<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with 9100 clusterXL with bond interface enabled in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265041#M52154</link>
    <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Greetings to beautiful Colombia! Hey, I dont believe we sadly have access to it, but my colleague may ask customers for the access. Do you recall what could have been an issue?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Dec 2025 21:48:26 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-12-10T21:48:26Z</dc:date>
    <item>
      <title>Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265008#M52143</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just wanted to run this by the team to see if anyone may have an idea/suggestion. Essentially, my colleague and I were helping client with cutover from Fortinet to new CP 9100 appliances and all was going well, until we enabled bond interface on both members. It all came up fine, but then we noticed clustering was broken and no matter what we tried, we could not get it to work.&lt;/P&gt;
&lt;P&gt;Since we were unable to get TAC on the phone, we tried bunch of things ourselves, such as changing bond type on the interface to active-backup and round robin and though round robin did work for cluster, bonded vlans were still showing as down.&lt;/P&gt;
&lt;P&gt;Since we had to roll back eventually, now we want to try figure out in the lab why this failed. Swithes are Aruba and all the config we verified seems correct. Just wondering if someone may had this problem before and if so, how did you solve it?&lt;/P&gt;
&lt;P&gt;We tried cphastop; cphastart, disable/re-enable cluster, reboot, no luck...bit tricky to tell at this point if this could be CP or Aruba switch issue...&lt;/P&gt;
&lt;P&gt;Below are some screenshots of the config:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32394iABEFE2498C58809A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;DIV id="tinyMceEditorthe_rock_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32395i3E609355A13D41A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Image.png" alt="Image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 2&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;
&lt;P&gt;eth1 UP&lt;BR /&gt;Sync (S) UP&lt;BR /&gt;bond1.154 (LS) DOWN&lt;BR /&gt;bond1.120 (LS) DOWN&lt;BR /&gt;maas_tunnel (P) DOWN (382.7 secs)&lt;/P&gt;
&lt;P&gt;Note: For more information on bond interfaces, use the command:&lt;BR /&gt;cphaprob show_bond [&amp;lt;bond_name&amp;gt;]&lt;/P&gt;
&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32396i0321E35B6B4A7FB1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32397i1C99913AC2E3E09C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_3.png" alt="Screenshot_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32399i64058F8AE8930EEC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tx as always for the help, I really appreciate it!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 15:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265008#M52143</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-10T15:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265037#M52151</link>
      <description>&lt;P&gt;Did you checked your bonding? Maybe your LACP channel is not up. What’s in&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;cat /proc/net/bonding/bondxx&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 20:45:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265037#M52151</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-12-10T20:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265038#M52152</link>
      <description>&lt;P&gt;This is what I see now Wolfgang, but keep in mind, though interface is enabled, there is nothing connected to it atm:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@PER_FW_02:0]# cat /proc/net/bonding/bond1&lt;BR /&gt;Ethernet Channel Bonding Driver: v3.7.1 (April 27, 2011)&lt;/P&gt;
&lt;P&gt;Bonding Mode: IEEE 802.3ad Dynamic link aggregation&lt;BR /&gt;Transmit Hash Policy: layer2 (0)&lt;BR /&gt;Use RxHash: 0&lt;BR /&gt;MII Status: down&lt;BR /&gt;MII Polling Interval (ms): 100&lt;BR /&gt;Up Delay (ms): 200&lt;BR /&gt;Down Delay (ms): 200&lt;/P&gt;
&lt;P&gt;802.3ad info&lt;BR /&gt;LACP rate: slow&lt;BR /&gt;Min links: 0&lt;BR /&gt;Aggregator selection policy (ad_select): stable&lt;BR /&gt;System priority: 65535&lt;BR /&gt;System MAC address: ca:33:60:f9:51:cb&lt;BR /&gt;bond bond1 has no active aggregator&lt;/P&gt;
&lt;P&gt;Slave Interface: eth3&lt;BR /&gt;MII Status: down&lt;BR /&gt;Speed: Unknown&lt;BR /&gt;Duplex: Unknown&lt;BR /&gt;Link Failure Count: 0&lt;BR /&gt;Permanent HW addr: 00:1c:7f:c8:04:0d&lt;BR /&gt;Slave queue ID: 0&lt;BR /&gt;Aggregator ID: 1&lt;BR /&gt;Actor Churn State: churned&lt;BR /&gt;Partner Churn State: churned&lt;BR /&gt;Actor Churned Count: 1&lt;BR /&gt;Partner Churned Count: 1&lt;BR /&gt;details actor lacp pdu:&lt;BR /&gt;system priority: 65535&lt;BR /&gt;system mac address: ca:33:60:f9:51:cb&lt;BR /&gt;port key: 0&lt;BR /&gt;port priority: 255&lt;BR /&gt;port number: 1&lt;BR /&gt;port state: 69&lt;BR /&gt;details partner lacp pdu:&lt;BR /&gt;system priority: 65535&lt;BR /&gt;system mac address: 00:00:00:00:00:00&lt;BR /&gt;oper key: 1&lt;BR /&gt;port priority: 255&lt;BR /&gt;port number: 1&lt;BR /&gt;port state: 1&lt;/P&gt;
&lt;P&gt;Slave Interface: eth4&lt;BR /&gt;MII Status: down&lt;BR /&gt;Speed: Unknown&lt;BR /&gt;Duplex: Unknown&lt;BR /&gt;Link Failure Count: 0&lt;BR /&gt;Permanent HW addr: 00:1c:7f:c8:04:0f&lt;BR /&gt;Slave queue ID: 0&lt;BR /&gt;Aggregator ID: 2&lt;BR /&gt;Actor Churn State: churned&lt;BR /&gt;Partner Churn State: churned&lt;BR /&gt;Actor Churned Count: 1&lt;BR /&gt;Partner Churned Count: 1&lt;BR /&gt;details actor lacp pdu:&lt;BR /&gt;system priority: 65535&lt;BR /&gt;system mac address: ca:33:60:f9:51:cb&lt;BR /&gt;port key: 0&lt;BR /&gt;port priority: 255&lt;BR /&gt;port number: 2&lt;BR /&gt;port state: 69&lt;BR /&gt;details partner lacp pdu:&lt;BR /&gt;system priority: 65535&lt;BR /&gt;system mac address: 00:00:00:00:00:00&lt;BR /&gt;oper key: 1&lt;BR /&gt;port priority: 255&lt;BR /&gt;port number: 1&lt;BR /&gt;port state: 1&lt;BR /&gt;[Expert@PER_FW_02:0]#&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 21:03:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265038#M52152</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-10T21:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265040#M52153</link>
      <description>&lt;P&gt;Hi Andy, regards from Colombia. I hope that perhaps we can talk again at some point. I also wish you an excellent December.&lt;/P&gt;&lt;P&gt;I’ve been analyzing your issue since this morning. If you’d like, could you share the trunk configuration of the Aruba Core 1 and 2? I once had a similar issue about two years ago on a VSX cluster. In this scenario, maybe it has to do with the same root cause. I could add if you want to check the CRCs from the Checkpoint interface side that are part of the port channel &lt;EM&gt;(sar -n EDEV)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;JS&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 21:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265040#M52153</guid>
      <dc:creator>sjni01</dc:creator>
      <dc:date>2025-12-10T21:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265041#M52154</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Greetings to beautiful Colombia! Hey, I dont believe we sadly have access to it, but my colleague may ask customers for the access. Do you recall what could have been an issue?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 21:48:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265041#M52154</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-10T21:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265054#M52157</link>
      <description>&lt;P&gt;What is the "native" (untagged) vlan on the bonds?&lt;/P&gt;
&lt;P&gt;Are the interfaces otherwise cabled properly and each firewall definitely using its own lag as the diagram shows?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 23:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265054#M52157</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-12-10T23:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265055#M52158</link>
      <description>&lt;P&gt;Hey Chris,&lt;/P&gt;
&lt;P&gt;Yes, they were definitely cabled right and as per diagram. Since we could not work with TAC as no one called us back in time, we had to roll back to Fortigates, but will try again in January. VLANs are 120, 140,150,152 and 154. We have guys who are super knowleagable in Aruba switches, so I will work with one of my colleagues Thursdya to see if we can replicate this in the lab with Aruba 4000 switch.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 23:15:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265055#M52158</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-10T23:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265061#M52159</link>
      <description>&lt;P&gt;Review the config in the context of this perhaps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk120684" target="_self"&gt;sk120684&lt;/A&gt;: No connectivity over VLAN interfaces configured on a Bond interface on Check Point Security Gateway&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 23:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265061#M52159</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-12-10T23:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265062#M52160</link>
      <description>&lt;P&gt;Thanks Chris. I will check with my colleague tomorrow when we do remote about this...since I dont have access to the switch and even if I did, truth be told, I would not have a good idea what to even look for, lets see how far we get with the lab testing.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 23:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265062#M52160</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-10T23:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265111#M52190</link>
      <description>&lt;P&gt;Hey Chris,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good morning from Canada : - )&lt;/P&gt;
&lt;P&gt;I will update the thread once we do remote today...lets see if we can figure something out?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 13:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265111#M52190</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-11T13:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265115#M52193</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;The key is here:&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;Actor Churn State: churned&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk169760" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk169760&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I spent a lot of time earier to debug this, and the Cisco ACI side the port was is "suspended" state&lt;/P&gt;
&lt;P&gt;Did you deattached and attached the cable into the port one-by-one?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 15:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265115#M52193</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-12-11T15:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265116#M52194</link>
      <description>&lt;P&gt;Hey Akos,&lt;/P&gt;
&lt;P&gt;Thanks for that, never really noticed. Now, here is my question...yes, we did bounce the ports the other night, but wondering though, is this more of generic thing or just with Cisco switches? Because in client's case, they have Aruba.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 15:32:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265116#M52194</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-11T15:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265119#M52195</link>
      <description>&lt;P&gt;I will mention this to my colleague as well, thanks for bring it up!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 15:38:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265119#M52195</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-11T15:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265121#M52196</link>
      <description>&lt;P&gt;Hi Bro,&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"One of the possible causes for a suspended port channel is the issue outlined in sk115516 with mismatching Aggregator IDs."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Long story short:&amp;nbsp; if you have the bond1 (members: eth1 eth2), unplug them,&amp;nbsp; wait a few second, then plug them back &lt;STRONG&gt;simultaneously&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't think so this relates to only Cisco Devices.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 15:42:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265121#M52196</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-12-11T15:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265122#M52197</link>
      <description>&lt;P&gt;And as I see the IDs are different, which is not a good thing according to the spellbooks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Slave Interface: eth3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;MII Status: down&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Speed: Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Duplex: Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Link Failure Count: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Permanent HW addr: 00:1c:7f:c8:04:0d&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Slave queue ID: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;Aggregator ID: 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;lave Interface: eth4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;MII Status: down&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Speed: Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Duplex: Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Link Failure Count: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Permanent HW addr: 00:1c:7f:c8:04:0f&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Slave queue ID: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;lave Interface: eth4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;MII Status: down&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Speed: Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Duplex: Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Link Failure Count: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Permanent HW addr: 00:1c:7f:c8:04:0f&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Slave queue ID: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;Aggregator ID: 2&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 15:44:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265122#M52197</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-12-11T15:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265123#M52198</link>
      <description>&lt;P&gt;I see what you meanm, BUT...where do you even set that up? because in gaia, you can only give bond group ID, which is number 1 on both cluster members, I dont see this aggregator ID anywhere...is that switch side?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 15:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265123#M52198</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-11T15:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265124#M52199</link>
      <description>&lt;P&gt;Thanks a lot for this man, I truly appreciate it. Lets us check all in few hours and I will update what we discover during the test. Great thing is we actually do have 4 devices we can test in our lab that another client purchased, so since its brand new config, its perfect to validate all this.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 15:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265124#M52199</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-11T15:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265126#M52200</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, the switch side. I am 100% sure the network team will understand this.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 16:00:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265126#M52200</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-12-11T16:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265127#M52201</link>
      <description>&lt;P&gt;K, sounds good.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 16:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265127#M52201</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-11T16:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 9100 clusterXL with bond interface enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265147#M52214</link>
      <description>&lt;P&gt;Hey, Andy mate,&lt;/P&gt;&lt;P&gt;I always remember you, thanks. I love my country. Let me explain in more detail: when we were finally able to check the configurations on the network core appliance from the security team’s side, we found that the bonds were down because the VLANs (dot1q) were not being propagated correctly on the Core Switch. Typically, the same VLANs seen on the Check Point Cluster should also appear on the port-channel or LAG (1 and 2 in this case for the Aruba appliance), but when I encountered the issue, those VLANs were missing on the trunk.&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;JS&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 20:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-9100-clusterXL-with-bond-interface-enabled/m-p/265147#M52214</guid>
      <dc:creator>sjni01</dc:creator>
      <dc:date>2025-12-11T20:28:05Z</dc:date>
    </item>
  </channel>
</rss>

