CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-01
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Active/Active ClusterXL unicast mode

scenario:

I have a pair of NG with AI R55 hfa_20 SPLAT firewalls
running in Active/Active ClusterXL unicast mode.

gw1 is a Dell dual P-Iv 2.8Ghz processors with 2GB of
RAM. gw2 is a single P-III 1.3Ghz processor with 512MB
of RAM. Currently, I have gw1 as the pivot node:

[Expert@GW1]# cphaprob state

Cluster Mode: Load Sharing (Unicast)

Number Unique Address Assigned Load State

1 10.1.1.1 30% active (pivot)
2 (local) 10.1.1.2 70% active

[Expert@GW1]#
[Expert@GW2]# cphaprob state

Cluster Mode: Load Sharing (Unicast)

Number Unique Address Assigned Load State

1 (local) 10.1.1.1 30% active (pivot)
2 10.1.1.2 70% active

[Expert@GW2]#

Since the cluster members do not have identical processors
and memory, is it recommended to make gw2 the pivot node
so that it can handle less load than gw1? Because gw1 has
faster processor and more memory, it should handle 70%
of the load.

Is this the correct assumption? Thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-03-01
Senior Member
 
Join Date: 2006-12-16
Posts: 161
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Active/Active ClusterXL unicast mode

That should be fine for a network with not alot of connections.
Reply With Quote
  #3 (permalink)  
Old 2008-03-02
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Active/Active ClusterXL unicast mode

what about for a network with a lot of connections?
Reply With Quote
  #4 (permalink)  
Old 2008-03-02
Senior Member
 
Join Date: 2006-12-16
Posts: 161
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Active/Active ClusterXL unicast mode

You want about 256 MB of Ram for about every 25000 connections. Just be smart with the rulebase. Put the most used rules at the top and enable full duplex on the switches and firewall interfaces and you will be fine. If you can get the Ram up to 1 GB that would be better.
Reply With Quote
  #5 (permalink)  
Old 2008-03-03
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Active/Active ClusterXL unicast mode

I think you're missing the point of my question. What I am asking is that,
given the situation that I have, which node should be used as the "pivot"
node?

"You want about 256 MB of Ram for about every 25000 connections. Just be smart with the rulebase. Put the most used rules at the top and enable full duplex on the switches and firewall interfaces and you will be fine. If you can get the Ram up to 1 GB that would be better."

I am aware of all the things you mentioned above.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:33.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0