Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Diego_dg
Collaborator
Jump to solution

interconnection of both cluster members though Internal VLAN used for virtual switch

Hello, I have one doubt about VSX and the internal VLAN used on Virtual Switches for interconnecting VSX clusters: I thought it only need to exist inside the virtual system, but taking into account that it is monitored by CCP:

https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_VSX_AdminGuide/html_frameset...

I suppose CCP packets are being send from one appliance to the other also for this internal VLAN and, in this case, we need to connect by some way (by physical wire or physical switch) this VLAN on one of the appliance with this same vlan in the oher appliance. could someone please confirm this?

Best regards

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

Individual Virtual Systems can be active on different cluster members so for communication via a vswitch to work between VS the vlan needs to be present in the adjacent network fabric, sync interfaces aren't used for this traffic flow.

Are you certain you need a virtual switch in your scenario, over the journey we've seen many deployments that have had unnecessary virtual routers or virtual switches.

 

CCSM R77/R80/ELITE

View solution in original post

2 Replies
Chris_Atkinson
Employee Employee
Employee

Individual Virtual Systems can be active on different cluster members so for communication via a vswitch to work between VS the vlan needs to be present in the adjacent network fabric, sync interfaces aren't used for this traffic flow.

Are you certain you need a virtual switch in your scenario, over the journey we've seen many deployments that have had unnecessary virtual routers or virtual switches.

 

CCSM R77/R80/ELITE
Diego_dg
Collaborator

Thanks, for your help, we will review our scenario according to you recomendations. We configured the virtual switches without configuring the VLAN on the adjacent network fabric and everyting works but the clusters are in state Active Attention/DOWN because CCP packets are not received on the warp interfaces, so I think this is the expected behaviour if the VLAN is not present on the adjacent network fabric, we will fix this as suggested. Thanks!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events