<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move Vlans to new Interface (10G-Bond) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/163516#M27307</link>
    <description>&lt;P&gt;I performed these steps:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Standby: add new vlan,&amp;nbsp; delete old vlan, conf new subinterface&lt;/LI&gt;&lt;LI&gt;Get interface without topology&lt;/LI&gt;&lt;LI&gt;Install policy&lt;/LI&gt;&lt;LI&gt;Cphastop;cphastart&amp;nbsp; Standby node (now you will have desidered output in cphaprob -a if)&lt;/LI&gt;&lt;LI&gt;cphastop on active node (trigger failover)&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Tue, 29 Nov 2022 10:49:13 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2022-11-29T10:49:13Z</dc:date>
    <item>
      <title>Move Vlans to new Interface (10G-Bond)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/83815#M16952</link>
      <description>&lt;P&gt;Hi CheckMates&lt;/P&gt;&lt;P&gt;We're currently running a clustered Firewall (4800, R80.20) with three connected 1G-interfaces&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;External (eth1): Vlan-Trunk, 1 Vlan&lt;/LI&gt;&lt;LI&gt;Internal (eth2), Vlan-Trunk, 8 Vlans&lt;/LI&gt;&lt;LI&gt;Sync (eth3), Access-Port&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The Firewalls were now upgraded with a 2x10G-Module (eth1-01, eth1-02) each. I will create a LACP-bond (2x10G) and would like to move all Vlans from the External- and Internal Interfaces to the new 10G-Bond. The Sync-Traffic will remain on the separate 1G-Interface for now.&lt;/P&gt;&lt;P&gt;My next steps would be:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create the new LACP-Bond (bond1) on both members and make sure it is UP&lt;/LI&gt;&lt;LI&gt;Standby-Node: Remove first Vlan-Interface (e.g. eth2.32) including IP-configuration in Web-UI&lt;/LI&gt;&lt;LI&gt;Standby-Node: Create new Vlan-Interface (e.g. bond1.32) on 10G-Bond with IP-address in Web-UI&lt;/LI&gt;&lt;LI&gt;Magic in SmartConsole and Policy Push *&lt;/LI&gt;&lt;LI&gt;Failover&lt;/LI&gt;&lt;LI&gt;Repeat Steps 2-4&lt;/LI&gt;&lt;LI&gt;Now repeat steps 1-6 for every Vlan or maybe do all in one run&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;* Now the part where i'm struggling..&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Should i now get the new topology of that cluster-interface (Int.32) in SmartConsole?&lt;/LI&gt;&lt;LI&gt;Or rather update the Interface-Name by hand? (see screenshot below)&lt;/LI&gt;&lt;LI&gt;Is it even possible to configure a VIP over two different ports for a short time (member1: eth2.32, member2: bond1.32)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="overview.png" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5876iE84C542371D0975A/image-size/small?v=v2&amp;amp;px=200" role="button" title="overview.png" alt="overview.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="interface-config.png" style="width: 191px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5875i0A98E3D3BA1D7B66/image-size/small?v=v2&amp;amp;px=200" role="button" title="interface-config.png" alt="interface-config.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is there another better and easier way? It wouldn't be a problem to announce a small downtime.&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;BR /&gt;Christian&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 12:27:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/83815#M16952</guid>
      <dc:creator>Christian</dc:creator>
      <dc:date>2020-05-01T12:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Move Vlans to new Interface (10G-Bond)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/83848#M16957</link>
      <description>First do this on all interfaces to be moved, of your backup gateway, in the clusterinterface in SmartConsole just update the name, do not in any case run the get interfaces with topology!!&lt;BR /&gt;Once the first member is done, flip the cluster and move the other member to the 10G interface Bond.</description>
      <pubDate>Fri, 01 May 2020 17:28:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/83848#M16957</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-05-01T17:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Move Vlans to new Interface (10G-Bond)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/83993#M16986</link>
      <description>&lt;P&gt;Hi Maarten&lt;/P&gt;&lt;P&gt;Thanks! Do i need to take precautions before starting with the procedure (like cphastop)?&lt;/P&gt;&lt;P&gt;According to your reply i would now do the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Standby-Node: Create new lacp-bond (bond1) and make sure it is UP&lt;/LI&gt;&lt;LI&gt;Standby-Node: Delete and Re-Create all Vlan-Interfaces (e.g. eth2.32) on new bond1 Interface&lt;/LI&gt;&lt;LI&gt;Ping-Check to IPs of Vlan-Interfaces / SIC-Test&lt;/LI&gt;&lt;LI&gt;SmartConsole: Change Interface-Name of all moved interfaces (e.g. eth2.32 =&amp;gt; bond1.32)&lt;/LI&gt;&lt;LI&gt;SmartConsole: Install Policy on both members&lt;/LI&gt;&lt;LI&gt;Initiate Failover&lt;/LI&gt;&lt;LI&gt;Run Steps 1-6 on new Standby-Node&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;And we are done? No need to change the Interface-Names somewhere else?&lt;BR /&gt;I'm surprised, this procedure looks pretty easy and straightforward to me.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Christian&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 07:15:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/83993#M16986</guid>
      <dc:creator>Christian</dc:creator>
      <dc:date>2020-05-04T07:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Move Vlans to new Interface (10G-Bond)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/84001#M16987</link>
      <description>You will see at some point that the cphaprob will have an issue, you could insert a cphastop before changing the interfaces on the node and cpahastart just before the failover, which can then be initiated by a cphastop on the other node.&lt;BR /&gt;Just make sure you do it in a sevice window as you will probaly drop all running connections when failing over.</description>
      <pubDate>Mon, 04 May 2020 07:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/84001#M16987</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-05-04T07:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Move Vlans to new Interface (10G-Bond)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/162090#M27056</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please share how was your activity ? did you follow same method or any changes ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 05:07:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/162090#M27056</guid>
      <dc:creator>lambda04</dc:creator>
      <dc:date>2022-11-15T05:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: Move Vlans to new Interface (10G-Bond)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/163516#M27307</link>
      <description>&lt;P&gt;I performed these steps:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Standby: add new vlan,&amp;nbsp; delete old vlan, conf new subinterface&lt;/LI&gt;&lt;LI&gt;Get interface without topology&lt;/LI&gt;&lt;LI&gt;Install policy&lt;/LI&gt;&lt;LI&gt;Cphastop;cphastart&amp;nbsp; Standby node (now you will have desidered output in cphaprob -a if)&lt;/LI&gt;&lt;LI&gt;cphastop on active node (trigger failover)&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 29 Nov 2022 10:49:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Move-Vlans-to-new-Interface-10G-Bond/m-p/163516#M27307</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-11-29T10:49:13Z</dc:date>
    </item>
  </channel>
</rss>

