<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: handle ARP broadcasting on cluster FW in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64549#M13156</link>
    <description>&lt;P&gt;Firstly, i have to tell you that the used version R77.30 is &amp;nbsp;out of support. In &lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111956&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22" target="_blank"&gt;sk111956: &lt;STRONG&gt;ARP&lt;/STRONG&gt; Forwarding in Check Point ClusterXL&lt;/A&gt;&amp;nbsp;you will find details about ARP and clusterXL...&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2019 14:56:28 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-10-08T14:56:28Z</dc:date>
    <item>
      <title>handle ARP broadcasting on cluster FW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64547#M13155</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the topology:&lt;/P&gt;&lt;P&gt;I have a cluster GW R77.30 and each cluster has an interface in VLAN 142 which are connected to Cisco L2 switch and on the other hand our client has two redundant server that are connected to another Cisco L2 switch and they configured the servers GW with my GW VIP 192.168.10.17&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.10.10 Server 1 &amp;lt;----&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.10.19 FW -1 active&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Cisco 3750&amp;nbsp; &amp;lt;-----&amp;gt; Cisco 3850&amp;lt;-----&amp;nbsp; VIP 192.168.10.17&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;------&amp;nbsp; &amp;nbsp;server B&lt;/P&gt;&lt;P&gt;192.168.10.11 server 2 &amp;lt;-----&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;192.168.10.18&amp;nbsp; FW-2 Passive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;additional Info:&lt;/P&gt;&lt;P&gt;1- in our network a few servers are in server B side want to talk to server 1 and 2&lt;/P&gt;&lt;P&gt;2-server 1 and 2 are Linux&lt;/P&gt;&lt;P&gt;so the problem is&amp;nbsp; when client patching their servers( 1 and 2)&amp;nbsp; and reboot them all TCP session from server B will be down and server 1 and 2 not respond to any TCP or ICMP request and when they ping VIP .17 is not getting response so they have to ping our FW physical IPs .18 and .19 and then ping VIP .17 , do you have any idea of this issue?&lt;/P&gt;&lt;P&gt;how the cluster FW handle ARP broadcasting ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;appreciate that if you share your experience&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 14:34:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64547#M13155</guid>
      <dc:creator>Kamiar_Sh</dc:creator>
      <dc:date>2019-10-08T14:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: handle ARP broadcasting on cluster FW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64549#M13156</link>
      <description>&lt;P&gt;Firstly, i have to tell you that the used version R77.30 is &amp;nbsp;out of support. In &lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111956&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22" target="_blank"&gt;sk111956: &lt;STRONG&gt;ARP&lt;/STRONG&gt; Forwarding in Check Point ClusterXL&lt;/A&gt;&amp;nbsp;you will find details about ARP and clusterXL...&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 14:56:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64549#M13156</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-08T14:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: handle ARP broadcasting on cluster FW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64550#M13157</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19727"&gt;@Kamiar_Sh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may want to try to enable virtual mac configuration in Cluster XL, it sounds that will solve your issue. This way you network will always see the same MAC address of your cluster.&lt;/P&gt;&lt;P&gt;Hope it helps,&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 15:05:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64550#M13157</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-08T15:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: handle ARP broadcasting on cluster FW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64553#M13159</link>
      <description>&lt;P&gt;I am wondering is there any potential impact if I enable VMAC ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 15:36:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64553#M13159</guid>
      <dc:creator>Kamiar_Sh</dc:creator>
      <dc:date>2019-10-08T15:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: handle ARP broadcasting on cluster FW</title>
      <link>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64554#M13160</link>
      <description>&lt;P&gt;Most issues arise from the fact that your switch will see the same mac address on different ports, but that is easly configurable from the switch perspective.&lt;/P&gt;&lt;P&gt;Even if it's not directly related, you may want to check a question that I asked here in this post&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/VSX/VSX-Cluster-Bond-Proxy-ARP-To-VMAC-or-not-to-VMAC/m-p/59255" target="_self"&gt;VSX Cluster + Bond + Proxy ARP: To VMAC or not to VMAC&lt;/A&gt;&amp;nbsp;where&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;share useful information about VMAC.&lt;/P&gt;&lt;P&gt;As always, try to do these changes on maintenance window, its easy to revert in case of failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 15:43:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/handle-ARP-broadcasting-on-cluster-FW/m-p/64554#M13160</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-08T15:43:08Z</dc:date>
    </item>
  </channel>
</rss>

