| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| 1/Install primary management server and firewalls 2/Install SmartCenter Server on a secondary management station. At install time, configure it as a secondary management server. 3/Create a secondary management server in SmartDashboard. Establish SIC. Install database on the secondary management server (important for logging failover). 4/ Policy -> Management High Availability - synchronise the secondary. 5/ Global Properties -> Management HA - configure the options you want for automatic sync. 6/ On each firewall object, change the masters to include both management stations. Configure the logging as required - generally you will configure it to log to one of the management stations, then fail over to the other if required. Install policy to the firewalls. That's pretty much all there is to it. Of course, if there are any firewalls between the management stations, they will need to be updated to allow comms between the management stations. |
| |||
| Yes. I've done this many times. You need to allow a fair bit of comms between the two management stations - e.g CPD, CPD_amon, CP_redundant, etc. There's probably a definitive list around somewhere. Check your routing, and check what your logs are telling you - are you seeing any drops between the two management stations (I know, it's not the ideal way to do it, but sometimes necessary) |
| |||
| Guys, Im wondering if you can help. I have configured my secondary SCS, created the checkpoint host on the primary SCS, confirmed SIC is working. I can push the masters policy down to the Secondary SCS, but the "Management High Availability" Button is greyed out. What am I missing here? Both SCS have enterprise licenses installed. They are sat on the same LAN, so no protocol blocking. Everything I have read, confirms what I have done, but..... its not working :( |
| |||
| Could you just clarify what you mean by "can push the masters policy down" - are you referring to doing a database install? Also, do you mean the "Management High Availability" menu option, not button? And I take it the object has "Secondary Management Server" checked in the object definition? |
| |||
| Yes I can install the Masters DB Yes you are correct the menu option And Yes, on the Primary SCS, I have set the Secondary option for the object, and also confirmed SIC status. When I use SmartView Monitor, and query the status of the Secondary SCS, i get an error message saying the CA DB hasnt be initalised? |
![]() |
| Thread Tools | |
| Display Modes | |
| |