<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5600 SG R80.40 Interface issues? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/90020#M6887</link>
    <description>&lt;P&gt;I swapped the switchports between two 5600s including the cables, so I took validated cables and switchports from the regular 5600 and connect them to my problematic 5600 and the same problem remains, my problematic 5600 has 4 ports working as a 100M/Half and my regular 5600 again has all ports 1000M/Full (except the sync interface between two 5600s).&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jun 2020 07:09:28 GMT</pubDate>
    <dc:creator>MladenAntesevic</dc:creator>
    <dc:date>2020-06-29T07:09:28Z</dc:date>
    <item>
      <title>5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89852#M6872</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Has anyone had issues with interfaces not coming UP as 1000M/Full on 5600 R80.40? &amp;nbsp;I have two 5600 in a cluster with identical topology, both connected to identically configured Cisco Nexus switches, where all the ports from one gateway are normally working as 1000M/Full but several ports from the other are only active as 100M/Half Duplex. If I try to force 1000M/Full, the interfaces will go down. I have such a issue on 5 ports connected to different devices and only two interface from the same SG5600 normally working as 1000M/Full. I have checked the cables and coresponding interfaces on the connected devices and everything is fine, but 5 interfaces on my 5600 are working only as 100M/Half:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;FONT&gt;CP2&amp;gt; show version all&lt;BR /&gt;Product version Check Point Gaia R80.40&lt;BR /&gt;OS build 294&lt;BR /&gt;OS kernel version 3.10.0-957.21.3cpx86_64&lt;BR /&gt;OS edition 64-bit&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;CP2&amp;gt; show interface eth5&lt;BR /&gt;state on&lt;BR /&gt;mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;type ethernet&lt;BR /&gt;link-state link down&lt;BR /&gt;mtu 1500&lt;BR /&gt;auto-negotiation on&lt;BR /&gt;speed N/A&lt;BR /&gt;ipv6-autoconfig Not configured&lt;BR /&gt;duplex N/A&lt;BR /&gt;monitor-mode Not configured&lt;BR /&gt;link-speed Not configured&lt;BR /&gt;comments&lt;BR /&gt;ipv4-address Not Configured&lt;BR /&gt;ipv6-address Not Configured&lt;BR /&gt;ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;TX bytes:0 packets:0 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;RX bytes:0 packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;[Expert@CP2:0]# ethtool -i eth5&lt;BR /&gt;driver: igb&lt;BR /&gt;version: 5.3.5.18&lt;BR /&gt;firmware-version:&amp;nbsp; 0. 6-2&lt;BR /&gt;expansion-rom-version:&lt;BR /&gt;bus-info: 0000:04:00.0&lt;BR /&gt;supports-statistics: yes&lt;BR /&gt;supports-test: yes&lt;BR /&gt;supports-eeprom-access: yes&lt;BR /&gt;supports-register-dump: yes&lt;BR /&gt;supports-priv-flags: no&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;For example, I have eth5 connected to the corresponding switch which does not allow 100M speed so interface is down. Other interfaces (eth1, eth2, eth3, eth4, eth6, eth7) are connected to devices which allow both 100M and 1000M speed and I have mixed result:&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Interface eth1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; state on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type ethernet&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-state link up&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto-negotiation on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; speed 100M&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-autoconfig Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; duplex half&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; monitor-mode Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-speed Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; comments outside&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4-address xx.xx.xx.xx/xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX bytes:35667905 packets:405184 errors:1 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:563116538 packets:457466 errors:0 dropped:0 overruns:0 frame:0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Interface eth2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; state on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type ethernet&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-state link down&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto-negotiation Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; speed N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-autoconfig Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; duplex N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; monitor-mode Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-speed Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; comments&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX bytes:0 packets:0 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:0 packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Interface eth3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; state on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type ethernet&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-state link up&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto-negotiation Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; speed 1000M&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-autoconfig Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; duplex full&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; monitor-mode Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-speed Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; comments&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX bytes:26408494 packets:97135 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:30682970 packets:104525 errors:0 dropped:0 overruns:0 frame:0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Interface eth4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; state on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type ethernet&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-state link up&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto-negotiation Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; speed 1000M&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-autoconfig Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; duplex full&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; monitor-mode Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-speed Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; comments&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX bytes:39517670 packets:938740 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:190616272 packets:3403862 errors:0 dropped:0 overruns:0 frame:0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Interface eth5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; state on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type ethernet&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-state link down&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto-negotiation on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; speed N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-autoconfig Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; duplex N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; monitor-mode Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-speed Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; comments&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX bytes:0 packets:0 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:0 packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;&lt;BR /&gt;Interface eth6&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; state on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type ethernet&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-state link up&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto-negotiation Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; speed 100M&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-autoconfig Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; duplex half&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; monitor-mode Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-speed Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; comments&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX bytes:728 packets:9 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:3832 packets:42 errors:0 dropped:0 overruns:0 frame:0&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;&lt;BR /&gt;Interface eth7&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; state on&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac-addr xx:xx:xx:xx:xx:xx&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type ethernet&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-state link up&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto-negotiation Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; speed 1000M&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-autoconfig Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; duplex full&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; monitor-mode Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-speed Not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; comments&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv4-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-address Not Configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ipv6-local-link-address Not Configured&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Statistics:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX bytes:661037290 packets:1624806 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:131111361 packets:1571111 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Jun 2020 21:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89852#M6872</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-06-25T21:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89861#M6875</link>
      <description>Did these same appliances work previously on a different release with these switches?&lt;BR /&gt;If so, it may be a side effect of upgrading kernel and drivers in R80.40.&lt;BR /&gt;In which case, a TAC case may be in order.</description>
      <pubDate>Thu, 25 Jun 2020 23:50:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89861#M6875</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-25T23:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89883#M6877</link>
      <description>&lt;P&gt;No, these are two brand new boxes and they have not been in production yet. I have not tried any other release on these boxes, I just performed upgrade from R80.30 (which was installed by default) to R80.40 using ISOMorphic tool.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 06:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89883#M6877</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-06-26T06:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89886#M6878</link>
      <description>May also be a hardware related issue.&lt;BR /&gt;Worth engaging the TAC in any case.</description>
      <pubDate>Fri, 26 Jun 2020 06:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89886#M6878</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-26T06:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89927#M6881</link>
      <description>&lt;P&gt;This may sound silly, but make sure you are using cat5e or cat6 cables, as cat5 and lower will only link up at 100Mbps.&amp;nbsp; The fact that it is going 100/half suggests some kind of autonegotiation issue as that is the default mode when there is no autonegotiation received.&lt;/P&gt;
&lt;P&gt;Your issue could be related to LLDP although this is normally only a problem with the Mellanox NICs, try these commands on the Nexus interface side:&lt;/P&gt;
&lt;P&gt;service unsupported-transceiver&lt;BR /&gt;no lldp transmit&lt;BR /&gt;no lldp receive&lt;/P&gt;
&lt;P&gt;This is supposed to be fixed in R80.40 but is worth a try.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 16:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89927#M6881</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-26T16:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89948#M6882</link>
      <description>&lt;P&gt;Actually, it was my first idea to check the cables, I was pretty confident this is a "cable" problem. After a lot of trying, changing cables and testing cables on different devices at the end I come to the conslusion all cables are fine, something else is root cause why interfaces are coming as 100M/Half only. Furthermore, I tried to disable autonegotiation on both sides (Cisco switch and Check Point) and to try 1000M/Full fixed on both sides, but unfortunatelly without any success, affected interfaces remain down.&amp;nbsp; Next step was to disable LLDP (which was actually disabled by default), also disabling CDP on Cisco side, but the original problem remains, still the same interfaces are working as 100M/Half only.&lt;/P&gt;&lt;P&gt;Just for clarification, I have two 5600s in a cluster, one cluster device is working OK, I believe the problem is limited just to my second 5600. So this second 5600 has 4 interfaces working as a 100M/Half and these connections are distributed, one towards my ISP (connected to ISP Cisco Catalyst 3750), two interfaces towards Cisco Nexus on the Inside and DMZ side and even one interface connected to primary 5600 is also &lt;SPAN&gt;100M/Half&lt;/SPAN&gt;. Additionally, on this device I have 3 interfaces working as 1000M/Full (two 1000M/Full interfaces connected to Cisco Nexus and one as a cluster sync).&lt;/P&gt;&lt;P&gt;I am using bonding, so if I have one 1000M/Full and one 100M/Half, the 100M/Half gets disabled. That was my second idea, to remove bonds, just to use physical interfaces, but the problem remains, I get the same "behavior" even without any bonding on Check Point and Cisco side.&lt;/P&gt;&lt;P&gt;On the other side, the problem is limited to my second cluster device only, my first 5600 has 6 interfaces in 1000M/Full state and just one 100M/Half because it is used as a cluster sync and obviously problematic device is "forcing" 100M/Half.&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;FONT color="#b00000"&gt;Timothy_Hall&lt;/FONT&gt; for a good hint, I did not know that interface is 100M/Half if no negotiation was received, so it actually brings me some new ideas. I am thinking to try some more deep debuging using mii-diag or ethtool tools.&lt;/P&gt;&lt;DIV class="lia-message-author-avatar lia-component-author-avatar lia-component-message-view-widget-author-avatar"&gt;&lt;DIV class="UserAvatar lia-user-avatar lia-component-common-widget-user-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 26 Jun 2020 21:00:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89948#M6882</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-06-26T21:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89950#M6883</link>
      <description>&lt;P&gt;Hmm sounds like you may have some kind of hardware issue with your secondary 5600.&amp;nbsp; Try swapping the set of switchports including the same cables between the two members.&amp;nbsp; So unplug the secondary from all its switchports, then plug the primary into those just-vacated switchports with its own cables, then plug the secondary into the primary's original ports with its own cables.&amp;nbsp; If the problem remains on the secondary that's a pretty good indication that it has a problem.&amp;nbsp; Other than perhaps running&lt;STRONG&gt; ethtool -i&lt;/STRONG&gt; against the various interfaces on both the primary and secondary to ensure they are using the same controller hardware and driver version, it is probably time for a TAC case and likely RMA.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 21:18:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89950#M6883</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-26T21:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89952#M6884</link>
      <description>&lt;P&gt;Yes, good idea, to switch the cables between 5600s, I will do it on Monday.&lt;/P&gt;&lt;P&gt;Actually, I was already switching the cables within the same "problematic" device, for example:&lt;/P&gt;&lt;P&gt;eth2 - 100M/Half&lt;/P&gt;&lt;P&gt;eth3 - 1000M/Full, working OK&lt;/P&gt;&lt;P&gt;eth2 &amp;amp; eth3 in the same bond connected to the Cisco Nexus (Port-channel is configured on a Cisco side).&lt;/P&gt;&lt;P&gt;I just switches the cables between eth2 and eth3 and the problem remains on eth2, so I still have the same situation, eth3 working OK and eth2 coming UP as a 100M/Half.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 21:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/89952#M6884</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-06-26T21:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/90020#M6887</link>
      <description>&lt;P&gt;I swapped the switchports between two 5600s including the cables, so I took validated cables and switchports from the regular 5600 and connect them to my problematic 5600 and the same problem remains, my problematic 5600 has 4 ports working as a 100M/Half and my regular 5600 again has all ports 1000M/Full (except the sync interface between two 5600s).&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 07:09:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/90020#M6887</guid>
      <dc:creator>MladenAntesevic</dc:creator>
      <dc:date>2020-06-29T07:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: 5600 SG R80.40 Interface issues?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/90053#M6889</link>
      <description>&lt;P&gt;Sounding more and more like hardware, although it could still be something in Gaia.&amp;nbsp; Try this on the problematic 5600:&lt;/P&gt;
&lt;P&gt;1) Take a snapshot from the Gaia web interface, and export/save a copy to your desktop&lt;/P&gt;
&lt;P&gt;2) Also take a backup of the box, and&amp;nbsp;export/save a copy to your desktop&lt;/P&gt;
&lt;P&gt;3) Scratch load the box from IsoMorphic/USB with R80.40&lt;/P&gt;
&lt;P&gt;4) After it boots back up, configure the interfaces with a minimal configuration from clish and check interface speeds.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My guess is you will still have the speed problem, and it is time for a RMA. Once you receive the new box revert the saved snapshot to it.&lt;/P&gt;
&lt;P&gt;If the speed problem disappears after the fresh load, something is messed up with the NIC driver in Gaia for the interfaces in your original image, so now restore the backup (not snapshot) to your freshly-loaded 5600 (make sure to run through the post-installation process and then reload any hotfixes/Jumbo HFAs first).&amp;nbsp; I doubt the speed problem is caused by something in your configuration that the restore will bring back.&amp;nbsp; If the speed problem returns after the restore (unlikely) something is seriously wrong in your Gaia config (/config/active file) and you need to look there.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 13:50:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/5600-SG-R80-40-Interface-issues/m-p/90053#M6889</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-29T13:50:01Z</dc:date>
    </item>
  </channel>
</rss>

