- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi,
I have two gateways configured in a ClusterXL High Availability (HA) setup.
However, when I run the cphaprob -a if command, I notice that two interfaces (bond0.8 & bond0.2053) are showing as LS (Load Sharing) mode, and I’m not sure why.
I’ve checked the SmartConsole GUI but couldn’t find any option to change these interfaces from LS to HA mode.
there is no reason to have them in LS because they run very little traffic!
Could you please advise how to correct this?
cphaprob -a if
CCP mode: Manual (Unicast)
Required interfaces: 4
Required secured interfaces: 1
Interface Name: Status:
Sync (S) UP
Mgmt Non-Monitored
eth1-01 UP
bond0.8 (LS) UP
bond0.2053 (LS) UP
S - sync, HA/LS - bond type, LM - link monitor, P - probing
Virtual cluster interfaces: 21
eth1-01
bond0.5
bond0.50
bond0.8
bond0.25
bond0.49
bond0.10
bond0.47
bond0.50
bond0.27
bond0.55
bond0.90
bond0.2053
bond0.41
bond0.70
bond0.56
bond0.27
bond0.53
bond0.940
vpnt10
vpnt11
So I’m wondering when and why these interfaces were configured to operate in Load Sharing (LS) mode, and how I can reconfigure them back to High Availability (HA) mode.
show cluster state
Cluster Mode: High Availability (Active Up) with IGMP Membership
LS would be default (normal) for LACP / 802.3AD bonds I expect.
LS would be default (normal) for LACP / 802.3AD bonds I expect.
but all other vlan interfaces are in the same bond interface which is bond0, so why only interface bond0.8 and bond0.2053 are LS?
Can you send a screenshot?
you can see all interfaces belongs to same bond?!
bond0.5
bond0.50
bond0.8
bond0.25
bond0.49
bond0.10
bond0.47
bond0.50
bond0.27
bond0.55
bond0.90
bond0.2053
bond0.41
bond0.70
bond0.56
bond0.27
bond0.53
bond0.940
i had other gateway here my bad
Because only the highest & lowest VLANs are relevant to that part of the output as monitored by ClusterXL.
If anything is odd it's why bond0.5 doesn't show there.
so maybe it is vlan 5 i should investigate
I totally remember now the case I had with TAC while back about this. Below sk is what they gave me.
https://support.checkpoint.com/results/sk/sk92826
Hey brother,
I see what Chris mentioned, makes total sense, it would indicate type of bond, as per output as well. here is output from my lab
[Expert@CP-FW-01:0]# cphaprob -a if
CCP mode: Manual (Unicast)
Required interfaces: 4
Required secured interfaces: 1
Interface Name: Status:
eth0 (LM) UP
eth1 (LM) UP
eth2 (LM) UP
eth3 (S-LM) UP
S - sync, HA/LS - bond type, LM - link monitor, P - probing
Virtual cluster interfaces: 3
eth0 172.16.10.246
eth1 192.168.10.246
eth2 172.31.10.246
[Expert@CP-FW-01:0]#
Im sure if you change below option, it would show way you want it.
Don't change this without considering the switch side configs unless you want to break it.
802.3AD is the defacto standard for bonds.
Yep, forgot to mention that, super important!
So i am not going to change any.
i only wonder why only 2 interfaces are LS
Hey brother, please refer to the sk I sent, it would be 100% relevant here, as Chris indicated.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 41 | |
| 26 | |
| 13 | |
| 13 | |
| 12 | |
| 11 | |
| 11 | |
| 9 | |
| 8 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY