CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-09-12
Junior Member
 
Join Date: 2005-09-09
Posts: 10
Rep Power: 0
al00ha has an average reputation (10+)
Default ClusterXL and virtual interfaces

Does anyone know if ClusterXL is supposed to support virtual interfaces?, after my research and a lot of testing I just can’t get it working so I guess it’s not?
I’m running NGX, CP-Express, ClusterXL, HA New Mode on Win2003.

I guess only the interfaces that is seen by fw ctl iflist on the gateways are able to be used as cluster interfaces and the virtual addresses doesn’t show up there?

Does anyone have a solution or workaround to this problem, Without this function its impossible to use multiple internal subnets on the same interface and to install about 30 hardware interfaces is not an option. Has anyone ran in to this problem before?

Thanks in advance
Regards
/Johan Ahlstrom
Reply With Quote
  #2 (permalink)  
Old 2005-09-13
Member
 
Join Date: 2005-08-15
Posts: 36
Rep Power: 0
flawless_cowboy has an average reputation (10+)
Default Re: ClusterXL and virtual interfaces

No checkpoint does not support multinetting and interface. The way this needs to be setup in order to work is with VLANs. You can still use a single network card, but you create virtual interfaces that use 802.1q VLAN tags. The virtual interfaces will then show up as seperate interfaces (even at the OS level ) not all network cards are capable of this, but many are. It sounds to me like you have one physical network with many logical networks, if that is the case you would need to redesign you entire LAN and create seperate broadcast domains for each network (VLANs). At that point you could assign the vlan tags to the server running checkpoint and create the interfaces needed.
Reply With Quote
  #3 (permalink)  
Old 2005-10-25
Junior Member
 
Join Date: 2005-09-09
Posts: 10
Rep Power: 0
al00ha has an average reputation (10+)
Default Re: ClusterXL and virtual interfaces

Thanks alot!
Didn´t think about that.
Currently using 802.1q VLAN tags on the switches so this solution will be easy to implement.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 04:23.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0