We have a customer wanting to connect a Checkpoint firewall in HA mode directly to the N7K. The problem is the HA traffic is not being passed. With Catalyst switches this could be resolved by configuring a static MAC address on each of the ports the Checkpoint is connected. It appears that static MAC entries can be configured, but will that work the same way as on the Catalyst Switches? (I think that it will, but I haven't had the time to research). Also is there another way to solve this on the Nexus?
The traffic is destined for MAC broadcast with the IP address of the firewall.
Actually it has been a long time since have done this. It is not possible to configure a static MAC address of ffff.ffff.ffff. You can't do this on Catalyst switches so it must be possible to change the checkpoint to send to a different MAC address, but I can't remember how.