<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cluster with only one member in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201590#M4493</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We want in the future to have a two firewall cluster, but at the moment only have one firewall (and license).&lt;/P&gt;&lt;P&gt;In order to make it easier in the future to add a second firewall, we want to set it up initially as a cluster.&lt;/P&gt;&lt;P&gt;We configured one interface as "sync" (required by SmartConsole), but the cluster object always is red since ClusterXL is not working (obviously).&lt;/P&gt;&lt;P&gt;Is there a way to have the single firewall ignore the "cluster problems" so the object will be green?&lt;/P&gt;&lt;P&gt;Or is the only way to change it back to a single firewall (cpconfig -&amp;gt; Disable cluster membership for this gateway), add it to SmartConsole as a standalone firewall object,&amp;nbsp; and in the future perform cpconfig-&amp;gt; re-enable cluster membership?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: It is a GCP CloudGuard firewall.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Dec 2023 11:02:53 GMT</pubDate>
    <dc:creator>Micha</dc:creator>
    <dc:date>2023-12-27T11:02:53Z</dc:date>
    <item>
      <title>Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201590#M4493</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We want in the future to have a two firewall cluster, but at the moment only have one firewall (and license).&lt;/P&gt;&lt;P&gt;In order to make it easier in the future to add a second firewall, we want to set it up initially as a cluster.&lt;/P&gt;&lt;P&gt;We configured one interface as "sync" (required by SmartConsole), but the cluster object always is red since ClusterXL is not working (obviously).&lt;/P&gt;&lt;P&gt;Is there a way to have the single firewall ignore the "cluster problems" so the object will be green?&lt;/P&gt;&lt;P&gt;Or is the only way to change it back to a single firewall (cpconfig -&amp;gt; Disable cluster membership for this gateway), add it to SmartConsole as a standalone firewall object,&amp;nbsp; and in the future perform cpconfig-&amp;gt; re-enable cluster membership?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: It is a GCP CloudGuard firewall.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 11:02:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201590#M4493</guid>
      <dc:creator>Micha</dc:creator>
      <dc:date>2023-12-27T11:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201591#M4494</link>
      <description>&lt;P&gt;I guess this is the classical "works as designed" behavior and i don't see any reason why a feature "ignore cluster problems" would make sense. So i would prefer using the simple gateway as it is and convert it to cluster later on when purchasing second cluster member device.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 11:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201591#M4494</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-12-27T11:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201601#M4495</link>
      <description>&lt;P&gt;Personally, but again, this is just my own opinion, I would not bother until you are ready to have a working custer. I mean, you can always enable/disable cluster membership option from the cpconfig menu (I know few customers who enabled that initially via default wizard, but then you can toggle it after from the menu, just needs a reboot).&lt;/P&gt;
&lt;P&gt;Alternatively, you can then set up all the needed cluster interfaces. I could be mistaken, but if I recall, you only technically need sync interface for functioning cluster. No, I think thats not true, as you need VIP for the cluster IP object, so that would make it 1 + sync, so thats 2.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 14:02:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201601#M4495</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-27T14:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201622#M4496</link>
      <description>&lt;P&gt;Forming a cluster requires two or more nodes to be active.&lt;BR /&gt;With a single member, there is no cluster, thus it will always appear "red" by design.&lt;BR /&gt;I wouldn't enable ClusterXL until you are ready to establish the cluster.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 18:28:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201622#M4496</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-27T18:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201625#M4497</link>
      <description>&lt;P&gt;The headache with moving from a single firewall to a cluster later is you then have to take a hard outage to change the IPs on the interfaces and use the old IPs as VIPs (or to change the routes on all adjacent things). If you start with a single-member cluster, you can add a second member at any time with zero traffic impact. This can be a big deal for locations which don't have qualified people nearby.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 18:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201625#M4497</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-12-27T18:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201648#M4498</link>
      <description>&lt;P&gt;Yep but since this is a Cloud deployment and we don't have context of the scale of the deployment I would encourage some further discussion with the local account team, Vsec / Cloudguard cores can be relatively inexpensive.&lt;/P&gt;
&lt;P&gt;Also does the topology mandate a traditional cluster vs auto-scale / MIG ?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 22:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201648#M4498</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-27T22:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201724#M4501</link>
      <description>&lt;P&gt;That is 100% true.&lt;BR /&gt;Hopefully ElasticXL will take some of this pain away.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 17:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201724#M4501</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-28T17:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201727#M4502</link>
      <description>&lt;P&gt;Are you saying this would work with elasticXL? if so, that would be pretty cool : - )&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 17:53:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201727#M4502</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-28T17:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201738#M4505</link>
      <description>&lt;P&gt;In short, yes, it should.&lt;/P&gt;
&lt;P&gt;ElasticXL will use much of the same technology that was developed for Maestro and Scalable Platforms.&lt;BR /&gt;Unlike with ClusterXL where you have to define the individual members before creating the cluster object, Maestro only requires a single management object, which is nothing more than a standard gateway object.&lt;BR /&gt;Members are added via the Orchestrator in Maestro and there will be gclish commands in R82 to add cluster members.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 20:42:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201738#M4505</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-28T20:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201740#M4507</link>
      <description>&lt;P&gt;Cool! But this will ONLY be possible on Maestro, nor regular Gaia gateways?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 20:43:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201740#M4507</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-28T20:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with only one member</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201741#M4508</link>
      <description>&lt;P&gt;ElasticXL is ultimately replacing ClusterXL on regular gateways.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 20:50:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cluster-with-only-one-member/m-p/201741#M4508</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-28T20:50:11Z</dc:date>
    </item>
  </channel>
</rss>

