- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Have an issue with VLAN subinterfaces not participating in HA.
R80.10, HW 6500 qty 2 running in active/active
I've got 3 VLAN subinterfaces on eth1-04:
eth1-04.200
eth1-04.300
eth1-04.500
Prior to yesterday, eth1-04.200 and eth1-04.300 were the only existing subinterfaces and they both were participating in HA. Yesterday, I set up new VLAN subinterface eth1-04.500 in Gaia and as a Cluster interfaces in FW gateway object, etc.
Afterwards, eth1-04.500 was not showing up in HA at either command line or in SmartConsole "Gateways & Servers".
Decided to go ahead and individually reboot the two enforcement points as a hopefully simple way to clear that up, and they had been up for a long time so wanted to refresh anyway.
Afterwards, eth1-04.500 did begin to show up in HA, but then eth1-04.300 stopped showing up in HA. Further reboot and policy pushes do not change this.
Here is cphaprob -a if from one gateway:
[Expert@chw_pbx_bbfw1:0]# cphaprob -a if
Required interfaces: 4
Required secured interfaces: 1
Sync UP sync(secured), multicast
bond41 UP non sync(non secured), multicast, bond Load Sharing
eth1-04 UP non sync(non secured), multicast (eth1-04.500)
eth1-04 UP non sync(non secured), multicast (eth1-04.200)
Virtual cluster interfaces: 4
bond41 10.150.2.188
eth1-04.500 10.5.1.21
eth1-04.200 10.2.0.1
eth1-04.300 10.3.6.49
Any idea what happened?
Thanks.
Q (Quentin)
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY