- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I have two gateways configured in a ClusterXL High Availability (HA) setup.
However, when I run the cphaprob -a if command, I notice that two interfaces (bond0.8 & bond0.2053) are showing as LS (Load Sharing) mode, and I’m not sure why.
I’ve checked the SmartConsole GUI but couldn’t find any option to change these interfaces from LS to HA mode.
there is no reason to have them in LS because they run very little traffic!
Could you please advise how to correct this?
cphaprob -a if
CCP mode: Manual (Unicast)
Required interfaces: 4
Required secured interfaces: 1
Interface Name: Status:
Sync (S) UP
Mgmt Non-Monitored
eth1-01 UP
bond0.8 (LS) UP
bond0.2053 (LS) UP
S - sync, HA/LS - bond type, LM - link monitor, P - probing
Virtual cluster interfaces: 21
eth1-01
bond0.5
bond0.50
bond0.8
bond0.25
bond0.49
bond0.10
bond0.47
bond0.50
bond0.27
bond0.55
bond0.90
bond0.2053
bond0.41
bond0.70
bond0.56
bond0.27
bond0.53
bond0.940
vpnt10
vpnt11
So I’m wondering when and why these interfaces were configured to operate in Load Sharing (LS) mode, and how I can reconfigure them back to High Availability (HA) mode.
show cluster state
Cluster Mode: High Availability (Active Up) with IGMP Membership
LS would be default (normal) for LACP / 802.3AD bonds I expect.
LS would be default (normal) for LACP / 802.3AD bonds I expect.
but all other vlan interfaces are in the same bond interface which is bond0, so why only interface bond0.8 and bond0.2053 are LS?
Can you send a screenshot?
you can see all interfaces belongs to same bond?!
bond0.5
bond0.50
bond0.8
bond0.25
bond0.49
bond0.10
bond0.47
bond0.50
bond0.27
bond0.55
bond0.90
bond0.2053
bond0.41
bond0.70
bond0.56
bond0.27
bond0.53
bond0.940
i had other gateway here my bad
Because only the highest & lowest VLANs are relevant to that part of the output as monitored by ClusterXL.
If anything is odd it's why bond0.5 doesn't show there.
so maybe it is vlan 5 i should investigate
I totally remember now the case I had with TAC while back about this. Below sk is what they gave me.
https://support.checkpoint.com/results/sk/sk92826
Hey brother,
I see what Chris mentioned, makes total sense, it would indicate type of bond, as per output as well. here is output from my lab
[Expert@CP-FW-01:0]# cphaprob -a if
CCP mode: Manual (Unicast)
Required interfaces: 4
Required secured interfaces: 1
Interface Name: Status:
eth0 (LM) UP
eth1 (LM) UP
eth2 (LM) UP
eth3 (S-LM) UP
S - sync, HA/LS - bond type, LM - link monitor, P - probing
Virtual cluster interfaces: 3
eth0 172.16.10.246
eth1 192.168.10.246
eth2 172.31.10.246
[Expert@CP-FW-01:0]#
Im sure if you change below option, it would show way you want it.
Don't change this without considering the switch side configs unless you want to break it.
802.3AD is the defacto standard for bonds.
Yep, forgot to mention that, super important!
So i am not going to change any.
i only wonder why only 2 interfaces are LS
Hey brother, please refer to the sk I sent, it would be 100% relevant here, as Chris indicated.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 18 | |
| 13 | |
| 12 | |
| 12 | |
| 10 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY