;BR /&gt;All&amp;nbsp; Devices Work with R81.20 T98. We did a Fallback&amp;nbsp; &amp;amp; had to deconfigure the ospf settings on the old devices also.&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Only afer this&amp;nbsp; did the cluster work again. Unfortunatly then time was running out....&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I suspect that the OSPF settings were implemented on the running system at some point for testing purposes.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The rollback was probably only on the switches, not the checkpoints.&amp;nbsp;&lt;SPAN&gt;But so far no one has been able to deny or confirm this.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;SPAN&gt;Unfortunately, I now have to provide technical evidence to prove my assumption before repeating the change.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 11:51:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256752#M50290</guid>
      <dc:creator>Herr_O</dc:creator>
      <dc:date>2025-09-08T11:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to Build a Cluster Interface OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256758#M50291</link>
      <description>&lt;P&gt;HW&lt;/P&gt;&lt;P&gt;Old: 5600&lt;BR /&gt;New: 9100&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 12:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256758#M50291</guid>
      <dc:creator>Herr_O</dc:creator>
      <dc:date>2025-09-08T12:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to Build a Cluster Interface OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256761#M50292</link>
      <description>&lt;P&gt;So, how did you configure the new appliances? FTW and then copy/paste config from the older ones?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;OSPF does not run on switches; it is for routers, as far as I know, but it does not matter. It might be that someone played with it and broke the config in the process.&lt;BR /&gt;&lt;BR /&gt;I would recommend taking the new appliances in the lab, cable them fully and test before production replacement. And of course, you need to figure out whether you need that OSPF in the first place. Check the dynamic routing status to see if it is talking to external routers, before dismissing it. If not, clean it from the config in the lab, ir even as text, before applying to the new boxes.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 13:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256761#M50292</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-08T13:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to Build a Cluster Interface OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256762#M50293</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hi Val, I'm configuring it using copy/paste.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The switch is a Layer 3 switch with routing functionality.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;My mistake in the description.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I do not have physical access to the machines, but am waiting for lab time to at least be able to recreate the misconfiguration there in order to identify the exact problem more precisely.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 13:43:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-Build-a-Cluster-Interface-OSPF/m-p/256762#M50293</guid>
      <dc:creator>Herr_O</dc:creator>
      <dc:date>2025-09-08T13:43:42Z</dc:date>
    </item>
  </channel>
</rss>

