<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA on Spark Devices - No cluster IP required for Active/Inactive? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274375#M13809</link>
    <description>&lt;P&gt;Thank you. These are 1590 appliances, so I don't believe R82 is available for them currently.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Mar 2026 18:52:00 GMT</pubDate>
    <dc:creator>SnafuNL</dc:creator>
    <dc:date>2026-03-27T18:52:00Z</dc:date>
    <item>
      <title>HA on Spark Devices - No cluster IP required for Active/Inactive?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274369#M13806</link>
      <description>&lt;P&gt;Hello All&lt;/P&gt;&lt;P&gt;Looking for some clarification on how HA works on the Spark Device, specifically ones managed in Spark Management.&lt;/P&gt;&lt;P&gt;I haven't worked with HA in Check Point for about 10 years, back then each firewall needed it's own IP along with the Cluster IP. Today I was setting up HA on some Spark Management connected devices, and while configuring the primary member I made all the interfaces non-HA with the intent of setting them up after. After I had the peer configured and synced up, I noticed all the interface settings (including IPs) from the primary had came over to the peer (Inactive).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know configuring an HA interface with cluster and devices IPs is still an option, but does Check Point now offer a Active/Passive HA similar to say Palo Altos? So,&amp;nbsp;I enable monitor state on each of the primary's interfaces will the peer assume the primary's IP if it goes down&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 18:15:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274369#M13806</guid>
      <dc:creator>SnafuNL</dc:creator>
      <dc:date>2026-03-27T18:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: HA on Spark Devices - No cluster IP required for Active/Inactive?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274371#M13807</link>
      <description>&lt;P&gt;I believe that is how it indeed works for spark devices HA, not like typical clusterXL, where you do need separate IP addresses.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 18:23:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274371#M13807</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-27T18:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: HA on Spark Devices - No cluster IP required for Active/Inactive?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274372#M13808</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;It is still required to have an IP address on the separate interfaces along with cluster IP (total of 3 addresses per clustered interface). &lt;BR /&gt;On the LAN interfaces the IP on the interfaces should be routable. On the internet connections the IPs on the interfaces can be private (non routable), while the cluster IP should be routable.&lt;BR /&gt;We had few bugs with non-HA interfaces on R81.10.17 and this is probably why the interface IP was duplicated. Are you using R81.10.17? If yes, I recommend upgrading to R82.00.10.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 18:30:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274372#M13808</guid>
      <dc:creator>sigal</dc:creator>
      <dc:date>2026-03-27T18:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: HA on Spark Devices - No cluster IP required for Active/Inactive?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274375#M13809</link>
      <description>&lt;P&gt;Thank you. These are 1590 appliances, so I don't believe R82 is available for them currently.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 18:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274375#M13809</guid>
      <dc:creator>SnafuNL</dc:creator>
      <dc:date>2026-03-27T18:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: HA on Spark Devices - No cluster IP required for Active/Inactive?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274376#M13810</link>
      <description>&lt;P&gt;Btw, not sure if you had a chance to have a look at below?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-High-Availability.htm?tocpath=Managing%20the%20Device%7CConfiguring%20High%20Availability%7C_____0#Prerequisites" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-High-Availability.htm?tocpath=Managing%20the%20Device%7CConfiguring%20High%20Availability%7C_____0#Prerequisites&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 18:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274376#M13810</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-27T18:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: HA on Spark Devices - No cluster IP required for Active/Inactive?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274377#M13811</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Follow-up question - Cluster status Monitored. The Admin Guide says&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;This status is also called&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;private monitored&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;The physical interface on this&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cluster Member&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is not coupled with another interface on the other&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cluster Member&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;as in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;interface mode.&lt;/P&gt;&lt;P&gt;The interface's status is still monitored, and if a problem occurs, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cluster Member&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;fails over to the other&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cluster Member&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN class=""&gt;Does that mean fail over to the peer but the IP from the primary is not assumed?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 19:11:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274377#M13811</guid>
      <dc:creator>SnafuNL</dc:creator>
      <dc:date>2026-03-27T19:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: HA on Spark Devices - No cluster IP required for Active/Inactive?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274378#M13812</link>
      <description>&lt;P&gt;An interface can be configured to one of three cluster status:&lt;BR /&gt;1. Non-HA (private): each cluster member has its own IP address. When the interface goes down the cluster state is not affected&lt;BR /&gt;2. Monitored:&amp;nbsp;each cluster member has its own IP address. When the interface goes down the associated cluster member becomes down&lt;BR /&gt;3. Clustered (HA):&amp;nbsp;each cluster member has its own IP address + cluster IP address that is visible to the network.&amp;nbsp;When the interface goes down the associated cluster member becomes down&lt;/P&gt;
&lt;P&gt;Since you are using R81.10.17 you can only use the third option.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 19:29:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/HA-on-Spark-Devices-No-cluster-IP-required-for-Active-Inactive/m-p/274378#M13812</guid>
      <dc:creator>sigal</dc:creator>
      <dc:date>2026-03-27T19:29:56Z</dc:date>
    </item>
  </channel>
</rss>

