CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-12
ds5879 ds5879 is offline
Junior Member
 
Join Date: 2006-11-15
Posts: 12
Rep Power: 0
ds5879 has an average reputation (10+)
Default Quick Question using HA with Load Balancing

We currently have 2 SPLAT (R65) firewalls running in Active/Standby type mode with SecureXL HA. I would like to enable the load balancing so we can utilize both firewalls instead of one just being in standby. Is this as simple as selecting that option of Load Balance under the cluster properties (or do I need a different license?)? We have a virtual ip on the inside of our firewalls for the default gw for internal clients and then a virtual IP on the outside. And if we use multicast for the load balancing does that mean that multicast routing needs to be set up on the switches that the firewall connects to? Thanks in advance!
Reply With Quote
  #2 (permalink)  
Old 2007-12-12
Pascal01 Pascal01 is offline
Junior Member
 
Join Date: 2006-11-03
Posts: 28
Rep Power: 0
Pascal01 has an average reputation (10+)
Default Re: Quick Question using HA with Load Balancing

Hi, it's indeed as simple as choosing 'load sharing' in stead of High availability in the cluster XL configuration tab. You will need a license to run in ct/act mode!
Reply With Quote
  #3 (permalink)  
Old 2007-12-13
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 347
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Quick Question using HA with Load Balancing

Active/Active is an extra license, so you will need to spend some $$. Search for "ClusterXL for Load Sharing" https://pricelist.checkpoint.com/pri...enerallist.jsp

Do you really have enough traffic that you feel you need 2 boxes running? Nowadays most firewalls can handle quite a bit of throughput.

Last edited by MarioL; 2007-12-13 at 02:40.
Reply With Quote
  #4 (permalink)  
Old 2007-12-13
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 324
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: Quick Question using HA with Load Balancing

Running Load Sharing with only two nodes is risky as well - consider the scenario where both devices are running at >50% utilisation, and one fails....

If you're serious about needing load sharing, you should be doing this with 3-4 devices to get the best results from a performance and redundancy view. The idea that you need to run load sharing to "use" the other box is not a good view to encourage.
Reply With Quote
  #5 (permalink)  
Old 2007-12-13
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: Quick Question using HA with Load Balancing

we're using ClusterXL Active/Active R55 where I am at on Intel platforms
and it is working just fine. The Enforcement module is a pair of Dell
1950 (dual Xeon 3.0 GHz with 2GB RAM). CPU is running at about 10%
on each firewall with about 500Mb memory utilization.

By the way, we use ClusterXL load-sharing unicast mode. It is
much simpler to configure and manage and broadcast mode.

It's is not risky at all.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:50.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0