<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall cluster interface design question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/143975#M22385</link>
    <description>&lt;P&gt;Hi.&amp;nbsp; Ive got the opportunity to replace an old existing appliance cluster with another new appliance cluster (way faster hardware).&amp;nbsp; The old cluster has a configuration that looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw1&lt;/P&gt;&lt;P&gt;bond1 on switch 1 -&amp;gt; internal vlans, cluster sync vlans&lt;/P&gt;&lt;P&gt;bond2 on switch 1 -&amp;gt; external vlans/interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw2&lt;/P&gt;&lt;P&gt;bond1 on switch 2 -&amp;gt; internal vlans, cluster sync vlans&lt;/P&gt;&lt;P&gt;bond2 on switch 2 -&amp;gt; external vlans/interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Performance has been fine and we dont come close to saturating a gig.&amp;nbsp; The load on this cluster is low and the projected growth of the traffic in the next few years is low as well.&amp;nbsp; Anyone have suggestions on a different design or am I good?&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2022 19:40:56 GMT</pubDate>
    <dc:creator>PIAndre</dc:creator>
    <dc:date>2022-03-16T19:40:56Z</dc:date>
    <item>
      <title>Firewall cluster interface design question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/143975#M22385</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; Ive got the opportunity to replace an old existing appliance cluster with another new appliance cluster (way faster hardware).&amp;nbsp; The old cluster has a configuration that looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw1&lt;/P&gt;&lt;P&gt;bond1 on switch 1 -&amp;gt; internal vlans, cluster sync vlans&lt;/P&gt;&lt;P&gt;bond2 on switch 1 -&amp;gt; external vlans/interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw2&lt;/P&gt;&lt;P&gt;bond1 on switch 2 -&amp;gt; internal vlans, cluster sync vlans&lt;/P&gt;&lt;P&gt;bond2 on switch 2 -&amp;gt; external vlans/interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Performance has been fine and we dont come close to saturating a gig.&amp;nbsp; The load on this cluster is low and the projected growth of the traffic in the next few years is low as well.&amp;nbsp; Anyone have suggestions on a different design or am I good?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 19:40:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/143975#M22385</guid>
      <dc:creator>PIAndre</dc:creator>
      <dc:date>2022-03-16T19:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cluster interface design question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144029#M22391</link>
      <description>&lt;P&gt;Different design would depend partly on the switch capabilities, are they fully independent or clustered / stacked in some way?&lt;/P&gt;
&lt;P&gt;Most importantly it comes down to requirements... maybe Sync / DMZ on separate ports etc but would depend on hardware constraints.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 14:08:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144029#M22391</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-18T14:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cluster interface design question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144084#M22403</link>
      <description>&lt;P&gt;Its a modern switch stack.&amp;nbsp; If there arent any issues with how the old cluster is configured I guess Ill continue to do the same thing.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 16:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144084#M22403</guid>
      <dc:creator>PIAndre</dc:creator>
      <dc:date>2022-03-17T16:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cluster interface design question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144090#M22404</link>
      <description>&lt;P&gt;So long as you are using multiple bonds in a cluster, I'd recommend keeping Sync on a separate one, if there are ports available on a switch stack to accommodate it. That said, I am prone to over-engineering for redundancy to cover even for low-probability events.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 17:39:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144090#M22404</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-03-17T17:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cluster interface design question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144123#M22410</link>
      <description>&lt;P&gt;Do you want things deterministic i.e. switch 1 fails then firewall 1 fails ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise some might mesh the bond slaves to try and protect against switch failure.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 23:19:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144123#M22410</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-17T23:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cluster interface design question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144138#M22414</link>
      <description>&lt;P&gt;fully agree, also our preferred setup:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/Working-with-VLANs-in-Cluster.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ClusterXL_AdminGuide/Topics-CXLG/Working-with-VLANs-in-Cluster.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;fw1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;bond1 on switch 1 -&amp;gt; internal vlans&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;bond2 on switch 1 -&amp;gt; external vlans/interfaces&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;bond3 -&amp;gt;&amp;nbsp;cluster sync vlan&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;fw2&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;bond1 on switch 2 -&amp;gt; internal vlans&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;bond2 on switch 2 -&amp;gt; external vlans/interfaces&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;bond3 -&amp;gt;&amp;nbsp;cluster sync vlan&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 09:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-cluster-interface-design-question/m-p/144138#M22414</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2022-03-18T09:01:51Z</dc:date>
    </item>
  </channel>
</rss>

