Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
fabiofabio
Collaborator

sync interfaces going up and down (partially up)

Hello,
this morning I replaced one of the two nodes in HA, the new one was configured and tested in a test environment and in fact now it has no problems. the problem occurs in the two interfaces (ETH4 and 5) that deal with the sync. these keep going up and down

image.png

image.png


from the smart console are partially up

image.png

ETH4 is set as secondary in sync while ETH5 is primary.
node 1 (the old one) restarted by itself when I attacked node 2 (new) and node 1 was not restarting for a year. at this moment node 1 is running and has no problems, but due to the problems on the interfaces there is no node 2 among the members of the HA

image.png

I read that I should broadcast the network cards to solve the problem but I don't want to, as it has worked so far. the problem shouldn't be here.

any suggestion?

thanks

 

0 Kudos
13 Replies
the_rock
Legend
Legend

I cant say this 100%, but I believe it was never recommended to use 2 sync interfaces. Regardless, you can try below steps. I always use to do this when someone had issues with sync in the cluster.

Andy

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Which GW version is this?

Note the use of more than one dedicated physical interface for synchronization redundancy is not supported. You can use Bonding for synchronization interface redundancy.

CCSM R77/R80/ELITE
0 Kudos
fabiofabio
Collaborator

this configuration works since 2014, I have no idea at this point how they made it work, however, can this modification to create the bonding be done hot? taking into account that I only have a functioning node and that I can no longer afford down periods.

0 Kudos
the_rock
Legend
Legend

You can do sync debug from the link I sent, hope that helps, as it should give you a clue why its failing.

0 Kudos
the_rock
Legend
Legend

Also, to add what @Chris_Atkinson said, I dont know if it says anywhere its not officially supported, but either way, all I can tell you from my experience is that I had customers run it and it does work, BUT, when it breaks, tough fixing it...its NOT an easy task, thats for sure.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

For reference it's explained in the Cluster XL admin guide here:

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/S...

CCSM R77/R80/ELITE
the_rock
Legend
Legend

Thank you for that.

0 Kudos
Timothy_Hall
Champion
Champion

Backing up what Chris said here, I even mentioned in my book that adding a second physical interface as a 2nd sync is not a good idea and to use a bond instead:

Click to Expand
If you elect to add a second sync network, bond the original physical interface with
another physical interface via the Gaia web interface (or clish) and declare the new
bonded aggregate interface as “1 st Sync” in the cluster object topology settings. DO
NOT simply add a new non-bonded interface and declare it as “2nd sync” in the cluster
topology, as this setup will severely degrade cluster performance. Check
netstat -ni statistics as well for the physical sync interfaces to ensure zero values
for RX-ERR and RX-OVR.

  

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
the_rock
Legend
Legend

I think I will buy your book @Timothy_Hall , one of my colleagues said he got it on Amazon and loved it :- ). Any discount code for checkmates peeps? haha

0 Kudos
Timothy_Hall
Champion
Champion

Unfortunately I have no ability to create discount codes at Amazon for the hardcopy edition.

However discount codes for the PDF edition and the self-guided video series offerings do tend to pop up during CPX season every year so stay tuned.  

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
the_rock
Legend
Legend

Just bought it on amazon, pays to be prime member : )

PhoneBoy
Admin
Admin

The top of this SK suggests you should, except in a few unique cases, only use bonded sync interfaces if you want redundancy.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
Chris_Atkinson
Employee Employee
Employee

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events