- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi to all,
I would like to replace my two Check Point 5100 with the 6200P I just purchased.
I installed the first 6200P, configured the network interfaces, connected the network cables of the standby node to the right interfaces, performed the SIC with management, modifying the cluster hardware from 5000 to 6000 (same R.81.20) and installed the policies.
Install policies works only without check mark "If installation fail do not install on that cluster" otherwise the installation fail.
The error refers some problem on the network interfaces that I can't identify, seem well configured.
I noticed that the "Sync" network interface ("Sync" on the 6200 and "eth1.7" on the 5100) is not marked as a trust interface on the 6200.
Could it be due to this? If so, how do I make it become a "trust"?
Thank you.
Regards
Great process to follow.
Andy
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216
Did you change the topology in the cluster object (and install policy after that)? You have to do this if interface names change (e.g. "Sync" vs "eth1.7").
Yes, the topology was changed and the policies were installed without the "if fails" flag.
I'll have to try power off the working 5100 as suggested by the previous post, but I don't want to do it remotely.
I'll try it as soon as I get back to the office.
Thank you.
I see what @Oliver_Fink is saying, topology has to match, make sure to do "get interfaces WITHOUT topology".
Andy
Done.
Smart console tells me that all ports except the sync port have been changed (pencil icon).
I checked them one by one and didn't notice any changes.
After that I installed the policies with the flag "if fails.." with same results, if I remove the flag "if fails.." the policies are installed.
Can you verify interfaces do match for new cluster?
Andy
Is the eth1.7 the lowest vlan on that trunk?
After powered off the 5100 the 6200P works like a charm without downtime.
No issue after the configuration of second 6200P, sync port it's now trusted and cluster xl working.
Thank you.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY