<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In an HA environment disable CCP packet check on specific interfaces in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129374#M5748</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;After I posted my question, I found this article&lt;/P&gt;&lt;P&gt;An I forgot one important thing, this is an SMB cluster R80.20.15. The article belongs to R81. Is it applicable on SMB appliances as well?&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 07:13:51 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2021-09-14T07:13:51Z</dc:date>
    <item>
      <title>In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129312#M5743</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I want to disable or switch off the CCP packet check on specific interfaces. Only on 1 interface out of 8.&lt;/P&gt;&lt;P&gt;So if the CCP packet is not receiving on this interfaces, this will not cause cluster failover.&lt;/P&gt;&lt;P&gt;Is it possible somehow?&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 18:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129312#M5743</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-09-13T18:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129326#M5744</link>
      <description>&lt;P&gt;Yes just define the desired interfaces as Network Type "private" in the topology of the cluster object.&amp;nbsp; However I don't think you are allowed to present a cluster/virtual IP address when the interface is in this mode; the firewalls just use their dedicated fixed IP addresses on the private interface.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 19:29:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129326#M5744</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-09-13T19:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129349#M5746</link>
      <description>&lt;P&gt;You can configure the interface to only monitor the physical link rather than CCP packets:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/CXLG/Configuring-Link-Monitoring-on-Cluster-Interfaces.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/CXLG/Configuring-Link-Monitoring-on-Cluster-Interfaces.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 22:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129349#M5746</guid>
      <dc:creator>mcatanzaro</dc:creator>
      <dc:date>2021-09-13T22:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129372#M5747</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;Yes, this can be a solution, but I need to present 1 IP as gateway, so this can't be a solution.&lt;/P&gt;&lt;P&gt;An I forgot one important thing, this is an SMB cluster R80.20.15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 07:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129372#M5747</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-09-14T07:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129374#M5748</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;After I posted my question, I found this article&lt;/P&gt;&lt;P&gt;An I forgot one important thing, this is an SMB cluster R80.20.15. The article belongs to R81. Is it applicable on SMB appliances as well?&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 07:13:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129374#M5748</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-09-14T07:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129427#M5749</link>
      <description>&lt;P&gt;Not sure if you can do this on Gaia Embedded.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you guys move this to the SMB forum&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 17:07:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129427#M5749</guid>
      <dc:creator>mcatanzaro</dc:creator>
      <dc:date>2021-09-14T17:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129429#M5750</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/63263"&gt;@mcatanzaro&lt;/a&gt;&amp;nbsp;Done. It was not obvious from the start that this is an SMB issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 17:29:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129429#M5750</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-09-14T17:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129468#M5757</link>
      <description>&lt;P&gt;This is not possible on locally managed SMBs. On centrally managed, you can configure it: W&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;hen High Availability is disabled on the interface, the interface is considered non-monitored private (not part of the cluster configuration).&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="page" title="Page 23"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;See Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.30 Centrally Managed Administration Guide p.23&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 15 Sep 2021 08:04:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129468#M5757</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-15T08:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129474#M5759</link>
      <description>&lt;P&gt;You are right, Sorry about that&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 08:52:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129474#M5759</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-09-15T08:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129484#M5760</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, it is a centrally managed SMB cluster. If I set non-monitored private, it will cause lost the ability of the virtual IP which is really important in that two trunc interface.&lt;/P&gt;&lt;P&gt;I know the cluster prerequisites, which describes between cluster interfaces must be layer 2 connection....&lt;/P&gt;&lt;P&gt;In a nutshell:&lt;/P&gt;&lt;P&gt;There is a special device with two interfaces:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2021-09-15 11_04_42-Clipboard.png"&gt;&lt;img src="https://community.checkpoint.com/skins/images/D3A53FBAA6E620D132A32F0F15A3E42A/responsive_peak/images/image_not_found.png" alt="2021-09-15 11_04_42-Clipboard.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;On the special device (appliance) eth1 and eth2 is a linux bond trunc interface. This device is probing its default gateway on both interfaces. The traffic will flow on that IF, which receives the ARP answer faster.&amp;nbsp;&lt;BR /&gt;And no, I can't put an active device there (router, switch, etc.) It is prohibited.&lt;/P&gt;&lt;P&gt;This is a very special scenario&lt;/P&gt;&lt;P&gt;Any idea will appreciate&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 09:52:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129484#M5760</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-09-15T09:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129487#M5761</link>
      <description>&lt;P&gt;Open an SR# with TAC !&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 10:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129487#M5761</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-15T10:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: In an HA environment disable CCP packet check on specific interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129502#M5764</link>
      <description>&lt;P&gt;Done &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 11:56:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/In-an-HA-environment-disable-CCP-packet-check-on-specific/m-p/129502#M5764</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2021-09-15T11:56:07Z</dc:date>
    </item>
  </channel>
</rss>

