<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49923#M86676</link>
    <description>&lt;P&gt;What happens with two clusters with automatic magic, when they haven't had a common VLAN before, but at some momet they will be connected into the same VLAN?&lt;/P&gt;&lt;P&gt;Do members of one of the clusters adjust their magic or the learning process is only performed during the initial configuration and no further adjustments is made when another cluster "appears suddenly"?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2019 14:03:27 GMT</pubDate>
    <dc:creator>Olavi_Lentso</dc:creator>
    <dc:date>2019-04-05T14:03:27Z</dc:date>
    <item>
      <title>Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49892#M86674</link>
      <description>&lt;P&gt;Dear Check Point,&lt;/P&gt;&lt;P&gt;according to the different manuals I`ve read concerning SRC-MAC of CCP- and Forward-Packages and it is not recommended to set &amp;lt;MAC magic&amp;gt; any more by hand.&lt;/P&gt;&lt;P&gt;(See sk-25977-Change Source MAC Addresses - Gateway Mode - Gaia R80.10 - Procedure)&lt;/P&gt;&lt;P&gt;It is stated there, that the algorithm for the MAC magic is the following:&lt;/P&gt;&lt;P&gt;"During the initial configuration of the cluster members, they apply the following algorithm to set the MAC magic value:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Try to set the 5th byte of the Source MAC address to 1.&lt;BR /&gt;If CCP packets with such value in the 5th byte of the Source MAC address are detected, then select the next value.&lt;/LI&gt;&lt;LI&gt;Try to set the 5th byte of the Source MAC address to 2.&lt;BR /&gt;If CCP packets with such value in the 5th byte of the Source MAC address are detected, then select the next value.&lt;/LI&gt;&lt;LI&gt;And so on and so forth, until an unused value is detected (it takes up to ~30 seconds).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note: All members of the same cluster will set the same value."&lt;/P&gt;&lt;P&gt;I am wondering, because this (locally limited) algorithm will, for each Cluster with a separated/dedicated sync-network, find the same value for its &amp;lt;MAC magic&amp;gt; (so the Cluster-ID).&lt;/P&gt;&lt;P&gt;According to the same SK there should be a unique Cluster-ID for all (managed) Clusters within the domain: "Enter a unique value for each cluster in the domain."&lt;/P&gt;&lt;P&gt;The above algorithm will not find the other Clusters if they have separated sync-networks. So as far as I understand, there will be the same Cluster-ID along many clusters ( in this case always the ID 1).&lt;/P&gt;&lt;P&gt;Could you please clarify this for me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 09:56:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49892#M86674</guid>
      <dc:creator>Linus_Espach</dc:creator>
      <dc:date>2019-04-05T09:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49918#M86675</link>
      <description>&lt;P&gt;CCP is blasted on all cluster interfaces, not over isolated SYNC link or network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I.e.:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;[Expert@HostName]# cphaprob -a if&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The CCP mode will appear at the end of the line.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Example&lt;/EM&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;PRE&gt; 
Required interfaces: 4
Required secured interfaces: 1

eth0       UP                    non sync(non secured), &lt;STRONG&gt;multicast&lt;/STRONG&gt;
eth1       UP                    sync(secured), &lt;STRONG&gt;multicast&lt;/STRONG&gt;
eth2       UP                    non sync(non secured), &lt;STRONG&gt;multicast&lt;/STRONG&gt;
eth3       UP                    non sync(non secured), &lt;STRONG&gt;multicast&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 05 Apr 2019 13:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49918#M86675</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-05T13:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49923#M86676</link>
      <description>&lt;P&gt;What happens with two clusters with automatic magic, when they haven't had a common VLAN before, but at some momet they will be connected into the same VLAN?&lt;/P&gt;&lt;P&gt;Do members of one of the clusters adjust their magic or the learning process is only performed during the initial configuration and no further adjustments is made when another cluster "appears suddenly"?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 14:03:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49923#M86676</guid>
      <dc:creator>Olavi_Lentso</dc:creator>
      <dc:date>2019-04-05T14:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49930#M86677</link>
      <description>Sure, probe-requests are sent along all interfaces, but as far as I understood this procedure, it is limited to L-2 communication. Therefor, if you have Clusters among different networks (I.e. VPN, or separated / routed networks) this will fail.</description>
      <pubDate>Fri, 05 Apr 2019 15:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49930#M86677</guid>
      <dc:creator>Linus_Espach</dc:creator>
      <dc:date>2019-04-05T15:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49962#M86678</link>
      <description>&lt;P&gt;More see here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-30-cheat-sheet-ClusterXL/td-p/41693" target="_self"&gt;R80.30 cheat sheet - ClusterXL&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 20:34:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/49962#M86678</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-05T20:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/50476#M86679</link>
      <description>The Magic MAC should be the same among all members of the same cluster and unique for each cluster on the same Layer 2 network.&lt;BR /&gt;It's possible (and expected) that clusters on different Layer 2/3 networks might have the same Magic MAC.&lt;BR /&gt;If suddenly a new cluster shows up on the same Layer 2 network and the Magic MACs collide, this will be detected and adjusted on the fly.</description>
      <pubDate>Wed, 10 Apr 2019 17:36:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/50476#M86679</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-10T17:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/50534#M86680</link>
      <description>&lt;P&gt;I would like to know more about the situation where 2 or more already operational clusters are going to have a shared layer 2/3 network. How the clusters decide, which of them wins the fight and could keep the existing ID and which one must change it's ID. What impact is expected while VMAC being ON or OFF?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 07:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/50534#M86680</guid>
      <dc:creator>Olavi_Lentso</dc:creator>
      <dc:date>2019-04-11T07:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Automated MAC magic value in R80.10 might lead to same Cluster-ID`s along all Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/63754#M86681</link>
      <description>&lt;P&gt;just stumbled across your question - sorry if this answer is for R80.30, surely there's one in the adminguide for .10 as well. I would assume the underlying mechanism of the packets on the wire hasn't changed - if it had it'd certainly pose problems when upgrading firewalls.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/198602" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/198602&lt;/A&gt;&lt;/P&gt;&lt;P&gt;... Chapter "Connecting Several Clusters on the Same VLAN"&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 15:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-MAC-magic-value-in-R80-10-might-lead-to-same-Cluster/m-p/63754#M86681</guid>
      <dc:creator>Albert_Wilkes</dc:creator>
      <dc:date>2019-09-26T15:43:47Z</dc:date>
    </item>
  </channel>
</rss>

