CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 4 of 4

Thread: redundancy Between clustered gateway

  1. #1
    Join Date
    2017-11-13
    Posts
    2
    Rep Power
    0

    Default redundancy Between clustered gateway

    HI
    i have 4 checkpoint firewall ( 5600 ) two will be deployed in the data center, and the other two will be deployed in disaster recovery site , we will be using clusterxl between each pair (DC-DR), both clusters will be having layer 2 line using OTV Cisco (overlay tunneling protocol) to serve our DMZ servers hosted on two ESXI server blade located on our data center and disaster recovery site , i was wondering are there any way to perform FHRP such as VRRP or HSRP between the two clusters (DC-DR) to add clusters redundancy .

  2. #2
    Join Date
    2007-03-30
    Location
    DFW, TX
    Posts
    422
    Rep Power
    17

    Default Re: redundancy Between clustered gateway

    Quote Originally Posted by araishee View Post
    HI
    i have 4 checkpoint firewall ( 5600 ) two will be deployed in the data center, and the other two will be deployed in disaster recovery site , we will be using clusterxl between each pair (DC-DR), both clusters will be having layer 2 line using OTV Cisco (overlay tunneling protocol) to serve our DMZ servers hosted on two ESXI server blade located on our data center and disaster recovery site , i was wondering are there any way to perform FHRP such as VRRP or HSRP between the two clusters (DC-DR) to add clusters redundancy .
    It is technically possible to sync geographically-distributed clusters. I cannot recommend doing this.

    What classes of failure are you trying to guard against? There are probably better ways to solve those problems.

  3. #3
    Join Date
    2017-11-13
    Posts
    2
    Rep Power
    0

    Default Re: redundancy Between clustered gateway

    what actually i'm trying to do is making the process of shifting my DMZ servers to DR site much more seamless and automated , by simply bringing down the inside interface of the cluster gateway on data center so the cluster on DR site can take over.

  4. #4
    Join Date
    2007-03-30
    Location
    DFW, TX
    Posts
    422
    Rep Power
    17

    Default Re: redundancy Between clustered gateway

    Quote Originally Posted by araishee View Post
    what actually i'm trying to do is making the process of shifting my DMZ servers to DR site much more seamless and automated , by simply bringing down the inside interface of the cluster gateway on data center so the cluster on DR site can take over.
    So you want to do whole-site failover?

    I typically do that by advertising the same network block from both sites with BGP, then stopping advertisement from a site when I want to take it down. You don't get stateful failover, but with how long Internet reconvergence takes, you wouldn't be likely to get that anyway.

Similar Threads

  1. Replies: 4
    Last Post: 2017-06-28, 09:16
  2. Replies: 3
    Last Post: 2012-10-10, 02:32
  3. Replies: 0
    Last Post: 2011-10-20, 03:28
  4. UTM-1 Edge and gateway with ISP redundancy
    By ice_o in forum ISP Redundancy
    Replies: 5
    Last Post: 2011-06-17, 05:35
  5. Clustered loopbacks...
    By ccie15672 in forum Clustering (Security Gateway HA and ClusterXL)
    Replies: 1
    Last Post: 2010-10-27, 01:44

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •