CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-06
idando idando is offline
Junior Member
 
Join Date: 2008-05-05
Posts: 3
Rep Power: 0
idando has an average reputation (10+)
Default another VIP for cluster

I have cluster with vip A, where the cluster object is defined with ip A and each of the 2 nodes has ip B and C on the same segmnet.
Can I set on that same segmnet another vip for the cluster, so that it would responde to vip A and D ?
thanks
idan
Reply With Quote
  #2 (permalink)  
Old 2008-05-06
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: another VIP for cluster

I believe that you are looking to do this for NAT purposes so that can have anotehr service on that IP address.

If you use Automatic NAT and set to be on the cluster then the cluster will respond to that IP address from the cluster.
Reply With Quote
  #3 (permalink)  
Old 2008-05-06
idando idando is offline
Junior Member
 
Join Date: 2008-05-05
Posts: 3
Rep Power: 0
idando has an average reputation (10+)
Default Re: another VIP for cluster

my Q was can I set 2 hide nat for the cluster so that it would listen to anothwer NAt address
Reply With Quote
  #4 (permalink)  
Old 2008-05-08
Noidea Noidea is offline
Junior Member
 
Join Date: 2008-04-10
Posts: 8
Rep Power: 0
Noidea has an average reputation (10+)
Default Re: another VIP for cluster

So what you mean is adding 2 VIP's on the Pivot?
I don't think this is possible to be honest. When using ClusterXL the VIP is handled by Checkpoint itself and not by the OS.
Reply With Quote
  #5 (permalink)  
Old 2008-05-09
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: another VIP for cluster

You can set as many hide nat ip's as you want into Check Point, as long as the IP is routed back to the cluster or the cluster proxy arps for the address.

You wouln'd configure another vip on the nokia though, just a proxy arp.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:05.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0