Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sudipta140201
Participant

Specific Bond interface status down at VSX-Cluster(checkpoint 9300)

 

two checkpoint Gateway(9300)----VSX cluster between them 

we have created bond interface bond1.150 at checkpoint firewall..connected to 10G Arista switch(192.168.150.6) and Arista 1G switch(192.168.150.5) (At Arista LACP active mode configured)

Initially, the Arista 1G switch did not have IP routing enabled. After configuring IP routing, the Layer 2 issue was resolved, and the Check Point firewall was able to successfully ping 192.168.150.5.

However, we were still unable to reach the Arista 10G switch (192.168.150.6). During troubleshooting, we observed that the bond1 interface the port connecting 10G unreachable switch showed churned status in the output of cat /proc/net/bonding/bond1.

Based on our observations, it appeared that the Check Point firewall was blocking the bond interface connected to the 192.168.150.6 (10G) Arista switch, as the bond links were terminating on different physical switches rather than a single logical switch.

To eliminate this possibility, we modified the topology as follows:

Both Check Point firewall links were terminated on the 10G Arista switch.
The 10G Arista switch was then connected downstream to the 1G Arista switch.

Despite this topology change, the Check Point firewall was still unable to reach the new 10G Arista switch (192.168.150.6). We again verified the bond status using cat /proc/net/bonding/bond1 and observed that the port churned condition still existed.

For further testing, we removed the bond interface configuration from the Check Point firewall and disabled LACP on the 10G Arista switch. The firewall and the 10G Arista switch were then connected using a single physical interface. After this change, the interface eth1-05.150 came up successfully (cphaprob -a if), and communication between the Check Point firewall and the 10G Arista switch was established.

 

0 Kudos
7 Replies
Sudipta140201
Participant

Now after topology change,(i mean all links from two checkpoint firewalls terminated at Arista 10G switch only)..Now at cat /proc/net/bonding/bond1 no slave ports are in churned state...all working fine..only cphaprob -a if..bond 1.150 is down showing ....

I have done one trick in expert mode run#ip address show bond1.150 ..there is one private ip assigned already 192.168.196.53..Now i have one doubt...is not this ip conflicting with bond 1.150 ip ? can we delete this ip ?

 

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

When you say 10G switch, this is fibre or copper? Did you check all the layer 1 stuff - cables, SFPs, etc. What did the link states say?

When you created the interface, did you install the security policy? This is a necessary step for new interfaces on VSX. 

The 192.168.196 internal IP won't be conflicting with anything else mentioned here, and you can't edit or remove it, they are automatically assigned. The only way you can affect these is to change the whole Private Internal Network to a different /22 network. 

0 Kudos
Sudipta140201
Participant

10G switch means all the ports are of 10G....the port of switch connecting the firewall 10G port.
all the interfaces' state on and link state up.

but when checking cphaprob -a if ..bond1.150 ---Down... but no port in churned state....

 

 

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

OK so if the links are up but the bond is churned then it seems like an LACP issue, have you made sure all the LACP config is the same across both gateway and switch? You have two separate bonds on the switch, one per gateway? Are they both showing the same issue?

0 Kudos
Sudipta140201
Participant

Yes LACP at Arista switch in active mode(status-active)..at both firewall Bond config  same 802.3AD.config all correct..

yes i have two separate bonds one terminating at Firewall 1 and other one terminating at firewall 2.

At active firewall it is showing Down ,at secondary firewall  all bonds are up

I have observed one thing when running this command to check internal database #cat /config/db/initial  the bond interfaces contain checkpoint harcoded internal subnet ip 192.168.196.0/28..not the ip i have configured...so at cphaprob -a if bond interfaces contain my configured ip and internal database contains checkpoint internal subnet ip .is this not conflicting ?

 

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Those IPs aren't conflicting, they are the normal way VSX works. What you are observing there is expected. 

0 Kudos
Sudipta140201
Participant

there was bond interface issue.At downstream switch links from checkpoint firewall 1 and from checkpoint firewall 2 configured at same portchannel group.I have seperated,and created two port channel ,issue resolved.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events