- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi all,
Here we have a CP6200p NGFW, i set a bond group to connect with Cisco switch, below is the configurations on both Checkpoint & Cisco side.
Cisco:
interface Port-channel2
switchport access vlan 254
switchport mode access
interface TenGigabitEthernet1/0/11
switchport access vlan 254
switchport mode access
channel-protocol lacp
channel-group 2 mode active
interface TenGigabitEthernet2/0/11
switchport access vlan 254
switchport mode access
channel-protocol lacp
channel-group 2 mode active
Checkpoint:
My question is: after setting, i found there is only one link member is active, is it normal? or are there anything that i setup wrong? please advise, thanks a lot.
Once a port goes into a suspended state due to a configuration mismatch, I don't believe it will try to recover on its own (kind of like errdisable). It is possible a mismatch was detected when you were still setting things up, try a shut/no shut on Te1/0/11 and see what happens. If it goes right back to a suspended state, do a show log which should have an error message showing the suspension reason.
Hello Oliver,
Is there any particular reason to leave "Transmit Hash Policy" to Layer 2 instead of Layer 3+4? Could you also send the result from command: cat /proc/net/bonding/bond10
Hi Nickel,
Actually no other particular reason, i just use the default settings in Advanced Option.
Hi Nickel,
Thank you for your reply first.
In fact, we don't have any particular reason to set that, the screenshot above(Bond group advanced option) is the default settings when i configuring ether-channel on CP side.
Once a port goes into a suspended state due to a configuration mismatch, I don't believe it will try to recover on its own (kind of like errdisable). It is possible a mismatch was detected when you were still setting things up, try a shut/no shut on Te1/0/11 and see what happens. If it goes right back to a suspended state, do a show log which should have an error message showing the suspension reason.
Thank you very much Timothy_Hall, i tried your suggestion, and then the portchannel came back normally.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY