<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SMB Cluster - Management  Interface in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201483#M10039</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I create SMB Cluster R80.20.50 via Smart Console in High Availability mode.&lt;/P&gt;&lt;P&gt;This cluster have s2s with Gaia 7000.&lt;/P&gt;&lt;P&gt;My Goal: to create managmenet inteface on each gateway of the SMB which is not monitored by the cluster&amp;nbsp;&lt;BR /&gt;in order to get access to each device seperatly.&lt;/P&gt;&lt;P&gt;In topology table I configred this interface as "Non-Monitored Private" and it is internal.&lt;/P&gt;&lt;P&gt;The problem is that I still got access to Avtive member interface and not to the standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this is because of the site to site.&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Dec 2023 11:02:38 GMT</pubDate>
    <dc:creator>leonid1890</dc:creator>
    <dc:date>2023-12-25T11:02:38Z</dc:date>
    <item>
      <title>SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201483#M10039</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I create SMB Cluster R80.20.50 via Smart Console in High Availability mode.&lt;/P&gt;&lt;P&gt;This cluster have s2s with Gaia 7000.&lt;/P&gt;&lt;P&gt;My Goal: to create managmenet inteface on each gateway of the SMB which is not monitored by the cluster&amp;nbsp;&lt;BR /&gt;in order to get access to each device seperatly.&lt;/P&gt;&lt;P&gt;In topology table I configred this interface as "Non-Monitored Private" and it is internal.&lt;/P&gt;&lt;P&gt;The problem is that I still got access to Avtive member interface and not to the standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this is because of the site to site.&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Dec 2023 11:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201483#M10039</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2023-12-25T11:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201544#M10044</link>
      <description>&lt;P&gt;What version/JHF is your management?&lt;BR /&gt;Setting a "Non-Monitored Private" interface isn't necessary here, but you may need to disable cluster fold NAT.&lt;BR /&gt;It is settable via the CLI from R81.10.00:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/170583.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/170583.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2023 20:59:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201544#M10044</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-26T20:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201551#M10045</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Smart Console version is R81.10&lt;/P&gt;&lt;P&gt;I don't use NAT on my SMB Cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 07:07:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201551#M10045</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2023-12-27T07:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201608#M10046</link>
      <description>&lt;P&gt;Clustering does this "NAT" by default.&lt;BR /&gt;It should also be settable in your software release via the CLI as well.&lt;BR /&gt;How precisely are you attempting to access the secondary member?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 14:18:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201608#M10046</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-27T14:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201609#M10047</link>
      <description>&lt;P&gt;1. I checked inside my SMB Cluster NAT settings:&lt;/P&gt;&lt;P&gt;perform-cluster-hide-fold: false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. I tried to access secondary cluster member via WAN or via one the LAN interfaces.&lt;/P&gt;&lt;P&gt;but it didn't work.&lt;/P&gt;&lt;P&gt;I am trying to find way to have access both of cluster members when the site to site is working.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 14:25:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201609#M10047</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2023-12-27T14:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201612#M10048</link>
      <description>&lt;P&gt;How are you attempting to perform this access?&lt;BR /&gt;Have you used tcpdump to see if the traffic is reaching the secondary member or not?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 14:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201612#M10048</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-27T14:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201617#M10049</link>
      <description>&lt;P&gt;Trying access via SSH / HTTPs&lt;/P&gt;&lt;P&gt;I can't used&amp;nbsp;&lt;SPAN&gt;tcpdump&amp;nbsp;on the&amp;nbsp;secondary member because I don't have access when site to site is working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I remove site to site I have access to both of the Cluster members via WAN interface.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 14:51:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201617#M10049</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2023-12-27T14:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201623#M10050</link>
      <description>&lt;P&gt;Might be worth TAC case or do remote session, sounds like something simple might be missing here.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 18:32:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201623#M10050</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-27T18:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201630#M10051</link>
      <description>&lt;P&gt;With the VPN in place, it would be expected for the traffic to traverse the primary node.&lt;BR /&gt;However, you should still be able to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Reach the primary node&lt;/LI&gt;
&lt;LI&gt;SSH from the primary node to the secondary node&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Are you able to do that?&lt;BR /&gt;I also think working with TAC on this would be advisable.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 19:06:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201630#M10051</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-27T19:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster - Management  Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201867#M10058</link>
      <description>&lt;P&gt;Ok thanks, I will check with TAC&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2024 07:24:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Management-Interface/m-p/201867#M10058</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2024-01-01T07:24:33Z</dc:date>
    </item>
  </channel>
</rss>

