Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Franktum
Contributor

[VSX] How to disable an interface in HA monitoring

Hi all,

In a regular cluster, when you want to failover when an interface goes down, you configure it as Cluster in Network Type field. Otherwise, you choose Private.

Don't know whether in VSX env, we could configure an interface not to be monitored by HA, hence a failover won't occur if that interface goes down.

Regards

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

I believe you can add the interface to $FWDIR/conf/discntd.if and do a cprestart (both in the context of the relevant VS).

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Previously that would remove the IP from the interface on boot up, so I would avoid testing that in prod. 

Private interfaces on SG clusters do not have VIPs, which is not an option on VSX. Essentially the IP you configure on the interface in SmartConsole is a VIP, so 'private' is not an option as you can't not have a VIP there on VSX. 

What is the problem you are looking to solve by not monitoring the interface?

0 Kudos
Franktum
Contributor

Last week we got a non-critical interface (eth1-06) in a VS that was flapping constantly and, hence, so was the cluster. We wanted to exclude for HA monitoring that interface in order to avoid that scenario in the future.

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

We don't really have an option to not monitor an access port on VSX. Ideally it would be best to understand why it was flapping and resolve that - if it's a barely used subnet, make sure there's always something in there with an IP address that will respond to ARPs and pings.

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

What type of interface, a specific VLAN or something else?

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events