- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have recently made teh switch froma standalone 6700 firewall to a HA cluster of two 6700's
as part of this process we are also starting use the MGMT interface for ... management!!
Previously our management was set to our LAN interface eth1-04 (10GbE).
To complicate matters we are migrating to a new network during renovation construction.
The management network is 10.x.50.0/24 which we get to via a bond10 L3 interface (eth1-02 & eth1-03) that connects the the L3 of our core switch stack.
The problem I am facing is that the management interfaces of both cluster nodes is also on 10.x.50.0 network.
The managment interface for each node is set to Private. Sync is set to a seprate interface and dedicated for that purpose.
This is causing an inconsistent routing issue and traffic is being drop by the MGMT interface, others are going through the bond10 interface.>>>>>
ip route
..
10.x.50.0/24 dev Mgmt proto kernel scope link src 10.x.50.31
..
Wondering what other could be doing?
Is my only option be to disable this management port and use my LAN port instead like before and isolate with rules?
I am aware the licensing may need to be re-worked since I am using that IP for the license.
The Mgmt interface is 'just another interface' on the box, so you can't have it in the same subnet as another interface on there. It's also all part of the same routing table as everything else by default. If you want to separate routing you can look at MDPS or VSX but there's no harm in using one of the prod interfaces to manage the box, it's quite common and 100% supported.
The Mgmt interface is 'just another interface' on the box, so you can't have it in the same subnet as another interface on there. It's also all part of the same routing table as everything else by default. If you want to separate routing you can look at MDPS or VSX but there's no harm in using one of the prod interfaces to manage the box, it's quite common and 100% supported.
Thanks for the clarification. Looks like I am heading in "prod interface" direction.
That makes sense, I know lots of people doing it that way.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY