CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-14
Junior Member
 
Join Date: 2006-02-14
Posts: 2
Rep Power: 0
F1LL82 has an average reputation (10+)
Default Checkpoint Express and VRRP

Hello all.

Up till now my organisation has always used a Nokia IP130 with a checkpoint express license running with both the enforcement and management modules on the nokia box. We have recently purchased two Nokia IP350's and two more checkpoint express license's with the plan being to implement a VRRP cluster that is centrally managed from a windows based machine.

Firstly, are these licenses suitable for what we have in mind. I have seen various posts on the net referring to a HA license. Is this necessary for use with VRRP?
Secondly, after re reading through some of the "Essential Checkpoint Firewall-1 NG" book on how to build this centrally managed cluster i notice a few differences to what i see when installing. I am presuming this is down to upgraded versions of IPSO and Checkpoint. The version of IPSO both IP350's are running is 3.0 build 41 and Checkpoint is NGX R60. When i run this initial setup of CPCONFIG i am presented with the options Checkpoint enterprise pro and Checkpoint express CI. as my license is for Checkpoint express would i be right in thinking that it is the express i need to install? If this is the case, will i still be prompted to decide between if i want it to act as a standalone or distributed server. I ask before trying as i have had long drawn out problems going through the reinstall of checkpoint in the past and would prefer to avoid doing so again.

Any help or suggestions would be greatly appreciated.

Regards,
Phill
Reply With Quote
  #2 (permalink)  
Old 2006-02-14
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Checkpoint Express and VRRP

Quote:
Originally Posted by F1LL82
I have seen various posts on the net referring to a HA license. Is this necessary for use with VRRP?

The version of IPSO both IP350's are running is 3.0 build 41 and Checkpoint is NGX R60.

When i run this initial setup of CPCONFIG i am presented with the options Checkpoint enterprise pro and Checkpoint express CI. as my license is for Checkpoint express would i be right in thinking that it is the express i need to install? If this is the case, will i still be prompted to decide between if i want it to act as a standalone or distributed server.
You don't need an HA license to run VRRP on IPSO. It's a function of IPSO, you will just need a firewall license for both appliances.

I'm presuming that you ment 4.0 build 41.

In all of my past installations, every time I pick anything with express, it installs it as a standalone (management and firewall on one) which is not what you want in a VRRP cluster. I would install the pro, I think you can still put the express license on it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:07.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0