<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Advertise (dual) WAN via BGP in ClusterXL in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Advertise-dual-WAN-via-BGP-in-ClusterXL/m-p/242344#M12147</link>
    <description>&lt;P&gt;Hi guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was having issues with a ClusterXL set-up and wanted to know if there is a solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So here is what currently is correctly working (non-clusterXL):&amp;nbsp;&lt;/P&gt;&lt;P&gt;- device: 1575 appliance, R81.10.15_996003919 (.10 build doesn't support loopback yet via GUI)&lt;/P&gt;&lt;P&gt;- firewallrules to allow BGP&lt;/P&gt;&lt;P&gt;- single WAN interface has a /31 public IP from the provider.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- loopback interface with /28 from provider that is advertised on BGP back to peer on WAN.&lt;/P&gt;&lt;P&gt;- a dorment (not connected) second WAN connection on different carrier with /31 public IP in same BGP set-up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last week we wanted to add a second firewall. This stopped working even BEFORE the member device was added.&lt;/P&gt;&lt;P&gt;Here is what we did:&lt;/P&gt;&lt;P&gt;- reset WAN interfaces to DHCP to bypass subnet restrictions on the HA wizard (seems it needs at least 3 usable IPs on all interfaces without DHCP, even if you are not going to use it. Else the wizard won't finish).&lt;/P&gt;&lt;P&gt;- set first device as primary cluster member with only LAN/internal interfaces in HA mode&lt;/P&gt;&lt;P&gt;- readded WAN interface /31 set-up (this is non-HA)&lt;/P&gt;&lt;P&gt;Now the problem is that "BGP peer is not reachable" (/var/log/routed). Even though only internal networks are now HA.&lt;/P&gt;&lt;P&gt;It seems that the non-HA interface is no longer used for advertising the BGP route. Mind you, the default gateway is still there and ANY other traffic is passed. Just not training data for the BGP.&lt;/P&gt;&lt;P&gt;When you Delete the cluster configuration it magically starts working again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second (less important for now) thing is that we have 2 /31 lines. So my thoughts were to add both to both firewalls (non-HA ofcourse) and leave one disconnected on the devices so that the firewall only uses one and the active firewall advertises on the connected one. This since the HA set-up needs at least 3 usable IP-adresses for the HA.&lt;/P&gt;&lt;P&gt;- second device:&amp;nbsp;1575 appliance, R81.10.15_996003919 (.10 build doesn't support loopback yet)&lt;/P&gt;&lt;P&gt;- loopback interface with /28 from provider that is advertised on BGP back to peer on WAN.&lt;/P&gt;&lt;P&gt;- firewall rules to allow SYNC traffic&lt;/P&gt;&lt;P&gt;- add as member to the cluster group&lt;/P&gt;&lt;P&gt;- WAN interface has a /31 public IP from the primary line&amp;nbsp;&lt;/P&gt;&lt;P&gt;- DMZ interface has a /31 public IP from other line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2025 08:15:44 GMT</pubDate>
    <dc:creator>bjbakker1984</dc:creator>
    <dc:date>2025-02-26T08:15:44Z</dc:date>
    <item>
      <title>Advertise (dual) WAN via BGP in ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Advertise-dual-WAN-via-BGP-in-ClusterXL/m-p/242344#M12147</link>
      <description>&lt;P&gt;Hi guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was having issues with a ClusterXL set-up and wanted to know if there is a solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So here is what currently is correctly working (non-clusterXL):&amp;nbsp;&lt;/P&gt;&lt;P&gt;- device: 1575 appliance, R81.10.15_996003919 (.10 build doesn't support loopback yet via GUI)&lt;/P&gt;&lt;P&gt;- firewallrules to allow BGP&lt;/P&gt;&lt;P&gt;- single WAN interface has a /31 public IP from the provider.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- loopback interface with /28 from provider that is advertised on BGP back to peer on WAN.&lt;/P&gt;&lt;P&gt;- a dorment (not connected) second WAN connection on different carrier with /31 public IP in same BGP set-up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last week we wanted to add a second firewall. This stopped working even BEFORE the member device was added.&lt;/P&gt;&lt;P&gt;Here is what we did:&lt;/P&gt;&lt;P&gt;- reset WAN interfaces to DHCP to bypass subnet restrictions on the HA wizard (seems it needs at least 3 usable IPs on all interfaces without DHCP, even if you are not going to use it. Else the wizard won't finish).&lt;/P&gt;&lt;P&gt;- set first device as primary cluster member with only LAN/internal interfaces in HA mode&lt;/P&gt;&lt;P&gt;- readded WAN interface /31 set-up (this is non-HA)&lt;/P&gt;&lt;P&gt;Now the problem is that "BGP peer is not reachable" (/var/log/routed). Even though only internal networks are now HA.&lt;/P&gt;&lt;P&gt;It seems that the non-HA interface is no longer used for advertising the BGP route. Mind you, the default gateway is still there and ANY other traffic is passed. Just not training data for the BGP.&lt;/P&gt;&lt;P&gt;When you Delete the cluster configuration it magically starts working again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second (less important for now) thing is that we have 2 /31 lines. So my thoughts were to add both to both firewalls (non-HA ofcourse) and leave one disconnected on the devices so that the firewall only uses one and the active firewall advertises on the connected one. This since the HA set-up needs at least 3 usable IP-adresses for the HA.&lt;/P&gt;&lt;P&gt;- second device:&amp;nbsp;1575 appliance, R81.10.15_996003919 (.10 build doesn't support loopback yet)&lt;/P&gt;&lt;P&gt;- loopback interface with /28 from provider that is advertised on BGP back to peer on WAN.&lt;/P&gt;&lt;P&gt;- firewall rules to allow SYNC traffic&lt;/P&gt;&lt;P&gt;- add as member to the cluster group&lt;/P&gt;&lt;P&gt;- WAN interface has a /31 public IP from the primary line&amp;nbsp;&lt;/P&gt;&lt;P&gt;- DMZ interface has a /31 public IP from other line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 08:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Advertise-dual-WAN-via-BGP-in-ClusterXL/m-p/242344#M12147</guid>
      <dc:creator>bjbakker1984</dc:creator>
      <dc:date>2025-02-26T08:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Advertise (dual) WAN via BGP in ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Advertise-dual-WAN-via-BGP-in-ClusterXL/m-p/242453#M12148</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;R81.10.15 does not yet support loopback in cluster mode. This functionality is currently planned for Q2.&lt;BR /&gt;As for the 3 usable IP addresses for the HA - this is no longer correct. You can use private IPs for the physical interfaces on each gateway and routable IP as VIP. See&amp;nbsp;&lt;A href="https://protect.checkpoint.com/v2/r02/___https:/sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-High-Availability.htm?tocpath=Managing%20the%20Device%7CConfiguring%20High%20Availability%7C_____10%23Single_Routable_IP_Cluster___.YzJlOmNwYWxsOmM6bzpjZjI2MGMzNWFkOGE0YWNjNzQ5OTk5MjExZjcxOWJmMjo3OjlhOTI6NDAyMjM2NWMwZDI1ZGE5OGI0NWMzM2E2YWRjY2ZiM2MwNjRkMTlhYjJiNjcxMzljOWMxMmI4MGQ4N2ZlMmQ1NTpoOlQ6Tg" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-High-Availability.htm?tocpath=Managing%20the%20Device%7CConfiguring%20High%20Availability%7C_____10#Single_Routable_IP_Cluster&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 16:57:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Advertise-dual-WAN-via-BGP-in-ClusterXL/m-p/242453#M12148</guid>
      <dc:creator>sigal</dc:creator>
      <dc:date>2025-02-26T16:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Advertise (dual) WAN via BGP in ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Advertise-dual-WAN-via-BGP-in-ClusterXL/m-p/243155#M12172</link>
      <description>&lt;P&gt;Hi Sigal,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply and advise. I will go testing this when the next opportunity presents itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 10:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Advertise-dual-WAN-via-BGP-in-ClusterXL/m-p/243155#M12172</guid>
      <dc:creator>bjbakker1984</dc:creator>
      <dc:date>2025-03-06T10:36:03Z</dc:date>
    </item>
  </channel>
</rss>

