CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-22
al00ha al00ha is offline
Junior Member
 
Join Date: 2005-09-09
Posts: 10
Rep Power: 0
al00ha has an average reputation (10+)
Default ClusterXL From win2003 to SPLAT

Hi.

Anyone has any experience of upgrading a Cluster XL environment from win2003 to SPLAT?

Is it possible to have different OS on the gateways in a Cluster XL environment during upgrade?
Upgrade the first module, reconfigure GW object, the "sic" and that stuff and after that install the policy.

Running management on win2003.

/Thanks in advance
Reply With Quote
  #2 (permalink)  
Old 2006-02-23
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: ClusterXL From win2003 to SPLAT

You will probably have problem with the cluster if they are on different operating systems.
Reply With Quote
  #3 (permalink)  
Old 2006-02-24
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: ClusterXL From win2003 to SPLAT

I have the same question from the customer. Windows Management server + Windows enforcement HA migrate to leave same Management server + SPLAT HA enforcement on new hardware.

Both cluster members must be identical. This is must. I recommend to the customer the fol owing:
1. Prepare 4-5 demo licenses on the usercenter (just for emergency issue)
2. Install and configure SPLAT on a new hardware. Configure all interfaces to be in the same networks like existing but use different IPs (e.g. existing cluster members .251 .252 for new set .241 .242)
3. Initialize SIC add SPALT objects. Use demo licenses to manage this host.
*** At this point everything is sill working
Select one of the following
4.1 Create new cluster with a new addresses on the interfaces (e.g. existing .254 new .253) and reconfigure routing on surrounding equipment to point to a new cluster
4.2 Throw away bought members from existing cluster and add new SPALT nodes.
*** Use only demo licenses. Stabilize you conifg and regenerate existing licenses after a week or two.
Reply With Quote
  #4 (permalink)  
Old 2006-02-24
al00ha al00ha is offline
Junior Member
 
Join Date: 2005-09-09
Posts: 10
Rep Power: 0
al00ha has an average reputation (10+)
Default Re: ClusterXL From win2003 to SPLAT

I actually tried the upgrade yesterday and so far it seems to work.

Im using the exact same hardware on the gateway, just used a new pair of disks to the RAID set and saved the old ones in case of failure of the upgrade.

1. Installed SPLAT with the exact same config as on win2003
2. Initiated SIC
3. Started HA on SPLAT
4. Installed policy
5. pushed license to SPLAT from Smartupdate.

This took about 40 mins and i had 0 downtime on the network.The Cluster works without any problems "so far" with win2003 on one GW and SPLAT on the other.
I will let this config run for a week and then upgrade the other GW to SPLAT.


VPN-1 Pro/Express, Cluster XL, HA New Mode

GW1: Win2003 NGX R60 hfa_01
GW2: SPLAT NGX R60 hfa_02
Smartcenter: Win2003 NGX R60 hfa_01

Hardware:
HP DL380 G4
Intel MT1000 Quad
Reply With Quote
  #5 (permalink)  
Old 2006-02-24
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: ClusterXL From win2003 to SPLAT

This is really new for me. I thought only same OS clusters supported. I dig down to ClusterXL User Guide and find the flowing:

Introduction to State Synchronization
State Synchronization enables all machines in the cluster to be aware of the connections passing through each of the other machines. It ensures that if there is a failure in a cluster member, connections that were handled by the failed machine will be maintained by the other machines.

Every IP based service (including TCP and UDP) recognized by VPN-1 Pro is synchronized.

State Synchronization is used both by ClusterXL and by third-party OPSEC-certified clustering products.

Machines in a ClusterXL Load Sharing configuration must be synchronized. Machines in a ClusterXL High Availability configuration do not have to be synchronized, though if they are not, connections will be lost upon failover.

Synchronized Cluster Restrictions
The following restrictions apply to synchronizing cluster members:
1 Only cluster members running on the same platform can be synchronized.
For example, it is not possible to synchronize a Windows 2000 cluster member
with a Solaris 8 cluster member.
2 The cluster members must be the same software version.
For example, it is not possible to synchronize a Version NG FP3 cluster member with a version NGX cluster member.
... some other restrictions ...

All this mean that it is possible to have mixed platform cluster. But the sate sync is not possible.

Last edited by Sergej; 2006-02-26 at 02:28.
Reply With Quote
  #6 (permalink)  
Old 2006-02-25
intehnet intehnet is offline
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: ClusterXL From win2003 to SPLAT

Quote:
Originally Posted by Sergej

All this mean that it is possible to have mixed platform cluster. But the sate sync is not possible.
that's news to me also! pretty handy for upgrades i think...
__________________
///M
Reply With Quote
  #7 (permalink)  
Old 2006-02-26
al00ha al00ha is offline
Junior Member
 
Join Date: 2005-09-09
Posts: 10
Rep Power: 0
al00ha has an average reputation (10+)
Default Re: ClusterXL From win2003 to SPLAT

Well,, by now I have tried the failover several times without any problems.
“Fw ctl pstat” shows that the sync is ok.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:25.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0