<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Cluster VLAN Interface Remove/Delete in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156007#M73180</link>
    <description>&lt;P&gt;Thanks Martin. So, would you recommend following the process outlined earlier in this post, or just delete the cluster interface, reconfigure the physical interfaces on the gateways, and then add the cluster interface referencing the new physical interfaces?&lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2022 15:04:21 GMT</pubDate>
    <dc:creator>Alan_S</dc:creator>
    <dc:date>2022-08-30T15:04:21Z</dc:date>
    <item>
      <title>HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140093#M73166</link>
      <description>&lt;P&gt;Hi Experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am planning to delete an interface from a HA Cluster setup (R81.10) and I have come up with the following steps.. Do these steps look correct to you? It's very hard for me to know the correct way to do this having never done it before and I'm praying this is correct..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Brief action plan for&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;removing&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;an interface from cluster topology (R80.10 and above)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Remove the Virtual IP address and Change the Interface to 'Private' in SmartConsole and push policy.&lt;/LI&gt;&lt;LI&gt;check &lt;STRONG&gt;chaprob -a if &lt;/STRONG&gt;for the change on both firewall gateway members.&lt;/LI&gt;&lt;LI&gt;Disable clustering on standby gateway.&lt;/LI&gt;&lt;LI&gt;delete the interface from standby gateway.&lt;/LI&gt;&lt;LI&gt;delete the interface from active gateway.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;Delete the interface&amp;nbsp; from SmartConsole and push policy.&lt;/LI&gt;&lt;LI&gt;Restart clustering on standby gateway.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Detailed action plan for&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;removing&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;an interface from cluster topology (R80.10 and above)&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Perform these steps in&amp;nbsp;&lt;STRONG&gt;SmartConsole&lt;/STRONG&gt;&amp;nbsp;(before&amp;nbsp;removing an interface from Cluster object topology, set it to 'Private'):&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Open the cluster object properties.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Go to the 'ClusterXL and VRRP' pane.&lt;/LI&gt;&lt;LI&gt;Under the 'Upon cluster member recovery' section, make sure the 'Maintain current active Cluster Member' option is selected.&lt;/LI&gt;&lt;LI&gt;Go to the 'Network Management' pane.&lt;/LI&gt;&lt;LI&gt;Highlight the interface by clicking on it once and then click on '&lt;STRONG&gt;Edit&lt;/STRONG&gt;' button.&lt;/LI&gt;&lt;LI&gt;Remove the Virtual IP address from the pair of the interfaces that should be removed from Cluster object topology.&lt;/LI&gt;&lt;LI&gt;In the 'Network Type' dropdown, select '&lt;STRONG&gt;Private&lt;/STRONG&gt;'&lt;/LI&gt;&lt;LI&gt;Click on '&lt;STRONG&gt;OK&lt;/STRONG&gt;' to apply the changes.&lt;/LI&gt;&lt;LI&gt;Proceed with installing the relevant policy to that cluster&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;On each cluster member:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Connect to the command line (over SSH, or console).&lt;/LI&gt;&lt;LI&gt;Log in to the Expert mode.&lt;/LI&gt;&lt;LI&gt;Run the&amp;nbsp;&lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt;&amp;nbsp;command.&lt;/LI&gt;&lt;LI&gt;Check the 'Required number of interfaces' - the total number has to decrease by the number of interfaces that were configured as 'Private'.&lt;BR /&gt;&lt;I&gt;&lt;BR /&gt;Example&lt;/I&gt;:&lt;BR /&gt;If there were 11 interfaces&lt;BR /&gt;And 1 interface was configured as 'Non-Monitored Private'&lt;BR /&gt;Then now 'Required number of interfaces' should show 10 interfaces.&lt;BR /&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&amp;nbsp;If the 'Required number of interfaces' did not decrease, then reboot the problematic cluster member.&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Perform these steps on the&amp;nbsp;&lt;STRONG&gt;Standby&lt;/STRONG&gt;&amp;nbsp;member:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Either stop the Clustering by running the '&lt;STRONG&gt;cphastop&lt;/STRONG&gt;' command, or bring this member administratively down by running the '&lt;STRONG&gt;clusterXL_admin down&lt;/STRONG&gt;' command.&lt;/LI&gt;&lt;LI&gt;Delete the interface via one of the following two ways:&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;Gaia Web Portal:&lt;/LI&gt;&lt;/UL&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Step&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Description&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;1&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;In the navigation tree, click Network Management &amp;gt; Network Interfaces.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;2&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Select the correct Interface from the list and Click the 'Delete' button.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Gaia Clish Mode:&lt;BR /&gt;&lt;STRONG&gt;delete interface eth1 vlan 172&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; save config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Perform these steps on the&amp;nbsp;&lt;STRONG&gt;Active&lt;/STRONG&gt;&amp;nbsp;member:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Do NOT disable clustering. Check clustering is active using the '&lt;STRONG&gt;cphaprob state&lt;/STRONG&gt;' command.&lt;/LI&gt;&lt;/OL&gt;&lt;OL&gt;&lt;LI&gt;Delete the interface via one of the following two ways:&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;Gaia Web Portal:&lt;/LI&gt;&lt;/UL&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Step&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Description&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;1&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;In the navigation tree, click Network Management &amp;gt; Network Interfaces.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;2&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Select the correct Interface from the list and Click the 'Delete' button.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Gaia Clish Mode:&lt;BR /&gt;&lt;STRONG&gt;delete interface eth1 vlan 172&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;save config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Perform these steps in &lt;STRONG&gt;SmartConsole&lt;/STRONG&gt;:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Open Cluster object properties.&lt;/LI&gt;&lt;LI&gt;Go to the 'Network Management' and then highlight the interface by clicking on it once and then click on 'Edit' button.&lt;/LI&gt;&lt;LI&gt;Remove the interface from the Topology table from the cluster object.&lt;/LI&gt;&lt;LI&gt;Click on 'OK' to apply the changes.&lt;/LI&gt;&lt;LI&gt;Install the relevant policy onto the cluster object.&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Perform these steps on&amp;nbsp;&lt;STRONG&gt;Standby&lt;/STRONG&gt;&amp;nbsp;member:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Connect to the command line (over SSH, or console).&lt;/LI&gt;&lt;LI&gt;Log in to the Expert mode.&lt;/LI&gt;&lt;LI&gt;Either start the Clustering by running the '&lt;STRONG&gt;cphastart&lt;/STRONG&gt;' command, or bring this member administratively up by running the '&lt;STRONG&gt;clusterXL_admin up&lt;/STRONG&gt;' command.&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Verify that the new interface was deleted from cluster topology - run this command on&amp;nbsp;&lt;STRONG&gt;each&lt;/STRONG&gt;&amp;nbsp;cluster member:&lt;BR /&gt;&lt;STRONG&gt;[Expert@HostName]# &lt;/STRONG&gt;&lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;If the new interface was not deleted yet, then reboot each cluster member.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 01 Feb 2022 15:17:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140093#M73166</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-01T15:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140094#M73167</link>
      <description>&lt;P&gt;Hi Martin,&amp;nbsp;&lt;SPAN&gt;sk57100 provides a reasonable reference for such activities.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;As a side, Cluster XL monitors the highest and lowest active VLANs on an interface, is the VLAN ID in question either of those or somewhere in-between?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 15:29:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140094#M73167</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-01T15:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140102#M73168</link>
      <description>&lt;P&gt;Hi Chris,&amp;nbsp;&lt;BR /&gt;I'm really glad you mentioned "&lt;SPAN&gt;&lt;EM&gt;Cluster XL monitors the highest and lowest active VLANs on an interface&lt;/EM&gt;", because I didn't know this. So am I right in saying that ClusterXL will monitor itself through all physical interfaces, but if an interface is trunked with VLANs, then it elects to monitor itself through one particular VLAN on that interface? I just checked now and I can see the VLAN in question is indeed the lowest numbered VLAN on it's particular interface that it's currently being trunked on, yes. What are the implications and what steps must I follow?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 16:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140102#M73168</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-01T16:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140131#M73169</link>
      <description>&lt;P&gt;The ClusterXL admin guide and serval SK articles describe VLAN monitoring in detail.&lt;/P&gt;
&lt;P&gt;The highest and lowest VLAN IDs on a trunk are both monitored by default (configurable).&lt;/P&gt;
&lt;P&gt;In your situation it's important to not take shortcuts since the lowest VLAN ID is one that will directly trigger the interface active check/pnote of ClusterXL.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 01:05:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140131#M73169</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-02T01:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140133#M73170</link>
      <description>&lt;P&gt;Just to tell you something from my own experience...when you add clans in web UI, and you go to dashboard, do NOT click "get interface with topology", as that can mess up everything. Just do get interfaces without topology and I would also recommend to set topology as "network defined by routes", as that calculates topology behind the interface.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 02:31:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140133#M73170</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T02:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140173#M73171</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;- thank you for this note about your experience with adding VLANs. I did actually see this in another post, that adding "WITH topology" will cause problems. I'll make sure I add new interfaces WITHOUT topology, yes. Many thanks for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 09:21:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140173#M73171</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-02T09:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140186#M73172</link>
      <description>&lt;P&gt;The ClusterXL admin guide says the following:&lt;BR /&gt;&lt;EM&gt;"ClusterXL (including VSX) supports the Synchronization Network (CCP packets that carry Delta Sync information) only on the lowest VLAN ID (VLAN tag). For example, if three VLANs with IDs 10, 20 and 30 are configured on interface eth1, then you can use only the VLAN interface eth1.10 for the State Synchronization."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This leaves me with more questions than answers. Okay so here are my questions:&lt;/P&gt;&lt;P&gt;Is the state synchronization mentioned here the same type of synchronization offered by a 'Sync' interface?&lt;BR /&gt;If I have a dedicated 'Sync' interface, is the above statement about 'the lowest VLAN ID' irrelevant?&lt;BR /&gt;If the state synchronization mentioned here is a different type of synchronization offered by a 'Sync' interface, then what exactly is that difference, where I can learn more information about this difference, and what are the mitigation steps to avoid any issues if this 'lowest VLAN ID' were to be deleted?&lt;BR /&gt;Where exactly does it mention that the lowest VLAN ID is one that will directly trigger the interface active check/pnote of ClusterXL?&lt;/P&gt;&lt;P&gt;Any information you can shed is very&amp;nbsp; gratefully appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 09:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140186#M73172</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-02T09:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140194#M73173</link>
      <description>&lt;P&gt;For a given cluster there is typically only a single sync interface defined in the cluster topology either physical or VLAN.&lt;/P&gt;
&lt;P&gt;Again, both the highest and lowest VLAN are monitored on a trunk port used as a data interface by default.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 10:06:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/140194#M73173</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-02T10:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/155991#M73174</link>
      <description>&lt;P&gt;Hi - could you not simply delete the interface in Cluster XL and then delete the interfaces on the gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 13:48:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/155991#M73174</guid>
      <dc:creator>Alan_S</dc:creator>
      <dc:date>2022-08-30T13:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156000#M73175</link>
      <description>&lt;P&gt;In very simple terms you have described what&amp;nbsp;&lt;SPAN&gt;sk57100 documents as the removal process.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 14:40:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156000#M73175</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-30T14:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156001#M73176</link>
      <description>&lt;P&gt;Thanks Chris. What I was wondering was, could you delete the cluster interface, and remove/disable the interface on the gateways, without entering "cphastop" and then "cphastart" on the standby gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 14:44:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156001#M73176</guid>
      <dc:creator>Alan_S</dc:creator>
      <dc:date>2022-08-30T14:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156004#M73177</link>
      <description>&lt;P&gt;This was the exact process I used. I did not need to use cpstop/cpstart.&lt;/P&gt;&lt;P&gt;1. Backup both gateways&lt;/P&gt;&lt;P&gt;Take backups and snapshots. Save to external location.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. Disable the interfaces from Solarwinds Monitoring.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3. Edit the Cluster object in SMS&lt;/P&gt;&lt;P&gt;Go into Cluster member tab, change the IP addresses for both cluster members to the new IP addresses.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;4. Perform a SIC test in SMS to ensure comms to/from both gateways function as expected.&lt;BR /&gt;SIC was working fine.&lt;BR /&gt;&lt;BR /&gt;5. Update the Alias URL (Platform Portal URL) within Smart Centre.&lt;BR /&gt;1. Place the new URLs in manually for each gateway.&lt;BR /&gt;&lt;BR /&gt;6. Push an blank/empty Policy change to the firewall cluster in SMS&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;7. Change the Management IP address of the gateway in GAIA&lt;/P&gt;&lt;P&gt;Update each gateway to the new management interface in CLISH&lt;BR /&gt;&lt;BR /&gt;Update the DNS host file entry for the firewall hostname/IP mapping:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;8. Check ID Awareness PDP to ensure the firewalls are still connected to ID sharing peers:&lt;/P&gt;&lt;P&gt;pdp connections pep&lt;/P&gt;&lt;P&gt;pep show pdp all&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Perform validation testing&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 14:52:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156004#M73177</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-08-30T14:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156005#M73178</link>
      <description>&lt;P&gt;Thanks - I was just wondering. I am due to remove a cluster object and reinstate it on a different interface on our firewall gateways. Would you recommend following that process?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 14:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156005#M73178</guid>
      <dc:creator>Alan_S</dc:creator>
      <dc:date>2022-08-30T14:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156006#M73179</link>
      <description>&lt;P&gt;Sorry, no. I didn't read the title of this thread properly. That process I just gave you was for changing a Management interface to a new interface on the same firewall. Do not follow it for what you are doing, no.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 15:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156006#M73179</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-08-30T15:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156007#M73180</link>
      <description>&lt;P&gt;Thanks Martin. So, would you recommend following the process outlined earlier in this post, or just delete the cluster interface, reconfigure the physical interfaces on the gateways, and then add the cluster interface referencing the new physical interfaces?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 15:04:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156007#M73180</guid>
      <dc:creator>Alan_S</dc:creator>
      <dc:date>2022-08-30T15:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156008#M73181</link>
      <description>&lt;P&gt;yes, follow it. You will need to cpstop / cpstart.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 15:06:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156008#M73181</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-08-30T15:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156009#M73182</link>
      <description>&lt;P&gt;Thanks - so that is "cphastop/cphastart" on the standby gateway? Just making sure to cover all bases.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 15:09:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156009#M73182</guid>
      <dc:creator>Alan_S</dc:creator>
      <dc:date>2022-08-30T15:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156010#M73183</link>
      <description>&lt;P&gt;yes, exactly as I have written it in bold in the original post.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 15:11:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156010#M73183</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-08-30T15:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: HA Cluster VLAN Interface Remove/Delete</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156011#M73184</link>
      <description>&lt;P&gt;Thank you Martin. Much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 15:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HA-Cluster-VLAN-Interface-Remove-Delete/m-p/156011#M73184</guid>
      <dc:creator>Alan_S</dc:creator>
      <dc:date>2022-08-30T15:12:17Z</dc:date>
    </item>
  </channel>
</rss>

