- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi,
I have an 1gb interface (eth5) that I would like to migrate as a vlan interface to an existing bond of two 10g interfaces (bond101.1).
I would like to know which steps exactly should I take to do so. It is a clusterXL, so it needs to be done on both members.
I saw some posts regarding this, but they are a little bit different from each other and old, so I would like to know which is the best option to do this today.
We are using R81.10, management is R81.20.
Thanks.
Is this a coincidence or extension of this discussion?
Is this a coincidence or extension of this discussion?
Pure coincidence 😂
Thanks!
I would definitely follow process Bob Zimmerman posted in the link Chris referenced, it works 100%.
Andy
For reference, here's the direct link:
The short explanation is that ClusterXL supports backing a cluster interface with a different logical interface on each member (e.g, you can have member 1 back the cluster VIP with eth5, then have member 2 back it with bond101.1). This isn't a common configuration, so I wouldn't leave it that way for more than a few hours.
Longer works fine, people just don't know what they're looking at when troubleshooting, and confusion extends outages.
One part that is missing for me is the dhcp relay part.
Probably should be configured between step 2 to 4.
Yeah, step 3 should really be "bring all the config over from the old interface to the new interface". DHCP relay, proxy ARP, interface-local routes (used for off-net VIPs, like how VSX works), and so on.
Thanks
One last question - it seems to me there is no downtime by following your method, am i correct?
Thats what I gather as well, though never personally tried it, but maybe @Bob_Zimmerman can say for sure.
There shouldn't be any downtime, but there may be PNOTEs and failovers. After all, you're changing the logical interfaces being monitored. This is why the process includes pinning the member down administratively until you're done with it and ready to fail over.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 9 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 3 | |
| 3 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY