- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm setting up an Active/Standby Bridge with two bridge groups.
Bridge Group 1: Eth1 <> Eth2
Bridge Group 2: Eth3 <> Eth4
I can see the bridge interfaces when I create the gateway at SmartConsole. But when creating the cluster bridge interfaces aren't discovered.
First and foremost is this behaviour is normal?
How can I achieve segregated policy packages per bridge group?
Since the bridge interfaces are not available in the topology table, we can’t protect them against Anti-spoofing. Is there any method to achieve this?
This is normal and documented: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Gui...
Make sure the Bridge interface and Bridge subordinate interfaces are not in the Topology.
To have a different policy for each bridge, you will need to use VSX (putting each bridge in a separate VS).
See also (for various limitations): https://support.checkpoint.com/results/sk/sk101371
This is normal and documented: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Gui...
Make sure the Bridge interface and Bridge subordinate interfaces are not in the Topology.
To have a different policy for each bridge, you will need to use VSX (putting each bridge in a separate VS).
See also (for various limitations): https://support.checkpoint.com/results/sk/sk101371
Thank you @PhoneBoy
Once we have converted the cluster into an Active/Standby bridge mode is it recommended to use other interface types such as Bond/L3 along with the bridge interfaces?
You can use bonded interfaces with bridge mode, yes.
You can also have L3 interfaces, but note the limitation around Double Inspection: https://support.checkpoint.com/results/sk/sk172204
Specifically, make sure that traffic does not traverse both an L2 and an L3 interface.
Management traffic can do so with a configuration change: https://support.checkpoint.com/results/sk/sk105899
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY