- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I observe this situation pretty much every time I am on client's premises:
There are clustered gateways or VSX appliances in separate racks.
There is typically a single management appliance per-site with single Mgmt interface connected to the network, (not counting LOM and Console).
Is there any downside to creating a bonded interface, connecting it to two clustered switches located in separate racks and using it for administration?
This approach should help with the situation when connectivity to one of the switches is interrupted or if one of the switches is offline.
Your thoughts?
as long as it uses L2 not L3 bonding ... and 803.2ad (proper lacp) it all works. have had lots of scenarious with it inc. R80.10 where round-robin on L3 bonding collapsed. thats a big topic mate ... lots to mention too much for a single line ![]()
Thanks,
I am talking strictly about HA capability for management appliances, so active/standby only, no need for round-robin.
All of Check Point's SMS code is user-space processes, and thus has no direct visibility into how the underlying interfaces are configured at the Gaia OS level, as the kernel provides a layer of abstraction between processes and the underlying hardware. The gateway is a different story though since most of Check Point's inspection code resides in kernel space and can directly touch the underlying hardware.
Bonded interfaces should be no problem for a SMS assuming the bond itself is set up correctly in Gaia, and the bonding settings match the attached switches.
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
Thanks.
I've done it before using LACP HA mode, but not ever seeing it elsewhere was trying to see if there were any downsides to it.
DOWNSIDES
One 'downside' I see is the advanced planning, configuration and troubleshooting efforts required for LACP bonded interfaces. Another 'downside' is the perceived redundancy resulting from bonded interfaces, redundant PSUs, hard disk RAID.., while it's still only one chassis meaning no physical redundancy (separate racks, rooms), no harddisk dd dumps, no instant fallback solutions, limitations on redundant hard disks and PSU's that are only available on expensive high-end Smart-1 Appliances (225, 3050, 3150), and so on.
VIRTUALIZATION
I prefer running the SmartCenter as a VM host within VMware ESXi instead of maintaining a physical appliance. This allows for easy VM snapshots and reverts making it easy and safe to quickly test a new hotfix, migration, whatever.
MANAGEMENT HIGH AVAILABILITY
In cases where a physical management appliance has to meet advanced redundancy requirements, I recommend adding a secondary management appliance to get a real Management-HA solution.
Danny,
The advanced planning is hardly a downside: have you seen the T-Shirt with "Four weeks of coding can save two days of planning" sign on it:)
The bonded interfaces on management appliances by no means are the substitute for full Management HA, but simply are a means to improve per-site redundancy in case of the switch or connectivity failure.
I'm just looking at it from perspective of people investing in gateway redundancy and fail over capability on per-site basis, and helping them to achieve the same with management.
Personally, I am also a big fan of the flexibility afforded by VM implementation of management and in most instances it is also what I recommend.
But in cases where the client invests in 3050s with 256GB of RAM and other bells and whistles, the use of bonded interfaces may be warranted.
Thank you,
Vladimir
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY