<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing bond mode on Security Group ports in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221729#M2769</link>
    <description>&lt;P&gt;That would be magg0. Either way, I have console access to the appliances.&lt;/P&gt;&lt;P&gt;My original question was, would changing the bond ports 1 and 2 from 802.3ad to XOR have an effect traffic flow?&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2024 18:56:38 GMT</pubDate>
    <dc:creator>Stephen_Schickl</dc:creator>
    <dc:date>2024-07-23T18:56:38Z</dc:date>
    <item>
      <title>Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221637#M2762</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am working with an HA pair of MHO-175s and a single site using a clustered pair of 23900s for my SGMs. Per &lt;SPAN&gt;sk178045, I&lt;/SPAN&gt;n order to perform an upgrade from R81.10 to R81.20, the bond ports will need to be changed to anything other than 802.3ad. Will doing this cause an interruption in traffic flow?&lt;/P&gt;&lt;P&gt;I'm wanting to know if I can perform this action during work hours, or wait until after hours or the weekend.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 23:43:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221637#M2762</guid>
      <dc:creator>Stephen_Schickl</dc:creator>
      <dc:date>2024-07-22T23:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221661#M2764</link>
      <description>&lt;P&gt;how does the management server connected to the SG ? via the Data ports of via the Mgmt ports ?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 07:12:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221661#M2764</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-07-23T07:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221702#M2765</link>
      <description>&lt;P&gt;Hello Nir,&lt;/P&gt;&lt;P&gt;The Maestro's management bonded port magg0 set at XOR.&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 14:42:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221702#M2765</guid>
      <dc:creator>Stephen_Schickl</dc:creator>
      <dc:date>2024-07-23T14:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221704#M2766</link>
      <description>&lt;P&gt;ok,&lt;/P&gt;
&lt;P&gt;so if you change the magg0 bond configuration it won't affect data traffic only management traffic, as I hope you data traffic is passing on other bonds.&lt;/P&gt;
&lt;P&gt;I usually configure magg0 as active-standby with eth1-mgmt as primary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 15:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221704#M2766</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-07-23T15:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221708#M2767</link>
      <description>&lt;P&gt;Nir,&lt;/P&gt;&lt;P&gt;The bonds I need to change are the inside network, bond1, and the outside network, bond 2. They are the bonds set at 802.3ad. I've attached a simple diagram.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 16:16:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221708#M2767</guid>
      <dc:creator>Stephen_Schickl</dc:creator>
      <dc:date>2024-07-23T16:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221716#M2768</link>
      <description>&lt;P&gt;But where does your Management Server is ? behind bond1/2 or behind magg0 ?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 18:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221716#M2768</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-07-23T18:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221729#M2769</link>
      <description>&lt;P&gt;That would be magg0. Either way, I have console access to the appliances.&lt;/P&gt;&lt;P&gt;My original question was, would changing the bond ports 1 and 2 from 802.3ad to XOR have an effect traffic flow?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 18:56:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221729#M2769</guid>
      <dc:creator>Stephen_Schickl</dc:creator>
      <dc:date>2024-07-23T18:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221740#M2770</link>
      <description>&lt;P&gt;Yes, because the switches will likely take the bond down due to no LACP negotiation.&lt;/P&gt;
&lt;P&gt;You don't need to change the configuration of your data ports, the SK only applies when the SG communicates to the management server via an LACP bond. In your case you've already stated that your administration comms go via magg0 which is configured as XOR.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 04:03:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221740#M2770</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-07-24T04:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221860#M2773</link>
      <description>&lt;P&gt;So there will be a loss of internet connectivity after changing the inside and outside bonds?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 21:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221860#M2773</guid>
      <dc:creator>Stephen_Schickl</dc:creator>
      <dc:date>2024-07-24T21:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221861#M2774</link>
      <description>&lt;P&gt;Hi Stephen, what Emma and Nir are asking saying is - the SK you are worrying about, it talking about taking LACP off your Mgmt (MAGG) port. If your inside / outside bonds are LACP, and are "data only" (not used for management) then you dont need to make any changes to them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, YES if you change the non-Magg port - in your case, inside and outside to non-LACP, it will cause disruption, and that's not related to CP/Maestro, but LACP. but, they are saying you dont need to change those non-Magg ports.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if you DONT change the mode on the data ports/bonds, then they wont have loss of connectivity, and you can/should leave them as they are, and change only the Mgmt/MAGG bond mode.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 21:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221861#M2774</guid>
      <dc:creator>Tom_Kendrick</dc:creator>
      <dc:date>2024-07-24T21:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Changing bond mode on Security Group ports</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221866#M2775</link>
      <description>&lt;P&gt;Thank you all for guiding me through this.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 00:58:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Changing-bond-mode-on-Security-Group-ports/m-p/221866#M2775</guid>
      <dc:creator>Stephen_Schickl</dc:creator>
      <dc:date>2024-07-25T00:58:06Z</dc:date>
    </item>
  </channel>
</rss>

