- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Dear All,
After we add a new trunk between Checkpoint Firewall and a Cisco L2 switch.
We found Check Point could not learn this VLAN Device MAC at ARP. The Check Point OS version is GAIA R80.40.
How we resolve this problem.
Thanks for a lot.
Can you please share more detail of the environment - Is the gateway (appliance model?) configured as a standard cluster or for VSX and what JHF is applied?
How is the trunk port configured on the Cisco, is it also a bond?
Hi Chris,
1. No VSX, only HA.
2. The gateway is 16200.
3. The GAiA OS is R80.40 with JFH Take 118.
4. The trunk is use interface bond.
LACP is used for the bond on both sides and cabling has been verified?
Please share the output of:
[Expert@HostName:0]# cat /proc/net/bonding/bondX
Note: Updating to a recent JHF is also recommended where possible.
Hi Sir,
Others VLAN trunk was normally, but when we create a new. We see this problem.
I will try to output cat /proc/net/bonding/bondX for you.
But we can see gateway interface Mac on local device. Why we can not see local device's Mac on gateway.
Are you on the active or standby gateway and what do you see in the ARP table if you do a broadcast ping or similar?
Hi Chris,
We can ping local device from firewall. But not see Mac at ARP.
But other VLAN trunk is normally,
Hi Chris,
Should we turn off/on the VLAN interface on gateway? If it will not influence other VLAN traffic.
I would suggest to contact TAC !
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY