- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Question for those whom have done VSLS deployments in R81.10
I have a deployment in works that I created 4 port LACP bonds for our core connections so that I don't loose a chassis as long as we have at least one link up.
What we found was while the bonds would stay up, the cluster would go down as soon as we lost more that one link in the bond.
I've found this section regarding clusterxl and bonding that I think fits:
While this 'feels' more related to traditionally load sharing mode, I wanted to check here if this also the same spot to update for a VSX VSLS deployment.
If thats the case and I have two bonds that I want to stay up in regards to ClusterXL as long as 1 of the 4 links is up, is this the edit?
****
cphaconf bond_ls set bond1 1
cphaconf bond_ls set bond3 1
***
If this is the correct setting, a couple of followups:
1) is this survivable for reboots, JHFs or major upgrades (i.e. R81.10 to R81.20).
- I believe reboot yes but not sure on the others
2) Once applied, is there any changes needed?
- The guide states policy install but is that it?
3) if i rollback, is it just "cphaconf bond_ls remove <bond#>" and push policy to have it go back to its default 'N-1' setting?
Got the same question to my professional service rep but trying to get a quick answer/conformation so we can get back to our validation testing. This isn't in production yet but my clock is ticking.....
Thanks everyone 🙂
Ok....thinking this is answered here 🙂
@Scottc98 yes you are correct, the default allows only one interface to fail in a BOND.
your questions:
1. yes to all for jumbo and hotfixes and for major upgrades. As long as you did in place upgrades.
2. Works without install policy.
3. Yes
I’ve done a similar discussion for MAESTRO environments minimum required intrerfaces for LACP bond
@Scottc98 configuration has to be done in every VS context. see Configuration in the $FWDIR/conf/cpha_bond_ls_config.conf file on VSX cluster member does not apply ...
Ok....thinking this is answered here 🙂
Thats exactly where its answered : - )
Andy
@Scottc98 yes you are correct, the default allows only one interface to fail in a BOND.
your questions:
1. yes to all for jumbo and hotfixes and for major upgrades. As long as you did in place upgrades.
2. Works without install policy.
3. Yes
I’ve done a similar discussion for MAESTRO environments minimum required intrerfaces for LACP bond
Ok....I have a follow up question:
Are these configs all done within vs0 or do i have to go into each VS where those bonds are used?
*****
*******
Bond 1 is my management network. After making these changes, I was able to down 3 of the 4 interfaces and keep VS0 active on the node.
Bond3 is used for VS1 VLAN networks. When I admin down more than 2 interfaces, its following the ns-1 default.
So do I need to do the following:
1) vsenv 1 to go into the VS
2) Then do the update for Bond 3: "cphaconf bond_ls set bond3 1"
I would also remove bond3 from the original file
So....end state, if i "cat $FWDIR/conf/cpha_bond_ls_config.conf" from VSO, i should only see the bond1
If i "cat $FWDIR/conf/cpha_bond_ls_config.conf " from VS1, I should only see bond3
Is that correct?
@Scottc98 configuration has to be done in every VS context. see Configuration in the $FWDIR/conf/cpha_bond_ls_config.conf file on VSX cluster member does not apply ...
Thanks @Wolfgang
Is it best to repeat the same config on each VS or break down the configs for only the interfaces servicing the VS(s)?
Bond1 for example will ONLY ever be used for VS0.
Alright.....this community ROCKS!
So to answer my last question: You can only add the interfaces on the non-VS0 VSs that has the bond assoicated to it. So since only bond1 in my case is configured as a VLAN trunk in my VS configs, it only accepts that.
And since you are creating the file from scratch on each VS, you will have to reboot the chassis as per the SK. For changing VS0 bonds only, you do not since the conf file already exists on the box.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 21 | |
| 10 | |
| 7 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Thu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY