CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-12
Junior Member
 
Join Date: 2007-08-03
Posts: 1
Rep Power: 0
lenrenee has an average reputation (10+)
Default Disjoining cluster members

Hello,

I was wondering if anyone as experiences (or may have good documentation/threads) on the current firewall work I am undertaking.

We currently have 2 Check Point VPN-1(TM) & FireWall-1(R) NG with Application Intelligence (R55) HFA_15, Hot fix 528 - Build 00 firewalls in a ClusterXL configuration. The task I have before me is to split the cluster members, so I may transport, and configure the firewall at a new IDC we are building out.

From there, the firewall will need to be reconfigured, as well as joined with a new magmt station, as its current mgmt station will not be accessible. Eventually, the old firewall peer will also be transported over to the new IDC, and the new cluster configuration will be renewed.

Regards,
Lenny
Reply With Quote
  #2 (permalink)  
Old 2007-09-13
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Disjoining cluster members

I would basically treat this as if a new build.

What I would do is remove the firewall from the existing cluster in the smartdashboard, making sure you remove the backup.

Then run the remaining node as a single node cluster.

At the new location I would do a completely fresh install of the Check Point box. You haven't specified what OS, but I am guessing SPLAT as is ClusterXL. Build this box as a single node cluster initially and SIC to the new management server. I have found just as quick to rebuild SPLAT and run the sysconfig then going through and changing everything on the box.

Treat this as if a new install, and then when the other box is ready to be moved across you can rebuild as a new member and slot into the cluster easily.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:51.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0