<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R81.10.07 and 08 - Centrally managed ClusterXL with Vmac : G-ARP issues in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/192399#M9476</link>
    <description>&lt;P&gt;We have upgraded some centrally managed spark clusters from R81.10.00 to R81.10.07 to activate SDwan and run into some serious stability issues. The problem seems to only be related to Vmac in ClusterXL.&lt;/P&gt;&lt;P&gt;It looks like internet lines are flapping, but by doing some troubleshooting, we see the reply traffic arriving in the standby firewall.For some reason, the standby firewall is sending&amp;nbsp; gratuitous ARP messages for the VIP IP addresses, sent out with the VMAC as source. This broadcast message will trigger a change in the mac table of the switch, and traffic for the VIP is put on the wire of the standby firewall.&lt;/P&gt;&lt;P&gt;TAC case is created and confirmed to be an issue, other customers have also seen this behavior. Disabling vmac solves the issue, shutting down the standby firewall also !&lt;/P&gt;&lt;P&gt;Be aware when upgrading to this version when you have VMAC enabled ! R81.10.00 does not have the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Sep 2023 12:08:18 GMT</pubDate>
    <dc:creator>K_R_V</dc:creator>
    <dc:date>2023-09-12T12:08:18Z</dc:date>
    <item>
      <title>R81.10.07 and 08 - Centrally managed ClusterXL with Vmac : G-ARP issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/192399#M9476</link>
      <description>&lt;P&gt;We have upgraded some centrally managed spark clusters from R81.10.00 to R81.10.07 to activate SDwan and run into some serious stability issues. The problem seems to only be related to Vmac in ClusterXL.&lt;/P&gt;&lt;P&gt;It looks like internet lines are flapping, but by doing some troubleshooting, we see the reply traffic arriving in the standby firewall.For some reason, the standby firewall is sending&amp;nbsp; gratuitous ARP messages for the VIP IP addresses, sent out with the VMAC as source. This broadcast message will trigger a change in the mac table of the switch, and traffic for the VIP is put on the wire of the standby firewall.&lt;/P&gt;&lt;P&gt;TAC case is created and confirmed to be an issue, other customers have also seen this behavior. Disabling vmac solves the issue, shutting down the standby firewall also !&lt;/P&gt;&lt;P&gt;Be aware when upgrading to this version when you have VMAC enabled ! R81.10.00 does not have the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 12:08:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/192399#M9476</guid>
      <dc:creator>K_R_V</dc:creator>
      <dc:date>2023-09-12T12:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10.07 and 08 - Centrally managed ClusterXL with Vmac : G-ARP issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/192440#M9482</link>
      <description>&lt;P&gt;Thanks for the heads up.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 15:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/192440#M9482</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-12T15:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10.07 and 08 - Centrally managed ClusterXL with Vmac : G-ARP issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/202062#M10068</link>
      <description>&lt;P&gt;Problem is resolved in the latest R81.10.08 version. ( as from 1690 )&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/202062#M10068</guid>
      <dc:creator>K_R_V</dc:creator>
      <dc:date>2024-01-30T08:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10.07 and 08 - Centrally managed ClusterXL with Vmac : G-ARP issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/204989#M10218</link>
      <description>&lt;P&gt;frustrated that this fix has been out here for a while with no code release or no SK listing issue.&amp;nbsp; Just had a customer POC hit this, would have been nice to have known.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 18:43:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/204989#M10218</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2024-02-04T18:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10.07 and 08 - Centrally managed ClusterXL with Vmac : G-ARP issues</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/207372#M10310</link>
      <description>&lt;P&gt;It also seems to be resolved and documented in the R81.10.10 release :&lt;/P&gt;&lt;TABLE border="1" width="100%" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;SMBGWY-6348&lt;/TD&gt;&lt;TD&gt;Firewall&lt;/TD&gt;&lt;TD&gt;When you enable Virtual MAC (VMAC) mode on a centrally managed cluster, the standby member sends GARP packets.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 28 Feb 2024 15:40:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R81-10-07-and-08-Centrally-managed-ClusterXL-with-Vmac-G-ARP/m-p/207372#M10310</guid>
      <dc:creator>K_R_V</dc:creator>
      <dc:date>2024-02-28T15:40:41Z</dc:date>
    </item>
  </channel>
</rss>

