<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint 3800 SMB ClusterXL in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141904#M21948</link>
    <description>&lt;P&gt;Thanks Val and Chris - appreciate the prompt respones.&lt;/P&gt;&lt;P&gt;Would you have any thoughts on my licensing query?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;One other question as an aside, when managing on prem FWs from an Azure SMS server, how does the licensing work, in terms of the central IP address - does it make more sense to do local licensing?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;For central licensing of the SMB GW, do I need a static IP for the SMS server?&lt;/P&gt;</description>
    <pubDate>Fri, 18 Feb 2022 13:26:51 GMT</pubDate>
    <dc:creator>superd</dc:creator>
    <dc:date>2022-02-18T13:26:51Z</dc:date>
    <item>
      <title>Checkpoint 3800 SMB ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141897#M21944</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Im trying to deploy two Checkpoint 3800s with ClusterXL.&lt;/P&gt;&lt;P&gt;Ive enabled clusterXL using cpconfig. And its telling me I need a policy pushed in order to start the HA module.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;FW02:0]# cphastart&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;cphastart: Policy should be installed to run the command&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I understand the clusterXL settings will be primarily deployed from SMS server. But from the local firewall point of view theres no HA sync interface, so Im trying to understand how the firewalls physically connect for HA sync. Is it just a matter of enabling HA sync on one of the ETH ports, and connecting back to back?&lt;/P&gt;&lt;P&gt;Im running R80.40, and ultimately they will be managed by an Azure SMS server.&lt;/P&gt;&lt;P&gt;Note, the boxes are not licensed yet. Ideally this will be deployed from the Azure SMS centrally.&lt;/P&gt;&lt;P&gt;One other question as an aside, when managing on prem FWs from an Azure SMS server, how does the licensing work, in terms of the central IP address - does it make more sense to do local licensing?&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 12:59:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141897#M21944</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-02-18T12:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 3800 SMB ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141900#M21945</link>
      <description>&lt;P&gt;Can you please explain what you mean by saying: &lt;EM&gt;"But from the local firewall point of view theres no HA sync interface, so Im trying to understand how the firewalls physically connect for HA sync"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;When you will be configuring the cluster in SmarConsole, you will have to chose one of NICs to be a sync. What do you mean "&lt;EM&gt;by local firewall point of view&lt;/EM&gt;"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 13:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141900#M21945</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-02-18T13:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 3800 SMB ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141901#M21946</link>
      <description>&lt;P&gt;Ah ok, so the actual sync interface is defined on SMS?&lt;/P&gt;&lt;P&gt;From a previous firewall deployment, I had a physical HA interface for sync. I guess that was throwing me off.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So essentially, should I just select an unused ETH port and connect it back to back, and then configure the sync IP addressing on the SMS server?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 13:12:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141901#M21946</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-02-18T13:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 3800 SMB ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141903#M21947</link>
      <description>&lt;P&gt;That's pretty much it, in SMS you fetch/configure the Gateway interface topology as you've configured on the appliance via Web UI/CLI.&lt;/P&gt;
&lt;P&gt;It's here you also define the VIP for each non Sync interface.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 13:17:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141903#M21947</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-18T13:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 3800 SMB ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141904#M21948</link>
      <description>&lt;P&gt;Thanks Val and Chris - appreciate the prompt respones.&lt;/P&gt;&lt;P&gt;Would you have any thoughts on my licensing query?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;One other question as an aside, when managing on prem FWs from an Azure SMS server, how does the licensing work, in terms of the central IP address - does it make more sense to do local licensing?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;For central licensing of the SMB GW, do I need a static IP for the SMS server?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 13:26:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141904#M21948</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-02-18T13:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 3800 SMB ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141910#M21949</link>
      <description>&lt;P&gt;For reference sk155632 talks to some of the caveats of your choice of IP/License mapping during upgrades.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 14:10:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141910#M21949</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-18T14:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint 3800 SMB ClusterXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141912#M21950</link>
      <description>&lt;P&gt;The interface which is labeled "Sync" on other boxes is just an interface with a weird name. There's nothing at all special about it. Any interface (or set of interfaces bonded together) can be used for state sync.&lt;/P&gt;
&lt;P&gt;Sync should always be run through a switch. Direct-wired sync can cause the remaining member to refuse to take over the cluster if a member fails.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 14:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-3800-SMB-ClusterXL/m-p/141912#M21950</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-02-18T14:46:08Z</dc:date>
    </item>
  </channel>
</rss>

