CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-14
switzer switzer is offline
Junior Member
 
Join Date: 2006-12-21
Posts: 27
Rep Power: 0
switzer has an average reputation (10+)
Default Synchronising 2 Management Servers

Hi All

We are currently going through a DR re- organisation.
We want to have two Smart Servers and we want them
to synchronise.
Do we have to put the NGX Firewalls in HA or do we have
to put the Smart Servers in HA in order to synchronise the
rule base or is there another way for them to synchronise
say at midnight each day without putting them in HA as
these are intended as Disaster Recovery and are not needed
as HA.
Hope that makes sense

Steve
Reply With Quote
  #2 (permalink)  
Old 2008-03-17
Peter Smith Peter Smith is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 14
Rep Power: 0
Peter Smith has an average reputation (10+)
Default Re: Synchronising 2 Management Servers

you need to get a licence for a secondary management server. You then load the checkpoint software onto the secondary management server (when you install the checkpoint software you simply specifiy a tick box saying "secondary management server"). Once you've installed the checkpoint software on the server you then have to go to the existing mangement server and create a new checkpoint object to represent the secondary management server. You then configure it to replicate with the secondary server (go into "manage high availability")
The two servers will act in active/ standby mode, not HA
Reply With Quote
  #3 (permalink)  
Old 2008-03-17
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Synchronising 2 Management Servers

You can either have it synchronize on policy install, or when you save the security policy. It will actually do the synchronization automatically.

One thing you will need to do though after building the secondary SMARTCenter is resic all of the existing gateways so that they know about the secondary management server and will establish a connection with it if the Primary SMARTCenter fails.

The secondary smartcenter license needs to be installed with the ip of the secondary smartcenter.

I also like to manually define my SMARTCenters on the gateways afterwards. The secondary SMARTCenter will not accept connections for logging etc unless you manually promote the SMARTCenter to become primary or it detects that the Primary has failed and the gateways start connecting to the secondary server.

I also ensure that I define my gateways with there public IP address and place manual routes on the internal network to get to them if necessary. This way when the failover occurs the secondary can still communicate with the gateway at the primary site.
Reply With Quote
  #4 (permalink)  
Old 2008-03-21
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 124
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Synchronising 2 Management Servers

One thing you will need to do though after building the secondary SMARTCenter is resic all of the existing gateways so that they know about the secondary management server and will establish a connection with it if the Primary SMARTCenter fails.


Above statement is not true, the Ica operations are pushed to second mgmt station. You just need to setup sic with this mgmt station and sync. Then open each firewall object and add backup mgmt to Masters list if it does not do it automatically.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:01.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0