CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-28
tohhwee72 tohhwee72 is offline
Junior Member
 
Join Date: 2007-04-10
Posts: 10
Rep Power: 0
tohhwee72 has an average reputation (10+)
Default Maximum no. of firewall in a cluster

Is there any limitation in the no. of firewalls in a cluster. l was told that the max. no. of firewall in a cluster is 5 when running on Crossbeam X80. Is this a limitation on Checkpoint firewall?
Reply With Quote
  #2 (permalink)  
Old 2008-01-28
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 495
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Maximum no. of firewall in a cluster

After 5 members are in a cluster, the noise and effort of synchronisation traffic eliminates any performance benefits. I don't think it's a hard-coded limitation, but a pragmatic one based on performance.

Why would you need a cluster of more than 5 members????
Reply With Quote
  #3 (permalink)  
Old 2008-01-28
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 754
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Maximum no. of firewall in a cluster

I was told 8 months ago from a Checkpoint SE during a checkpoint
NGx R65 presentation that you can cluster up to either 16 nodes
or 32 nodes with Checkpoint. Granted, most of the times, information
provided by Checkpoint SEs are faulty.

my 2c
Reply With Quote
  #4 (permalink)  
Old 2008-01-28
mikem mikem is offline
Junior Member
 
Join Date: 2007-01-26
Posts: 19
Rep Power: 0
mikem has an average reputation (10+)
Default Re: Maximum no. of firewall in a cluster

I was told by another engineer anything over 3 members in a cluster was not really worth it.

I would think cluster xl is going to take care of performance issues and all you will need a cluster for is redundancy.

mike
Reply With Quote
  #5 (permalink)  
Old 2008-01-28
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 754
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Maximum no. of firewall in a cluster

I was one of those who really likes ClusterXL Active/Active and
IPSO Clustering until I have to deploy it in a production environment.

Let say you cluster 5 firewalls together in Cluster Active/../../../Active
mode. If there is a problem and you have to troubleshoot an issue,
you have to run 5 tcpdump. Ouch...

Active/Active.../Active sound good in theory but in actual implementation,
people need to understand the aspect of mantenance and support.
Reply With Quote
  #6 (permalink)  
Old 2008-01-28
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Maximum no. of firewall in a cluster

It really depends on your environment but in general the practical limit is 4 nodes to a cluster before sync traffic starts to degrade performance. There is a lot that can be tuned to increase performance (Like you really don't need to sync http in most cases) but a 4-node cluster still seems to be as far as you can go.

Pre-R65 (I haven't checked R65 yet) the limit was 6 nodes. IIRC ClusterXL on VPN-1 (Not VSX, which is very different) was QA'ed to 8-nodes.

As cciesec2006 points out, think before you jump into the active/active... clustering vs just a simple HA design as it is harder to debug.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:15.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0