<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster in Bridge mode in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199346#M9867</link>
    <description>&lt;P&gt;Also see in sk178604Check Point R81.10.X for 1500, 1600, and 1800 appliance Known Limitations and Resolved Issues:&lt;/P&gt;
&lt;TABLE id="LimitationsTable" class="footnote" style="table-layout: fixed; width: 100%;" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;TD&gt;If a bridge is configured on network interfaces, a cluster can only be created when the Quantum Spark appliance is Centrally Managed.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="background-color: #cccccc;"&gt;
&lt;TD colspan="4" style="text-align: center;"&gt;Networking - Bridge&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;BR /&gt;SMBGWY-2478&lt;/TD&gt;
&lt;TD&gt;Bridge interfaces cannot be disabled.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SMB-10543&lt;/TD&gt;
&lt;TD&gt;Embedded Gaia appliances conform to the Maintrain bridge (L2) limitations listed in &lt;A href="https://support.checkpoint.com/results/sk/sk101371" target="_blank" rel="noopener"&gt;sk101371&lt;/A&gt;&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SMB-12375&lt;/TD&gt;
&lt;TD&gt;Attempting to assign the pivot port of a switch to a bridge using the CLI fails, but does not display an error.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;Site-to-Site VPN is not supported with layer 2 (bridge) connection types.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;BR /&gt;SMBGWY-2443&lt;/TD&gt;
&lt;TD&gt;When more than one VAP is added to a local network switch or bridge, it cannot be unassigned.&lt;BR /&gt;&lt;BR /&gt;Workaround: delete it and then recreate it.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
    <pubDate>Thu, 30 Nov 2023 12:03:59 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-11-30T12:03:59Z</dc:date>
    <item>
      <title>Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/198510#M9825</link>
      <description>&lt;P&gt;How to deploy active/standby cluster in bridge mode on SMB 1800 appliances R81.10.08 centrally managed?&lt;/P&gt;&lt;P&gt;According to documentation:&amp;nbsp;A cluster in a Bridge Active/Standby mode is supported, but appliances are working only in Cluster Mode: High Availability (Active Up) with IGMP Membership.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 13:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/198510#M9825</guid>
      <dc:creator>LGRES</dc:creator>
      <dc:date>2023-11-21T13:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/198529#M9826</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Per the product documentation, you cannot create a &lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;cluster&lt;/SPAN&gt;&lt;SPAN&gt; when you have a switch or &lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight2"&gt;bridge&lt;/SPAN&gt;&lt;SPAN&gt; defined in the network settings on the appliance.&lt;BR /&gt;&lt;/SPAN&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Configuring-High-Availability.htm?Highlight=Cluster%20bridge" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Configuring-High-Availability.htm?Highlight=Cluster%20bridge&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 15:10:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/198529#M9826</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-21T15:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199021#M9835</link>
      <description>&lt;P&gt;How then to deploy cluster in bridge mode, if there is no cpconfig command in Gaia Embedded?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199021#M9835</guid>
      <dc:creator>LGRES</dc:creator>
      <dc:date>2023-11-27T13:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199027#M9836</link>
      <description>&lt;P&gt;Check this SK for configuring a&amp;nbsp; bridge cluster for centrally managed SMBs.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;A title="How to create a centrally managed cluster for Embedded Gaia SMB gateways" href="https://support.checkpoint.com/results/sk/sk138893" target="_self"&gt;How to create a centrally managed cluster for Embedded Gaia SMB gateways&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Since this is for R77.20.XX, also refer to the admin guide, though I believe there is not much difference between the versions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A title="Quantum Spark 1500, 1600, and 1800 Appliances R81.10.X Centrally Managed Administration Guide" href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Configuring-High-Availability.htm?Highlight=cluster" target="_self"&gt;Quantum Spark 1500, 1600, and 1800 Appliances R81.10.X Centrally Managed Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Also the alternative for cpconfig is enabling a specific kernel parameter in fwkern.conf in both members and reboot the gateway.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;fwha_active_standby_bridge_mode=1&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You can find this information in this SK as well.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A title="Cluster in Active-Standby bridge mode in 1200R / 1400 centrally managed appliances" href="https://support.checkpoint.com/results/sk/sk122659" target="_self"&gt;Cluster in Active-Standby bridge mode in 1200R / 1400 centrally managed appliances&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:12:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199027#M9836</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2023-11-27T14:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199165#M9854</link>
      <description>&lt;P&gt;The way I interpret this statement is that a cluster in bridge mode is not supported on SMB appliances.&lt;BR /&gt;I would confirm with TAC, though: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 15:00:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199165#M9854</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-28T15:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199173#M9855</link>
      <description>&lt;P&gt;Definitely one for TAC, the section beneath this (prerequisites) contains a contradictory statement.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 15:21:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199173#M9855</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-28T15:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199346#M9867</link>
      <description>&lt;P&gt;Also see in sk178604Check Point R81.10.X for 1500, 1600, and 1800 appliance Known Limitations and Resolved Issues:&lt;/P&gt;
&lt;TABLE id="LimitationsTable" class="footnote" style="table-layout: fixed; width: 100%;" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;TD&gt;If a bridge is configured on network interfaces, a cluster can only be created when the Quantum Spark appliance is Centrally Managed.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="background-color: #cccccc;"&gt;
&lt;TD colspan="4" style="text-align: center;"&gt;Networking - Bridge&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;BR /&gt;SMBGWY-2478&lt;/TD&gt;
&lt;TD&gt;Bridge interfaces cannot be disabled.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SMB-10543&lt;/TD&gt;
&lt;TD&gt;Embedded Gaia appliances conform to the Maintrain bridge (L2) limitations listed in &lt;A href="https://support.checkpoint.com/results/sk/sk101371" target="_blank" rel="noopener"&gt;sk101371&lt;/A&gt;&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SMB-12375&lt;/TD&gt;
&lt;TD&gt;Attempting to assign the pivot port of a switch to a bridge using the CLI fails, but does not display an error.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;-&lt;/TD&gt;
&lt;TD&gt;Site-to-Site VPN is not supported with layer 2 (bridge) connection types.&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;R81.10.00&lt;/TD&gt;
&lt;TD style="text-align: center;"&gt;-&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;BR /&gt;SMBGWY-2443&lt;/TD&gt;
&lt;TD&gt;When more than one VAP is added to a local network switch or bridge, it cannot be unassigned.&lt;BR /&gt;&lt;BR /&gt;Workaround: delete it and then recreate it.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 30 Nov 2023 12:03:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199346#M9867</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-11-30T12:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199408#M9868</link>
      <description>&lt;P&gt;Yes, my understanding is that a bridge mode cluster is possible in R81.10.XX if centrally managed, as well I have tested this in lab before.&lt;/P&gt;
&lt;P&gt;Maybe some SK's or the admin guide need to be updated, so it includes specific directions on how to configure a centrally managed bridge cluster &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 00:32:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199408#M9868</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2023-12-01T00:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199423#M9869</link>
      <description>&lt;P&gt;&lt;SPAN&gt;There is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk122659" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk122659: Cluster in Active-Standby bridge mode in 1200R / 1400 centrally managed appliances&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 08:46:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199423#M9869</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-01T08:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199425#M9870</link>
      <description>&lt;P&gt;...but the newest is mentioned in the table, &lt;STRONG&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk101371" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk101371: Bridge Mode on Gaia OS and SecurePlatform OS&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Should be named &lt;SPAN class="css-1tluag8"&gt;Gaia OS and Gaia Embedded, as shown as OS in the SK !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 09:17:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199425#M9870</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-01T09:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster in Bridge mode</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199426#M9871</link>
      <description>&lt;P&gt;Oh I meant by that currently it only mentions 1200R/1400 and not the current 1500/1600/1800s &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 09:44:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-in-Bridge-mode/m-p/199426#M9871</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2023-12-01T09:44:49Z</dc:date>
    </item>
  </channel>
</rss>

