CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-13
greenhold greenhold is offline
Junior Member
 
Join Date: 2007-07-20
Posts: 6
Rep Power: 0
greenhold has an average reputation (10+)
Default Splat HA without ClusterXL

I have installed 2 ngx65 splat servers and 1 smartcenter ngx65 splat server. The 2 enforcement's are FW/VPN only, they were setup as cluster members, and then the Smartcenter server was setup as just the primary smartcenter server only.

I have pulled the topology into smartdashboard for both enforcements, sic is good, etc.. and I have setup the VIP's for the external and interal cluster topology. However I cannot ping the internal or external VIP's (there is an any any rule setup and when I dump the interfaces the pings to the VIP aren't showing up on either fw or in the logs)...

I've been looking through the ClusterXL doc's, but they aren't much help... Do you still use VIP's with classic HA and no clusterXL? Thanks for any feedback!
Reply With Quote
  #2 (permalink)  
Old 2007-11-13
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Splat HA without ClusterXL

You should create a Check Point Cluster object and then attach both boxes into the cluster. You then define the Cluster IP on the Cluster Object.

Set the CLusterXL to be High Availability and that should be all. You still use ClusterXL and it should be enabled at the cli of the gateway.
Reply With Quote
  #3 (permalink)  
Old 2007-11-13
greenhold greenhold is offline
Junior Member
 
Join Date: 2007-07-20
Posts: 6
Rep Power: 0
greenhold has an average reputation (10+)
Default Re: Splat HA without ClusterXL

I did create the Cluster object and add the members, but I removed the checkbox from the ClusterXL option, since I just want to do HA without ClusterXL... So I need to leave the ClusterXL checked and I won't have to buy a ClusterXL license?
Reply With Quote
  #4 (permalink)  
Old 2007-11-13
greenhold greenhold is offline
Junior Member
 
Join Date: 2007-07-20
Posts: 6
Rep Power: 0
greenhold has an average reputation (10+)
Default Re: Splat HA without ClusterXL

Well the VIP does now respond and everything is working as I had originally hoped it would, I just want to confirm that I won't have to buy a ClusterXL license?

Thanks again for your time!
Reply With Quote
  #5 (permalink)  
Old 2007-11-13
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 335
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Splat HA without ClusterXL

A ClusterXL license is only required if you want to use Load-Sharing. In active-standby, no CXL license is required.
Reply With Quote
  #6 (permalink)  
Old 2007-11-14
greenhold greenhold is offline
Junior Member
 
Join Date: 2007-07-20
Posts: 6
Rep Power: 0
greenhold has an average reputation (10+)
Default Re: Splat HA without ClusterXL

Great, Thanks!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:17.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0