- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear mates,
I’m in charge of replacing a cluster of 12600 configured in VRRP and running R80.20 to a new cluster of 6600 running R81.10. From experience of hardware replacement, and after reading some posts here, I think of doing the following:
Usually I don’t really think of ARP issue because of the VMAC feature of ClusterXL but being new to VRRP, I’m having seconds thoughts.
On the router side, on the PortChannel of the 12600 I see the following mac addresses :
Am I wrong on the analysis ? Is there some things I should verify before/after the switch of the cluster ?
Any tips will be appreciated.
Thanks.
What about the SMS ?
Hi,
Management is done through a MDSM already running R81.10.
Hi,
So the new cluster will also be VRRP or are you going for ClusterXL on the new setup?
If you stay with VRRP and use the same VRRP router ID, the virtual MAC for the virtual IP's should not change.
ClusterXL by default uses the MAC of the active member, but with VMAC you can change this if you like.
Yes, the MAC of the bonding group will change, but if you are going for VRRP or VMAC that should not be a problem for the virtual IP's. But in these cases it is always good to know how to send a G-ARP to clear ARP tables. Just in case. Or have access to routers to clear the ARP table on those devices.
Note the current MAC for virtual IP's and compare them after the change.
And with hardware swap, check if local.arp files are created for static NAT.
Martijn
Hi Martijn,
Thanks for your reply.
I’ll Keep VRRP as it’s a customer’s request, with the same configuration so VRIDs will be the same.
I found this post about sending garp from the Check Point https://community.checkpoint.com/t5/Security-Gateways/How-to-send-G-ARP-manually/td-p/69895 seems usefull, but I might just do it from the router side.
I really believe below process would be best for you.
Andy
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY