CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point UTM-1 Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-05
Member
 
Join Date: 2008-04-12
Posts: 53
Rep Power: 1
doccocaubai has an average reputation (10+)
Default How to connect SmartCenter to Nokia VRRPv2

Hi, all
Please instruct me how to configure VRRPv2 on IPSO 4.2 and how to connect the smartcenter to VRRPv2. Because VRRPv2 doesn't have the VIP.
thanks all.

Last edited by doccocaubai; 2008-08-05 at 03:00.
Reply With Quote
  #2 (permalink)  
Old 2008-08-05
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: How to connect SmartCenter to Nokia VRRPv2

You wouldn't connect the SMARTCenter to the vrrp address.

You connect the SMARTCenter to the individual nodes in the vrrp cluster. ie

if .1 is the vrrp address, .2 and .3 are the individual nodes then you connect .2 and .3 as individual gateways establish SIC, attach license etc.

You then define the Check Point Cluster and add the .2 and .3 gateways as members.

If you want to use VRRP then you need to goto Legacy Configuration under VRRP. Simple Mode VRRP is purely for Monitored Circuit.
Reply With Quote
  #3 (permalink)  
Old 2008-08-05
Member
 
Join Date: 2008-04-12
Posts: 53
Rep Power: 1
doccocaubai has an average reputation (10+)
Default Re: How to connect SmartCenter to Nokia VRRPv2

Quote:
Originally Posted by mcnallym View Post
You wouldn't connect the SMARTCenter to the vrrp address.

You connect the SMARTCenter to the individual nodes in the vrrp cluster. ie

if .1 is the vrrp address, .2 and .3 are the individual nodes then you connect .2 and .3 as individual gateways establish SIC, attach license etc.

You then define the Check Point Cluster and add the .2 and .3 gateways as members.

If you want to use VRRP then you need to goto Legacy Configuration under VRRP. Simple Mode VRRP is purely for Monitored Circuit.
Thanks mcnallym,
But I need to use the VRRPv2, not VRRP monitored Circuit.
I can connect the SMARTCENTER to the VRRP monitored circuit group because it have the VIP.
But now, i want to use the VRRPv2. What can I do to connect SMARTCENTER to VRRPv2 group? Does I define the IP of the active device as VIP of VRRPv2 group?
Reply With Quote
  #4 (permalink)  
Old 2008-08-07
Member
 
Join Date: 2008-04-12
Posts: 53
Rep Power: 1
doccocaubai has an average reputation (10+)
Default Re: How to connect SmartCenter to Nokia VRRPv2

no one can help me?
Help me please
Reply With Quote
  #5 (permalink)  
Old 2008-08-08
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: How to connect SmartCenter to Nokia VRRPv2

I will say it again!

Check Point SMARTCenter DOES NOT connect to the VRRP address in a VRRP pair.

You should connect the SMARTCenter to the individual nodes in a VRRP pair.

ie connect the two individual nodes to the SMARTCenter as if there is no VRRP.

You then define the Check Point Cluster Object and say that the two nodes are Cluster Members which makes the node objects part of the cluster and they are relocated to be underneath the Cluster Object and the settings are moved to the Cluster Object. The IP address used for the Cluster Object is the VRRP address but the SMARTCenter actually connects to the individual node IP addresses not the VRRP address.

To configure VRRPv2 then you need to use VRRP then goto the Legacy Configuration and manually configure the VRRP. Addressing scheme as already explained. ie x.x.x.1 as the vrrp vip with x.x.x.2 and x.x.x.3 as the individual node ip's.

As a question why cannot you use VRRP monitored Circuit as only the two Nokia's in question will be talking within this VRRP Group.

It's not that no one can help you with this merely that what you are asking to do is incorrect.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0