Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sony_James
Participant
Participant

Checkpoint Bridge mode

Checkpoint Firewall Cluster with OS version R81.10 with Latest Jumbo Hotfix installed

Topology

Internet Router --> L2 Switch (Internet Side)--> Checkpoint in Bridge mode --> Trent Micro IPS -- L2 Switch (LAN Side)

The deployment is successful but we are seeing MAC flapping messages on Internet L2 Switch for Router MAC.

Reason for MAC flap is Router MAC is getting Learned on Checkpoint connected port also. For resolving the issue we put static MAC entry on switch side. 

For troubleshooting the issue we have taken capture on switch Firewall port and switch but we are not able to find the problematic MAC broadcast or ARP reply from Checkpoint interfaces. 

Any suggestion how to troubleshot further

0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

How is the L2 / STP elements of this topology configured?

CCSM R77/R80/ELITE
0 Kudos
Sony_James
Participant
Participant

On switch Side STP is enabled and we tried to disable also still same issue.

the switch Interface configured for Checkpoint connectivity is trunk port with Vlan 400 and 100 is passing through it. On checkpoint side we have not configured Vlan interface for bride. we have added physical interface on Checkpoint Bridge 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events