CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-28
srirat srirat is offline
Junior Member
 
Join Date: 2006-05-15
Posts: 16
Rep Power: 0
srirat has an average reputation (10+)
Default Cluster across 2 sites

Hello,

I've some questions to ask about clustering across 2 sites. Can/shoud i put the first firewall component at the first site and put the second firewall at the second site? That means the HA connection will be remotely across 2 sites.

Thanks for all suggestion.
Reply With Quote
  #2 (permalink)  
Old 2006-07-28
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Cluster across 2 sites

Although this is possible, in the real world it tends not to work because of latency on sync network.

For DR you really want to work with your ISP/network vendor on a BGP solution
Reply With Quote
  #3 (permalink)  
Old 2006-07-31
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Cluster across 2 sites

It is possible if your sites are not too far apart (around 30km or so max, IIRC) and you can run fiber between the sites, to bridge the sync connection. I've seen this working pretty well.

But otherwise, Jim's right, sync is your problem. If you can't get a low-latency connection for the sync link, you need to look into dynamic routing-type scenarios. Of course, this works for failover, but can be a hassle if there are any long-running connections - they will be out of state, and dropped by the backup firewall. Your options depend a bit on what sort of applications you're trying to split across sites, and your architecture.
Reply With Quote
  #4 (permalink)  
Old 2006-08-05
kaldek kaldek is offline
Junior Member
 
Join Date: 2006-08-02
Posts: 11
Rep Power: 0
kaldek has an average reputation (10+)
Default Re: Cluster across 2 sites

I agree with the previous posts. I have a customer who is running a 4-node cluster spread across two sites, about 3 kilometres apart. The inter-site link is a dark fibre (i.e. they own the entire line) connected between two Cisco Catalyst 6000 series switches. The link carries a large number of VLANs aside from just the sync network. This customer is also operating in multicast load sharing mode, so the potential bandwidth usage there might seem scary. The cross-site link is 1Gb/s Ethernet handling all those VLANs, but the firewall and its sync networks are all 100Mb/s, which explains why it is working.

We have recently discussed with the customer the long term goal of migrating to a Layer-3 redundancy design (i.e. Layer 4-7 load balancing to distribute user connections to the two different sites) and setting up separate clusters at each site, due in part to the fact that we know their network usage will grow and eventually saturate the cross-site link due to the severe number of multicast packets.

Having two separate clusters also increases your redundancy, because a software fault on one cluster won't affect the other one. As it is right now, if the customer stuffed up their static MAC address tables in their switches, or broke the static ARP entries in their routers, the entire cluster would malfunction. Given all that, this customer is one of the largest organisations in the country, and I have not heard a peep out of them regarding firewall problems since we installed the solution. Their website performance is also exemplary, so sometimes things that seem precarious can end up being quite solid.

P.S. In case you're wondering why we even built a cross-site cluster in the first place, you must understand the customer's history. Their existing cluster was cross-site, based on Checkpoint Firewall-1 4.0 on Solaris with StoneBeat providing the HA functionality. Behind these firewalls, the entirety of their server infrastructure is shared-layer 2 cross-site VLANs. Changing that entire design to a routed environment between the sites was just not economically feasible in the short term.

Last edited by kaldek; 2006-08-06 at 16:25.
Reply With Quote
  #5 (permalink)  
Old 2006-08-05
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Cluster across 2 sites

Just one further thing - if you read the ClusterXL guide, it explicitly states that this is possible, provided latency on the sync link is not more than 100ms.
Reply With Quote
  #6 (permalink)  
Old 2007-02-22
ppnair@gmail.com ppnair@gmail.com is offline
Member
 
Join Date: 2007-01-10
Posts: 32
Rep Power: 0
ppnair@gmail.com has an average reputation (10+)
Default Re: Cluster across 2 sites

I was just going through this post to get a clarity on my doubt. But first of all I appreciate all of your great answers for the orginal question. Would you all please clarify this question for me ?

1. Two sites with two different public IP range running BGP with respective ISPs. 192.152.123.X and 198.153.221.X

2. Wish to set up ClusterXL with 100Mbps WAN syncronization.

3. SmartCenter server in 192.152.123.X network.

4. 198.153.221.X network have two FW-1 cluster members and 192.152.123.X have only one cluster member.

5. Both sites have it own internet connections; but in after the firewall we have a dedicated 100mbs inter-office link for LAN-to-LAN.

My question is how the Virtual IP address for this cluster should setup and how should I assign external interface IPs to each members? In this case should it have a common Public IP which is routed using BGP in both sites??

Assuming 100mbs link uses for WAN syncronization. Please help

Praveen

Here attaching the network diagram to make it clear:
Attached Files
File Type: txt CheckPoint.txt (498 Bytes, 118 views)

Last edited by ppnair@gmail.com; 2007-02-22 at 08:42. Reason: Adding more info
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0