- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Luis,
yes that's possible.
You have to build one bond interface on one CheckPoint appliance and connect the interfaces of these bond to each CISCO-switch.
I would prefer to use LACP as BOND protocol. To create a BOND spanning over both switches they must be member of the same stack or they need something like vPC.
You can't create a bond over two separate switches.
Without having vPC or stack you can configure the BOND on the CheckPoint appliances as HA (active-backup). But with this you can't do LoadSharing and the passive interface is only used if the active link goes down. With a bond like this you don't need a BOND configuration on the switches.
In the "Gaia R80.20 Administration Guide" you'll find a detailled description how to configure BONDs, chapter "Bond Interfaces (Link Aggregation)"
Wolfgang
simply LACP L2 Fast and off you go 🙂 not really complicated task though.
I can recommend to avoid L2 LACP. When having for example a proxy behind the switch all traffic that comes from the proxy will pass via the same link to the firewall.
This can cause disbalanced links within the bond. Try to use L3/4 LACP, but this needs software support on the affected switch.
On firewall side you have to configure xmit-hash-policy layer3+4.
Regards
Sven
hi Sven
proxy wasn't mentioned at all by the original post hence my advise on L2 LACP.
I completely second your advise when it comes to the proxying any traffic indeed, but that is a matter of a proper design on application level as you've already wrote.
In any case the question is not an easy one to answer, there are dependencies to consider as well as consequences of the decisions which definitely need to be taken into the account.
Jerry, you are absolutly right.
My advaice was just a general hint not based on the specific problems of Luis.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY