CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-21
Junior Member
 
Join Date: 2007-05-19
Posts: 10
Rep Power: 0
bornamonday has an average reputation (10+)
Default VRRP - Advanced Questions

Hello,

Is it possible to have the VIP of the firewall and the physical IP addresses of the firewall in different networks with Nokia VRRP?

sample:
VIP: 192.168.1.1 / 30
RT1: 192.168.1.5 / 30
RT2: 192.168.1.6 / 30

why I am asking this is because I don't want to change the current network IP addresses connecting the firewall to router with netmask /30 which means I don't have an additional free IP for the 2nd firewall when migration to Nokia VRRP cluster. and the whole picture of the scenario is to avoid IP change on router.

Thanks for your help!!!

BAM.
Reply With Quote
  #2 (permalink)  
Old 2007-05-22
Junior Member
 
Join Date: 2007-01-12
Posts: 10
Rep Power: 0
olasoji has an average reputation (10+)
Default Re: VRRP - Advanced Questions

Yes. It is possible to have the physical IP addresses in a different subnet from the VIP. Checkpoint is able to map the virtual cluster Ip address to the member interface addresses.

In the Cluster object, just specify the network that the members reside on and that is it. This would be the member network.

If this solves your problem please do let me know
Reply With Quote
  #3 (permalink)  
Old 2007-05-22
Junior Member
 
Join Date: 2007-05-19
Posts: 10
Rep Power: 0
bornamonday has an average reputation (10+)
Default Re: VRRP - Advanced Questions

ok and thanks, I will give a shot anyway and let you know. But I have noticed that on the Nokia side, if the VIP is not on the same network as both physical IP addresses, both physical network interfaces wont advertised their physical mac addresses to the switch when issuing "show mac address-table" as well as the Virtual MAC of the VIP wont appear on the switch as well. So nothing shows up on the switch no mac addresses of both physical IP and VMAC as well. it should not work.

if you could NOT see the mac addresses of both physical addresses as well as the VMAC of the VIP. I dont see how CP could ease the problem.

Please put your comments.

Thanks.
BAM.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0