CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-15
scottyb-cpug scottyb-cpug is offline
Junior Member
 
Join Date: 2006-06-15
Location: Ottawa, Ont. (Canada)
Posts: 2
Rep Power: 0
scottyb-cpug has an average reputation (10+)
Default IPSO Clustering and HA/LS

I have 2 x IP350 and 2 x IP380 that I want to set up in one of the MANY different versions of clustering (VRRP/VRRPmc, IPSO Clustering, ClusterXL...).

I believe VRRP is passe?, VRRPmc is reasonable but with IPSO 3.8 and CP FW NG (R55), the IPSO Clustering (via Voyager) is my best bet?

Does anyone have a working 2 node IPSO cluster in Load Sharing (or even HA mode). The added complication is we doe Hide NAT as well.

tia,

Scott.

ps. I have the Syngress CPNG...Advance Config and TS book and just bought Essential Check Point Firewall-1 NG (by Daemon W-A/Phoneboy) but I remain nervous about the deployment even after reading through both.
Reply With Quote
  #2 (permalink)  
Old 2006-08-01
plemaster plemaster is offline
Junior Member
 
Join Date: 2006-06-06
Posts: 1
Rep Power: 0
plemaster has an average reputation (10+)
Default Re: IPSO Clustering and HA/LS

we are running Nokia IP530 and loadsharing / IPSO clustering with R55p on nodes and R60 on Smartconsole.
Reply With Quote
  #3 (permalink)  
Old 2006-08-01
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: IPSO Clustering and HA/LS

I think before you deploy anything, you should have a better understanding of what your options are, and what the pros/cons of each of them are.

Since you have Nokia boxes, your options are only VRRP or IP Clustering. Nothing else.

VRRP is HA only. Don't worry about the VRRPv2, MC thing. Just click simplified mode VRRP. It's all monitored circuits now. Very simple, works very well. No special config required anywhere. Failover time is ~3s.

IP Clustering is load sharing only. This means you can (in theory) process more traffic than just one node. If you've got two nodes, you're looking at a 10% improvement in connection setup rate, and a 30% improvement in throughput. VPN throughput goes up by more. Clustering can be problematic though, particularly with multicast mode. Some devices (Cisco I'm looking at you) don't like the multicast MAC address, and require manual configuration. You can use forwarding mode instead, but that's not so elegant. Remember also that your cluster has to be able to handle the traffic with a node down. The main advantage you get with clustering, if you're not pushing large amounts of VPN traffic, or in a 3/4 node cluster, is that you get 0.5s failover.

So is that worth it to you? Are you at the limits of what the 350/380 can do? Do you even know what those limits are? Or are you just looking to deploy clustering because it's "cool", and VRRP is "passe". Ask yourself what you are trying to achieve. Do you need load sharing, or HA? Do you need fast failover? What is it worth to you?

Hide NAT will work fine with both.

You should probably have a read of the IPSO Clustering Config guide, from Nokia.
Reply With Quote
  #4 (permalink)  
Old 2006-08-03
kekec kekec is offline
Junior Member
 
Join Date: 2006-08-03
Posts: 1
Rep Power: 0
kekec has an average reputation (10+)
Default Re: IPSO Clustering and HA/LS

We are running two clusters with IP350 in load sharing MCAST mode without any limits (R55p).

Kekec
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:05.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0