CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-28
cmarcusson cmarcusson is offline
Junior Member
 
Join Date: 2007-12-27
Posts: 4
Rep Power: 0
cmarcusson has an average reputation (10+)
Default VRRP HA with 1 Public IP

Is it possible to run VRRP with only 1 public IP. There seems to be little or no documentation covering this implemenatation. I beleive that the reason for that is because in order to publish a how-to on VRRP with 1 IP, you need to include switch configuration, and that exceeds the scope of the simplified VRRP setup docs. My colleges are convinced that it cannot be done due to the lack of documentation, but I still think it can.

You should just be able to address your Virtual Router with your Public IP, and then address the 2 physical external interfaces with anything like 1.1.1.1 or something. The Checkpoint Gateway Cluster Object should then be able to push the policy to all memebers on those private external interfaces??? Switch configuration would be another story, but should be possible right?

Can someone clarify this for me (any available diagrams would be greatly appreciated too.)

Thanks in advance for any advice,

Chad

Nokia 560's x 2 w/ NGX R65

Last edited by cmarcusson; 2007-12-28 at 11:36.
Reply With Quote
  #2 (permalink)  
Old 2008-01-02
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: VRRP HA with 1 Public IP

Not possible... Each external interface must have it's own unique public address in addition to the main IP shared by the cluster. Speak to your ISP to obtain a larger pool.

A /30 Net has 6 usable addresses and should work for you
A /29 Net will give you 14 usable addresses

When considering IP pool sizes, consider the following:
1 IP - Router (yours or ISP provided - MANDATORY)
1 IP - FW1 (Physical interface)
1 IP - FW2 (Physical interface)
1 IP - VRRP/HA/Cluster (Virtual interface)
1 IP - RADIUS (2 IPs if HA RADIUS)
1 IP - For each server (web, FTP, Email, etc.) that needs Static NAT IP
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2008-01-02
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: VRRP HA with 1 Public IP

I believe that SPLAT/ClusterXL can do HA using a HA address outside the interface range, however that is NOT VRRP.

However I have not really looked at it too much as I need to be able to connect to the individual boxes across the Internet anyway.
Reply With Quote
  #4 (permalink)  
Old 2008-01-02
inetd inetd is offline
Member
 
Join Date: 2006-11-03
Posts: 34
Rep Power: 0
inetd has an average reputation (10+)
Default Re: VRRP HA with 1 Public IP

Quote:
Originally Posted by lammbo View Post
Not possible... Each external interface must have it's own unique public address in addition to the main IP shared by the cluster. Speak to your ISP to obtain a larger pool.

A /30 Net has 6 usable addresses and should work for you
A /29 Net will give you 14 usable addresses

When considering IP pool sizes, consider the following:
1 IP - Router (yours or ISP provided - MANDATORY)
1 IP - FW1 (Physical interface)
1 IP - FW2 (Physical interface)
1 IP - VRRP/HA/Cluster (Virtual interface)
1 IP - RADIUS (2 IPs if HA RADIUS)
1 IP - For each server (web, FTP, Email, etc.) that needs Static NAT IP
Please check your subnetting here. Regards
Reply With Quote
  #5 (permalink)  
Old 2008-01-02
manrag manrag is offline
Member
 
Join Date: 2007-05-31
Posts: 52
Rep Power: 2
manrag has an average reputation (10+)
Default Re: VRRP HA with 1 Public IP

It is not possible using only 1 IP the minumum will be 2 IPs using VRRPv2.
Reply With Quote
  #6 (permalink)  
Old 2008-01-03
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: VRRP HA with 1 Public IP

Quote:
Originally Posted by inetd View Post
Please check your subnetting here. Regards
oops! sorry, should be /29 and /28 respectively...
__________________
There's no place like 127.0.0.1
Reply With Quote
  #7 (permalink)  
Old 2008-01-04
donshoutarp donshoutarp is offline
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 3
donshoutarp has an average reputation (10+)
Default Re: VRRP HA with 1 Public IP

If you own the router...

You could have the router NAT.

A setup would be something like this

FW VIP 10.1.1.1
FW1 real IP 10.1.1.2
FW2 real IP 10.1.1.3

Router NAT Public IP to 10.1.1.1

It gets more complicated to to this if you have branch offices with the Checkpoint management server behind this firewall group, but could be possible.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 09:10.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0