CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-10
Testing-123 Testing-123 is offline
Member
 
Join Date: 2007-07-27
Posts: 74
Rep Power: 1
Testing-123 has an average reputation (10+)
Default Single module to cluster

Hello All,

I'm upgrading from a single firewall solution to a cluster due to resiliency requirements. I'm comfortable with creating a cluster in FW-1 and enabling cpha on the primary firewall but was looking at ways in which i could minimise downtime.

Anyone have any advice from previous experience?

The firewalls will be running NGX R60 and as a VRRP cluster (active-passive). I would ideally like to use the physical ip addresses assigned to the existing firewall as VIP addresses and introduce a secondary so that routing tables on devices connecting through the firewall do not have to be changes.

Regards
Testing-123
Reply With Quote
  #2 (permalink)  
Old 2008-05-10
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 612
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: Single module to cluster

In the lab:

1- build the secondary firewall with VRRP and use the physical IP address
of the primary fireall as VRRP but remove this firewall from the network
so that you do not have IP conflict.

2- install the latest HFA on the secondary firewall. Make sure you have
the ip address in place,

3- perform fw unloadlocal,

4- perform SIC with the secondary from the SmartCenter, create gateway
cluster and so forth,

5- push policy to the firewall cluster from the SmartCenter,

6- bring everything down,

7- bring up the SmartCenter and the Secondary nokia into your
production network, but have the switchport shutdown for these
devices,

8- shutdown the primary firewall,

9- enable the switchports for the secondary Nokia and the SmartCenter.
Clear the CAM table on the layer-2 switch and clear arp on the
upstream router,

10- At this point, traffics should flow normal,

11- rebuild the primary nokia and put it into the cluster,

12- push policy to the cluster again,

12- if everything goes accordingly, you should be down no more
than 30 seconds, depending on how fast your are with step 8 and step 9,

I used to do this all the time when I work as an engineer for an MSSP,
we managed nothing but Nokia devices with Provider-1,


Enjoy!!!!!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0