CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Interoperability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-28
K2Technologies K2Technologies is offline
Junior Member
 
Join Date: 2007-03-11
Posts: 10
Rep Power: 0
K2Technologies has an average reputation (10+)
Default SmartCenter on VMWare

Has anyone used a VM running Windows (server 2000/3) as their SmartCenter server? Is this supported or even recommended?
Reply With Quote
  #2 (permalink)  
Old 2007-03-28
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 876
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SmartCenter on VMWare

I've never used VMWare but I have installed SmartCenter R62 & R65 on Microsoft Virtual Server 2005 R2 for testing and it runs fine. SmartCenter is not a product that does anything weird, so I doubt you would have any problems.

Virtual servers can present a physical security issue, though, if they are running on a box that runs other virtual servers. Non-security admins that have access to the virtual server now have physical access to the SmartCenter server. If there's no controls over the browser management interface, you have the same problem. They've got access to the logon screen.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-03-28
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: SmartCenter on VMWare

Vmware is not officially supported. Yepp it works like a charm but you may experience cold shoulder from checkpoint support if you need their help in future.
Reply With Quote
  #4 (permalink)  
Old 2007-03-28
Reaper Reaper is offline
Member
 
Join Date: 2006-11-15
Location: Tallinn, Estonia
Posts: 82
Rep Power: 2
Reaper has an average reputation (10+)
Send a message via Skype™ to Reaper
Default Re: SmartCenter on VMWare

SmartCenter R62 working ok on Red Hat Enterprise Linux on VMWare on Linux. Problem is the clock drift, to solve update clock frequently with ntpdate (ntpd does not work because of too big too random clock drift).
__________________
CCNA certified
Reply With Quote
  #5 (permalink)  
Old 2007-04-05
Dzenboy Dzenboy is offline
Junior Member
 
Join Date: 2007-02-26
Posts: 25
Rep Power: 0
Dzenboy has an average reputation (10+)
Default Re: SmartCenter on VMWare

i have my smartcenter server on vmware win 2000 for testing aims. it works pretty good.
Reply With Quote
  #6 (permalink)  
Old 2007-05-10
wowtek wowtek is offline
Junior Member
 
Join Date: 2006-05-16
Location: Poland, wielkopolska, Poznan
Posts: 23
Rep Power: 0
wowtek has an average reputation (10+)
Send a message via Skype™ to wowtek
Default Re: SmartCenter on VMWare

I use many smart centers, firewalls, connectra and other software under VMWare Server in my lab and I don't have any "hardware/system" problem with this system.
I support few commerce installation, with smart center under VMWare server/ESX and my client don't have any platform specific problem.
In my opinion the platform is critical for support gateway platform, but on smart center platform (VMWare) have second role.
Reply With Quote
  #7 (permalink)  
Old 2007-06-12
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 135
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: SmartCenter on VMWare

Tac will not support it, only vsx
Reply With Quote
  #8 (permalink)  
Old 2007-06-22
masterloo masterloo is offline
Junior Member
 
Join Date: 2006-06-22
Posts: 19
Rep Power: 0
masterloo has an average reputation (10+)
Default Re: SmartCenter on VMWare

I've heard some rumblings that limited support for certain CP products may be on the way.. liek Eventia.. we'll see.
And not to be redundant here ;) but I've run CP R55-R62 on VMware for lab and testing environment and have not found any real problems (win2k/3, Splat, RHEL)
Reply With Quote
  #9 (permalink)  
Old 2007-06-23
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SmartCenter on VMWare

Quote:
Originally Posted by Routerkid1 View Post
Tac will not support it, only vsx
VSX is not supported on VMWare
Reply With Quote
  #10 (permalink)  
Old 2007-06-23
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SmartCenter on VMWare

Quote:
Originally Posted by masterloo View Post
I've heard some rumblings that limited support for certain CP products may be on the way.. liek Eventia.. we'll see.
I haven't heard anything about Eventia on VMWare, but by the end of the year you should start seeing support for at least one product on VMWare Infrastructure and blade servers.

Quote:
And not to be redundant here ;) but I've run CP R55-R62 on VMware for lab and testing environment and have not found any real problems (win2k/3, Splat, RHEL)
We all know it works, and sometimes you can even get support on a SmartCenter running on VMWare but not much else.

If the first project proves not to be a support nightmare, I would suspect you will see official VMWare support for some of the other management products, but not for gateways.

Note -- none of what I just said is anything but guessing on my part and rumors I've heard, nothing official.
Reply With Quote
  #11 (permalink)  
Old 2007-08-10
beefdart beefdart is offline
Junior Member
 
Join Date: 2007-07-11
Posts: 1
Rep Power: 0
beefdart has an average reputation (10+)
Default Re: SmartCenter on VMWare

Quote:
Originally Posted by Reaper View Post
SmartCenter R62 working ok on Red Hat Enterprise Linux on VMWare on Linux. Problem is the clock drift, to solve update clock frequently with ntpdate (ntpd does not work because of too big too random clock drift).
that is a common misconception... If you are going to run anything production in VMware: http://www.vmware.com/pdf/vmware_timekeeping.pdf is a must-read.

ntpd or heavy use of ntpdate will slaughter the performance of your VMs. VMware has a timekeeping function already, just poorly documented.

all that being said... SPLAT works great in VMware, and if you really try hard... IPSO does too :]
Reply With Quote
  #12 (permalink)  
Old 2008-06-12
dreambuddy dreambuddy is offline
Junior Member
 
Join Date: 2007-06-12
Posts: 8
Rep Power: 0
dreambuddy has an average reputation (10+)
Default Re: SmartCenter on VMWare

Quote:
all that being said... SPLAT works great in VMware, and if you really try hard... IPSO does too :]
Fellow Members/Seniors,

It's a news for me.. can we run IPSO under VMWare, if we have the image. Have anyone really achieved this. It's seemingly hard to believe, keeping in mind IPSO is an appliance.

Regards
-=KIK=-
Reply With Quote
  #13 (permalink)  
Old 2008-06-13
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: SmartCenter on VMWare

IPSO is based on BSD so in theory no reason why not. I haven't tried it myself as if going to do this then SPLAT is easier to get going.

SMARTCenter and Connectra and VPN-1 are now all tested and certified to run with VMWare ESX/ESXi providing on SPLAT.
Reply With Quote
  #14 (permalink)  
Old 2008-06-13
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 139
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: SmartCenter on VMWare

Quote:
SMARTCenter and Connectra and VPN-1 are now all tested and certified to run with VMWare ESX/ESXi providing on SPLAT.
Do you have a link to a document from Checkpoint where the certification is confirmed?
I like to read a document, where this setup is described, for example with/without VMware-tools ...
Reply With Quote
  #15 (permalink)  
Old 2008-06-14
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 135
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: SmartCenter on VMWare

Quote:
Originally Posted by Routerkid1 View Post
Tac will not support it, only vsx

Correction I intended to say ESX not VSX.
Reply With Quote
  #16 (permalink)  
Old 2008-06-15
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SmartCenter on VMWare

Quote:
Originally Posted by dsb.nepo View Post
Do you have a link to a document from Checkpoint where the certification is confirmed?
I like to read a document, where this setup is described, for example with/without VMware-tools ...
Posted on the HCL Check Point Software: Virtual Machines for VPN-1 and Connectra on SecurePlatform -

No vmware tools as of yet.
Reply With Quote
  #17 (permalink)  
Old 2008-06-15
fireverse fireverse is offline
Junior Member
 
Join Date: 2007-05-01
Posts: 11
Rep Power: 0
fireverse has an average reputation (10+)
Default Re: SmartCenter on VMWare

Link to Check Point VMWare document:

From the document:

VPN-1 NGX R65 for VMware supports the following VMware ESX Server versions:
• VMware ESX Server versions 3.0.2, 3.5 or 3i
• VirtualCenter 2.0.1 or higher (Optional - useful for managing multiple ESX Server hosts using
a single GUI client, cloning virtual components and deploying objects from templates)

VPN-1 NGX R65 for VMware currently supports the following Check Point products:
• VPN-1 Power NGX R65
• VPN-1 UTM NGX R65
• VPN-1 Power UTM NGX R65
• SmartCenter NGX R65

BTW if you are looking at hosting more than one SmartCenter on VMware, you should consider Provider-1 Enterprise. Will be more cost effective:

SmartCenter Power Unlimited = $22k
P1 Enterprise 3 (equivalent to 3 SmartCenter Powers) = $45k

A separate SmartCenter for your Internet, WAN, and data center is a common architecture when moving away from a single SmartCenter.

HTH
Reply With Quote
  #18 (permalink)  
Old 2008-06-17
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SmartCenter on VMWare

Quote:
Originally Posted by fireverse View Post
BTW if you are looking at hosting more than one SmartCenter on VMware, you should consider Provider-1 Enterprise. Will be more cost effective:

SmartCenter Power Unlimited = $22k
P1 Enterprise 3 (equivalent to 3 SmartCenter Powers) = $45k
Please note that P1 is not supported in ESX and in fact doesn't work.

For testing though, it does work with workstation and GSX (the free version of Server). Not good for production, but to look at.
Reply With Quote
  #19 (permalink)  
Old 2008-06-21
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 139
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: SmartCenter on VMWare

@chillyjim,fireverse
Thanks for the link to the documents

One point that is special interesting at ESX Clusters
Quote:
Known Limitations
----------------------------
2. VMotion is not supported
3. VMtools is not supported
Reply With Quote
  #20 (permalink)  
Old 2008-06-22
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SmartCenter on VMWare

Yeah none of the add-on packages are supported. Hopefully at some point they be if there is enough customer demand for them.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:27.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0