Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
nabil_l
Participant
Jump to solution

MHO 140 Mgmt

Dear Team

I have single MHO 140 and Single Firewall Appliance with single Downlink. I want to use bond Port1/1/1(eth1-Mgmt1) and Port1/2/1(eth1-Mgmt2) to two different switch that are in stack. Can i do this or i need to connect only single Mgmt interface for SMS connection? If i can bond, can anyone please guide me the process, whether i need to configure in Orchestrator or where.

R81.20

Thank you

0 Kudos
1 Solution

Accepted Solutions
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

The Mgmt1 and Mgmt2 interfaces exist on the MHO, not the security group. You need to console into your SGM to configure the magg bond - and anything else on the security group. All SG bonding, IPs, everything is configured at the security group, not the MHO. 

View solution in original post

0 Kudos
7 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP
0 Kudos
nabil_l
Participant

Hello

 

I followed the steps mentioned in this article, i have already configured Security Gateway and i am able to access security Gateway IP to open GUI access. Then from MHO Cli clish i tried to configure bond but it only show Mgmt1 and Mgmt2 interface that is OOB interface, no eth1-Mgmt1 and eth1-Mgmt2 shown there that why i have posted in this forum.

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

To clarify what IP address are you accessing and which interface is it assigned to?

Note slave interfaces that already have an IP address / VLAN / Alias etc cannot be used without first reconfiguring them... are they assigned to the security group?

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_AdminGuide/Content/Topi... 

CCSM R77/R80/ELITE
0 Kudos
nabil_l
Participant

Hello,

Let me Clarify in Detail.

At first, I have Created security group with ip address 10.30.222.180 and i selected one gateway and one eth1-Mgmt1 and two uplink port 1/5/1 and 1/6/1 and it is working fine, Gecurity Group IP is visible in eth1-Mgmt1 interface and both uplink interface are visible when i access GUI from 10.30.222.180. Till now everything is fine. Now again i open MHO GUI with ip address 10.30.222.176 and in security group i add another eth1-Mgmt2 interface and again it is visiible on GUI opened through Security Group IP address. There are two interface visible now eth1-Mgmt1(10.30.222.180) and eth1-Mgmt2. Now i connect console cable to MHO and try to configure Bond of both Mgmt but not successful. Am i missing something or am i in wrong way to configure Bond for Mgmt, Please suggest.

 

Thank you

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

The Mgmt1 and Mgmt2 interfaces exist on the MHO, not the security group. You need to console into your SGM to configure the magg bond - and anything else on the security group. All SG bonding, IPs, everything is configured at the security group, not the MHO. 

0 Kudos
nabil_l
Participant

Hello,

You mean to say, to bond Interface 1/1/1 and 1/2/1 Physical Ports of MHO i need to console on Gateway Appliance(SGM) and from there i need to create bond for interfaces that are physically located on MHO?

0 Kudos
nabil_l
Participant

Hello, Got your point, sorry i missed Bond Configuration point no 3 of R81.20 Maestro Administrative Guide. Thank you for your response.

 

Thank you