Dual Chassis in Bridge Mode
This chapter describes how to deploy Dual Chassis in Layer 2 Bridge mode.
Bridge Mode Topologies
Active/Active Bridge Mode supports these topologies:
BPDU
The BDPU maximum age timer controls the maximum length of time that passes before a bridge port saves its configuration BPDU information.
The default time it takes to reach a chassis failover is 20 seconds. It is possible to configure be configure this time to a value from 6 to 40 seconds.
Example for Cisco switches:
Use the "spanning-tree vlan
" command on each VLAN to configure the BDPU maximum age timer. For more information, see Cisco documentation.
Configuring Bridge Interfaces in Gateway Mode
Description
Use the applicable commands in Gaia gClish The name of the global command line shell in Check Point Gaia operating system for Security Gateway Modules. Commands you run in this shell apply to all Security Gateway Module in the Security Group. to work with Bridge interfaces.
For more information, see the R81.20 Gaia Administration Guide > Chapter Network Management > Section Network Interfaces - Subsection Bridge Interfaces.
Example
Configuring Bridge Interfaces in VSX Mode
Configure a Virtual System in Bridge Mode when you first create its object.
For more information, see the R81.20 VSX Administration Guide.
To configure an existing Virtual System in Active/Standby Bridge Mode:
Step |
Instructions |
|
---|---|---|
1 |
Connect with SmartConsole to the Security Management Server, or the TargetDomain Management Server that manages this Virtual System. |
|
2 |
From the left navigation panel, click Gateways & Servers. |
|
3 |
Open the Virtual System object. |
|
4 |
In Virtual System General Properties, select Bridge Mode. |
|
5 |
Click Next. The Virtual System Network Configuration window opens. |
|
6 |
Configure the external and internal interfaces for the Virtual System. |
|
7 |
Click Next. |
|
8 |
Click Finish. |
|
9 |
Connect to the command line on the Security Group |
|
10 |
Log in to Gaia Clish. |
|
11 |
Go to Gaia gClish: enter |
|
12 |
Switch to the context of the applicable Virtual System:
|
|
13 |
Examine the interfaces:
|
Configuring Virtual Systems in Bridge Mode to Forward Non-IP Protocols
Step |
Instructions |
|
---|---|---|
1 |
Connect to the command line on the Security Group. |
|
2 |
Log in to the Expert mode. |
|
3 |
Create the required empty file on all Security Group Members:
|
|
4 |