I am deploying a pair of Check Point Firewalls running R81.20 JHF t76 in ClusterXL Active/Standby Bridge Mode between 2 pairs of stacked switches. The firewall interfaces are connected to each switch stack using a pair of LACP bonds. The adjacent switch stacks use VPC to connect to the firewall's bonds and trunk several VLANs running STP. A basic image of the topology is attached.
What would be the appropriate way to configure the CPFWs so that the STP BPDUs generated by the switches can traverse the bridge? Should the bonds be configured with sub-interfaces for each of the VLANs that the switches are trunking? I believe this would be required in order to maintain VLAN separation and enable the switches to perform the root bridge election process.
The R81.20 Installation and Upgrade Guide page for ClusterXL in Active/Standby Bridge Mode states that the "best practice" is to disable STP on the adjacent switches, but it is unclear to me why this recommendation exists or how this topology would be expected to function without it.
I have inquired the same with TAC in SR 6-0004219095 but would appreciate any second opinions from this audience.