- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hey all,
Just playing about in my Lab and I've got two CP GW's running on ESXi with a Vswitch for the External interfaces, this then connects to a physical Cisco 3750 switch and is trunked to a Cisco 887 with a VDSL internet link. To make my life easier I configured RIPv2 and this works well in the sense my CP's have internet access without messing about with routes.
However my ClusterXL now shows that ClusterXL has a problem on the standby node:
|
Is the error, if I flip the cluster nodes then it goes to the other node. If I check the routes no RIP routes show on the standby node. I then thought ah maybe its because its not using the VIP so I ticked the Virtual Address box on the RIP interface setup but that just broke everything (I think I then read that is for VRRP not ClusterXL?)...
Anyone had this before, its not a game changer for my studying as my lab still works but a tad annoying.
Thanks,
Charles
Please check if you are using vMAC in the ClusterXL properties and if not, try enabling it.
Hey,
Sorry forgot about that setting I meant to go back and look at that after this..
https://community.checkpoint.com/thread/7328-interface-bonding-problem
You'll be glad to know I've got rid of VirtualBox & GNS3 and I'm not running a full Cisco Stack with ESXi hosting my CP's and its a million times better!
I'll investigate vMAC and report back!
Thanks,
Charles
Next to that make sure that you have set you clustering to broadcast as multicast is by default not allowed on these VM Vswitches. Or on the ports make sure to disable all security features, especially when you are working with vMAC.
Ah ok that makes sense.. I've changed over to Broadcast and lost all my routes.... tried to change RIPv2 to Broadcast on my Cisco Router and I need a firmware upgrade (typical ha!) the command doesn't exist so I've put it back and will tackle upgrading that firmware tomorrow far too late in the day now!
Thanks for the extra information! Everyday's a school day!
Charles
To your question " I think I then read that is for VRRP not ClusterXL?". It also works with VRRP.
Gaia supports the advertising of the virtual IP address of the VRRP Virtual Router. You can
configure RIP to avertise the virtual IP address rather than the actual IP address of the interface . If you enable this option, RIP runs only on the master of the Virtual Router; on a failover, RIP stops running on the old master and then starts running on the new master. A traffic break might occur during the time it takes both the VRRP and RIP protocols to learn the routes again. The larger the network, the more time it would take RIP to synchronize its database and install routes again.
Regards
Heiko
Hey Heiko,
Thanks for replying as you can tell fairly new to CP.
You mentioned "Gaia supports the advertising of the virtual IP address of the VRRP Virtual Router" sorry just to confirm is this feature only for VRRP then? It doesn't work on ClusterXL does it?
VRRP is the older method of High Availability I believe isn't it?
Thanks,
Charles
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY