CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-14
Wainer19 Wainer19 is offline
Junior Member
 
Join Date: 2006-10-28
Location: Canada
Posts: 15
Rep Power: 0
Wainer19 has an average reputation (10+)
Default Single license vrrp - Management interface

Hey all,

Beginning in IPSO 4.2 Nokia has implemented single license VRRP. As some may know only the master member has CP policy installed on it and not the backup, hence only the one CP lic is being used at a time. In this configuration only the master member of the pair has all interfaces as up and on the backup only the management interface is up.

Now, lets say that I wanted to use the internet facing side of the pair so that I could remotely manage them, this would mean that the backup member with no policy installed is remotely accessable by network access.

This of course is by design, as your only paying for the one lic. But does anyone know a good way to lock down the management interface to all traffic expect that concerned with vrrp management and failover??

I'm fairly certain I could configure some IPSO ACL's for this purpose but was wondering if anyone has had any EXP with doing this? Otherwise I'm sure I can open up a ticket with Nokia and ask for a RFE.

Thanks
__________________
CCNA, CCSE, NSA, A+
Reply With Quote
  #2 (permalink)  
Old 2007-12-17
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Single license vrrp - Management interface

Presumably the box will be running the default Check Point policy as opposed to a completely open or no policy as such.

Could you not modify the default policy file to do what you want.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:24.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0