<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: best practice on Full HA setup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142044#M25601</link>
    <description>&lt;P&gt;I second what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;says&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_up:"&gt;👆🏻&lt;/span&gt;, Full HA cannot be considered a best practice in the first place because of certain limitations and complexity.&lt;/P&gt;
&lt;P&gt;Now, whether you want to run bot FW and MGMT on the same machine or not, it depends on where you SmartConsole client is located. It may or may not be a good idea to run MGMT on the secondary. From a performance perspective, it does make sense to keep MGMT active on your standby FW node.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Feb 2022 11:15:37 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-02-21T11:15:37Z</dc:date>
    <item>
      <title>best practice on Full HA setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142029#M25599</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently, i have a question flowed out from my mind on what is the best practice setup of FULL HA:&lt;/P&gt;&lt;P&gt;1. active management and firewall on one of the member&lt;/P&gt;&lt;P&gt;2. active management one of the member and the active firewall will be on another member&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advise and appreciate for your effort.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 09:29:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142029#M25599</guid>
      <dc:creator>LeeBingKang</dc:creator>
      <dc:date>2022-02-21T09:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: best practice on Full HA setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142030#M25600</link>
      <description>&lt;P&gt;Out of my experience, i can not recommend Full Management HA Cluster deployment at all. But yes, you would have the active FW on one and primary management on the other node.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 09:36:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142030#M25600</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-02-21T09:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: best practice on Full HA setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142044#M25601</link>
      <description>&lt;P&gt;I second what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;says&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_up:"&gt;👆🏻&lt;/span&gt;, Full HA cannot be considered a best practice in the first place because of certain limitations and complexity.&lt;/P&gt;
&lt;P&gt;Now, whether you want to run bot FW and MGMT on the same machine or not, it depends on where you SmartConsole client is located. It may or may not be a good idea to run MGMT on the secondary. From a performance perspective, it does make sense to keep MGMT active on your standby FW node.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 11:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142044#M25601</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-02-21T11:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: best practice on Full HA setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142045#M25602</link>
      <description>&lt;P&gt;Agree with the others, aim to move to a distributed setup if you can then employ HA of the respective components.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 11:20:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142045#M25602</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-21T11:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: best practice on Full HA setup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142124#M25603</link>
      <description>&lt;P&gt;Noted with thanks&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 03:49:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-practice-on-Full-HA-setup/m-p/142124#M25603</guid>
      <dc:creator>LeeBingKang</dc:creator>
      <dc:date>2022-02-22T03:49:53Z</dc:date>
    </item>
  </channel>
</rss>

