CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-11
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default what is a monitored private interface

hi all i am new to cluster XL. I couldn;t get much info on the monitored private interface. what is this interface and why and when would be need a monitored private interface.

any info would be great.

regards

sebastan
Reply With Quote
  #2 (permalink)  
Old 2008-05-11
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 119
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: what is a monitored private interface

Here is a basic break down of where you would use this option.

Lets say you have two machines in a cluster that have 4 interfaces each. You only need an internal, external and sync. You would mark the left over interface as non monitored private so the clustering software would not send ccp packets on udp 8116 to get status on this interface. I will also use this option if I need to plug in this interface but I am not ready to cluster the subnet connected on this interface.
Reply With Quote
  #3 (permalink)  
Old 2008-05-11
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: what is a monitored private interface

hi mate thanks for ur reply. but as per the documentation it states something else.

here is from the documentation.

When defining VLAN tags on an interface, cluster IP addresses can be defined only on the VLAN interfaces (the tagged interfaces). Defining a cluster IP address on a physical interface that has VLANs is not supported. This physical interface has to be defined with the Network Objective Monitored Private.

can u pls help part i am not getting it clearly.

waiting for ur reply mate,

regards

sebastan
Reply With Quote
  #4 (permalink)  
Old 2008-05-12
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 119
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: what is a monitored private interface

That is another use aswell. Do you plan on using vlans ?
Reply With Quote
  #5 (permalink)  
Old 2008-05-13
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: what is a monitored private interface

yeah mate since there is some problem with my splat and since it recognises only one single nic. i am planning to use vlans for creating the internal dna external interface and even the sync interface on vlans.

is this possible cause i read in NGX R65 sync interface is supported on vlan interface though not recommended.

waiting for ur reply.

regards

sebastan
Reply With Quote
  #6 (permalink)  
Old 2008-05-13
jaskaran224 jaskaran224 is offline
Junior Member
 
Join Date: 2008-05-11
Posts: 16
Rep Power: 0
jaskaran224 has an average reputation (10+)
Default Re: what is a monitored private interface

you should have atleast two separate physical interface for defining internal and external... however u can have sync interface by creating a vlan on internal one..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:25.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0