| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi, we are running NG AI R55 and I have been using SSL Network Externder on our single IP350 for some time. We are now moving to new hardware which includes a Nokia HA pair. Nokia say they support this but where do I put the licence? |
| |||
| Ideally you need to get another license from checkpoint for your secondary Nokia gateway. Since your cluster is for HA and not load balancing, you can attach the SNX license to your primary Nokia gateway, which will terminate all your SNX SSL sessions. |
| |||
| just to follow up. Both comments were of value but I don't want to upgrade to NGX just yet so I'm talking with the supplier about getting another key for the secondary until we upgrade. In case anyone is trying this I found that setting :slim_gw_ip in the slim.conf to the VRRP address was the key to getting it to answer to the the VRRP address correctly. Obvious when you think about it, the cert has to match the IP address, and this is SNX's way of setting that. Bruce |
![]() |
| Thread Tools | |
| Display Modes | |
| |