- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Just noticed it recently during initial configuration of R80.10 Cluster: there is no cluster ID field in the first time configuration wizard.
Can someone clarify if there is now a different mechanism resolving same ID issues and how doe it deal with clusters already present in the infrastructure with IDs defined?
Thank you,
Vladimir
Hi,
From R80.10 onwards there is indeed a new algorithm which does automatic selection for the MAC magic.
The procedure is explained in sk25977 under (III-1-E) Change Source MAC Addresses - Gateway Mode - Gaia R80.10 - Procedure.
Kr,
Nick
I guess the old "magic" number sk25977 explains what's changed and how it was applied before R80.10
I don't want to copy any details here as it's quite long article ![]()
Kaspars,
It is hard for me to believe that CP would on purpose remove the cluster id feature and will force the old method on us.
Likely, some new mechanism is in place and I am trying to determine what it is.
Thank you Kaspars and Nick!
I've just finished reading through the SK and have found the R80.10 section in it, sorry for not spotting it earlier.
From sk25977:
qoute
Starting in Gaia R80.10, the 5th byte of the Source MAC address (MAC magic) in all types of CCP packets is assigned automatically.
During the initial configuration of the cluster members, they apply the following algorithm to set the MAC magic value:...
unqoute
When does the "initial configuration" happen? Is it when I run the FTW on the device (at this time I have not yet configured all interfaces) or is it the fist time I push a policy to the gateways, where they are part of a cluster? This is important as I have to share one VLAN with another existing CheckPoint ClusterXL setup.
If it is when I push the policy, can I be sure that the gateway (even if I enable clusterXL in the FTW) will not interfere with the other cluster(s) even if I configure and enable all interfaces? In that case it is important the the shared VLAN is connected to the new cluster first time I push the policy, so the other cluster's CCP traffic can be detected...
Thanks in advance.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY