<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117608#M16618</link>
    <description>&lt;P&gt;yes and yes&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 07:59:59 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-05-04T07:59:59Z</dc:date>
    <item>
      <title>Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are moved?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117396#M16590</link>
      <description>&lt;P&gt;We have Cloudguard R80.10 gws [48 of them] running on a VMWARE NSX-V Cluster 's hosts.&lt;/P&gt;&lt;P&gt;These Cloud guard gws are managed by R80.40 manager.&lt;/P&gt;&lt;P&gt;When VMs are moved between hosts in the VMWARE cluster, all connections drop, and we were of the understanding that all individual Cloudguard gateways are in sync, so that when VMs are moved, traffic will flow without drops [ie... without seeing First packet is no syn].&lt;/P&gt;&lt;P&gt;When I looked at fw tab -t connections -s in individual gateways, I can see the numbers are very different, meaning, Cloud guard gateways are not in sync so it is obvious that when VMs move between hosts in the VMWARE cluster, Is there any fix or workaround that we can apply? This must be a common issue for many out there.&lt;/P&gt;&lt;P&gt;I dont see there is any mechanism that runs among these Cloud guard gateways to do tcp/ udp state synchronisation like Cluster XL, so I can guess the answer. I am bit confused because at the time of selling the product, we questioned the same feature and the answer was it does keep "in sync" the statetable among Cloud gurads, not sure whether we tried that indeed in a lab and took the word on its own merit.&lt;/P&gt;&lt;P&gt;So your expert reply is very much appreciated with any tips and tricks.&lt;/P&gt;&lt;P&gt;Thank you and Kind regards,&lt;/P&gt;&lt;P&gt;Kanishka&lt;/P&gt;</description>
      <pubDate>Sat, 01 May 2021 10:58:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117396#M16590</guid>
      <dc:creator>kanishkaw</dc:creator>
      <dc:date>2021-05-01T10:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117539#M16605</link>
      <description>&lt;P&gt;Did you configure your group of CloudGuard gateways as a cluster object (CloudGuard NSX Admin Guide, page 34 and below)?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 11:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117539#M16605</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-03T11:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117542#M16607</link>
      <description>&lt;P&gt;Thank you _Val_.&lt;/P&gt;&lt;P&gt;Please see below. Yes we have a cluster defined and the same policy is applied to all members.&lt;/P&gt;&lt;P&gt;How do I verify state sync is happening and all the members have the same tcp state info, (and udp state info as well if applicable for udp).&lt;/P&gt;&lt;P&gt;Appreciate your reply with thanks.&lt;/P&gt;&lt;P&gt;Kanishka&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 11:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117542#M16607</guid>
      <dc:creator>kanishkaw</dc:creator>
      <dc:date>2021-05-03T11:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117544#M16608</link>
      <description>&lt;P&gt;cphaprob stat on any of the cluster members should show you the cluster status.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 12:02:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117544#M16608</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-03T12:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117574#M16612</link>
      <description>&lt;P&gt;Hi _Val_&lt;/P&gt;&lt;P&gt;It says "HA module not started". What steps can I take to enable HA among members?&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 17:25:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117574#M16612</guid>
      <dc:creator>kanishkaw</dc:creator>
      <dc:date>2021-05-03T17:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117599#M16615</link>
      <description>&lt;P&gt;"cpconfig", look for clusterxl settings. Also, policy push is required again.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 06:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117599#M16615</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-04T06:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117606#M16617</link>
      <description>&lt;P&gt;Thank you _Val_.&lt;/P&gt;&lt;P&gt;Did you mean this option (as attached) in the Cloudguard R80.10 gateway?&lt;/P&gt;&lt;P&gt;Is this service impacting to enable it? Do I want a maintenance window?&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;Kanishka&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 07:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117606#M16617</guid>
      <dc:creator>kanishkaw</dc:creator>
      <dc:date>2021-05-04T07:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117608#M16618</link>
      <description>&lt;P&gt;yes and yes&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 07:59:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117608#M16618</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-04T07:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117610#M16620</link>
      <description>&lt;P&gt;Also, the cluster object itself should have dedicated sync network. Considering the nature of your question, I would advise looking for professional services engagement with Check Point or a third party having some experience in this kind of deployment.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If not, build a lab environment, study the guide and make it work in the lab first, to build up expertise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 08:02:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117610#M16620</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-04T08:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard R80.10 gws running on a VMWARE NSX-V Cluster - Is state sync working when VMs are mov</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117892#M16681</link>
      <description>&lt;P&gt;Thanks _Val_.&amp;nbsp; We are going to enable Sync link and ClusterXL in a maint window. Thanks for the replies which clarified what should be done.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 07:01:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cloudguard-R80-10-gws-running-on-a-VMWARE-NSX-V-Cluster-Is-state/m-p/117892#M16681</guid>
      <dc:creator>kanishkaw</dc:creator>
      <dc:date>2021-05-07T07:01:32Z</dc:date>
    </item>
  </channel>
</rss>

