- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I see the mention of the logical interfaces being used when VIPs belong to a different subnet and we have to use scopelocal to enable routing through the cluster members.
I am looking at one of my client's configs and am seeing default routes as well as internal static route configured with next hop logical interfaces.
According to our documentation this option should be "Use this option only if the next hop gateway has an unnumbered interface."
What does constitute an unnumbered interface from the cluster's perspective? I am pretty sure that there is an L3 switch downstream or a VLAN interface with IP.
Cluster does not complain about this setup, but I wander if it is an acceptable configuration.
Please share the wisdom.
Thank you,
Vladimir
That's what I was thinking may happen. I'll take a look at their arp cache tomorrow to see how it looks.
If the arp cache starts filling up, the Internet will appear to "not work." Ask me how I know 😬
Exactly! I have seen this situation too Dameon, enough that it got mentioned in my book:
I had a limited time to figure out what was going on on that cluster, but arp overflow did not appear to be the issue.
Running #arp -a | wc -l returned 711 on active cluster member and something like 19 on the standby.
This cluster was slated for the memory upgrade and redux in newly created R80.20 environment. I did change the next hop for the default route to the IP address.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 9 | |
| 9 | |
| 9 | |
| 6 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY