
Originally Posted by
cciesec2006
were you Tested and validated on R77.30 with JHFA 205?
I did the followings, ON THE SAME HARDWARE:
scenario #1:
1- on both gw1 and gw2, use snapshot to revert back to R77.30 with JHFA_159 on both gateways,
2- configure both gateways with 802.3AD active/active for the SYNC interface; reboot, and push policy to the gateways, gw1 is Active, gw2 is standby (eth4 and eth8 are bonded interface bond1)
3- frrom the switch, shut down eth4 on gw2, still active/standby. bring up eth4, still in active/standby. shutdown eth8, still in active/standby, bring up eth8 still in active/standby
scenario #2:
1- on both gw1 and gw2, use snapshot to revert back to R77.30 with JHFA_205 on both gateways,
2- configure both gateways with 802.3AD active/active for the SYNC interface; reboot, and push policy to the gateways, gw1 is Active, gw2 is standby (eth4 and eth8 are bonded interface bond1)
3- frrom the switch, shut down eth4 on gw2, still active/down. bring up eth4, in active/standby. shutdown eth8, in active/down, bring up eth8 in active/standby
@jdmoore0883: I am very surprised by your revelation and comments about diamond engineers. I thought with diamond support, one would expect the best from checkpoint in term of engineer and the ability to replicate issue in diamond lab environment. Most customers are multi-vendors and it is very hard to replicate issue without equipments, especially non-checkpoint equipments. The company I am working for is not a big company but we have Palo Alto, Juniper, (Cisco routers, switch, VPN, firewalls) and Checkpoint equipments so that we can replicate all kind of issues in production. Granted these are not top of the line equipments but they are enough to build out and test scenarios when we have issues in production. Now I know it always takes a long time to resolve issues by Checkpoint TAC :-(
Bookmarks