Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Balakrishna_Med
Explorer

Guidance Needed: R82 T34 ClusterXL Bridge Mode Causing Loops & Crashes

Hello Team,

We have recently deployed Check Point R82 Take 34 in bridge mode with ClusterXL (Active/Standby).

After a couple of hours, both gateways crashed. We observed:

  • Packet loops forming

  • Connections multiplying abnormally

When we reconfigured the cluster in Active/Active mode, everything worked as expected.

Environment data flow:

  • Perimeter firewall (Active/Passive) → Core switch (Active/Passive) → Check Point (Active/Active) → Aggregator switch

Additional details:

  • The firewall is operating in bridge mode.

  • On the core switch, STP is enabled, and it cannot be disabled on the ports connected to the Check Point appliances.

  • We are also noticing that SIP telephones restart every 1–1.5 hours, which seems to be related to this issue.

Request:
Could someone please guide me on the correct switch port configurations when connecting to Check Point in bridge mode? I want to avoid trial-and-error in the production environment.

Thanks in advance for your support.

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

ClusterXL bridge mode requires two or four switches per the documentation: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui... 

With a single switch, Active/Active + STP is likely your best option, at least based on what I've seen in the past.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events