Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LGRES
Explorer

Cluster in Bridge mode

How to deploy active/standby cluster in bridge mode on SMB 1800 appliances R81.10.08 centrally managed?

According to documentation: A cluster in a Bridge Active/Standby mode is supported, but appliances are working only in Cluster Mode: High Availability (Active Up) with IGMP Membership.

0 Kudos
10 Replies
PhoneBoy
Admin
Admin

Per the product documentation, you cannot create a cluster when you have a switch or bridge defined in the network settings on the appliance.
See: https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Co...

 

0 Kudos
LGRES
Explorer

How then to deploy cluster in bridge mode, if there is no cpconfig command in Gaia Embedded?

0 Kudos
Tom_Hinoue
Advisor
Advisor

Check this SK for configuring a  bridge cluster for centrally managed SMBs.

How to create a centrally managed cluster for Embedded Gaia SMB gateways 

Since this is for R77.20.XX, also refer to the admin guide, though I believe there is not much difference between the versions.

Quantum Spark 1500, 1600, and 1800 Appliances R81.10.X Centrally Managed Administration Guide 


Also the alternative for cpconfig is enabling a specific kernel parameter in fwkern.conf in both members and reboot the gateway.

fwha_active_standby_bridge_mode=1

You can find this information in this SK as well.

Cluster in Active-Standby bridge mode in 1200R / 1400 centrally managed appliances 

G_W_Albrecht
Legend Legend
Legend

Also see in sk178604Check Point R81.10.X for 1500, 1600, and 1800 appliance Known Limitations and Resolved Issues:

- If a bridge is configured on network interfaces, a cluster can only be created when the Quantum Spark appliance is Centrally Managed. R81.10.00 -
Networking - Bridge

SMBGWY-2478
Bridge interfaces cannot be disabled. R81.10.00 -
SMB-10543 Embedded Gaia appliances conform to the Maintrain bridge (L2) limitations listed in sk101371 R81.10.00 -
SMB-12375 Attempting to assign the pivot port of a switch to a bridge using the CLI fails, but does not display an error. R81.10.00 -
- Site-to-Site VPN is not supported with layer 2 (bridge) connection types. R81.10.00 -

SMBGWY-2443
When more than one VAP is added to a local network switch or bridge, it cannot be unassigned.

Workaround: delete it and then recreate it.
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
Tom_Hinoue
Advisor
Advisor

Yes, my understanding is that a bridge mode cluster is possible in R81.10.XX if centrally managed, as well I have tested this in lab before.

Maybe some SK's or the admin guide need to be updated, so it includes specific directions on how to configure a centrally managed bridge cluster 🙂

0 Kudos
G_W_Albrecht
Legend Legend
Legend

There is:

sk122659: Cluster in Active-Standby bridge mode in 1200R / 1400 centrally managed appliances

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
G_W_Albrecht
Legend Legend
Legend

...but the newest is mentioned in the table, sk101371: Bridge Mode on Gaia OS and SecurePlatform OS

Should be named Gaia OS and Gaia Embedded, as shown as OS in the SK !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Tom_Hinoue
Advisor
Advisor

Oh I meant by that currently it only mentions 1200R/1400 and not the current 1500/1600/1800s 🙂

0 Kudos
PhoneBoy
Admin
Admin

The way I interpret this statement is that a cluster in bridge mode is not supported on SMB appliances.
I would confirm with TAC, though: https://help.checkpoint.com 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Definitely one for TAC, the section beneath this (prerequisites) contains a contradictory statement.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events