<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster with Single Public IP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33014#M2629</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's correct. A SMS will not be able to manage Cluster over the Internet if that cluster is configured according to &lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&amp;quot;" rel="nofollow"&gt;sk32073&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Mar 2018 00:45:42 GMT</pubDate>
    <dc:creator>KernelGordon</dc:creator>
    <dc:date>2018-03-01T00:45:42Z</dc:date>
    <item>
      <title>Cluster with Single Public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33009#M2624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a cluster I am setting up behind a Cradlepoint running Verizon as the only ISP. I have a single static IP from Verizon. I'm curious how other folks have solved this. Would you trick the external interface with private IPs and static NAT them to the single Public IP? My first time working with a firewall behind cellular. Just looking for the simplest way to configure the external interfaces and VIP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 16:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33009#M2624</guid>
      <dc:creator>Kevin_Orrison</dc:creator>
      <dc:date>2018-02-28T16:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with Single Public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33010#M2625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're trying to set up a cluster with only public IP then I would suggest looking at &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&amp;quot;"&gt;sk32073&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 20:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33010#M2625</guid>
      <dc:creator>KernelGordon</dc:creator>
      <dc:date>2018-02-28T20:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with Single Public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33011#M2626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is going to be a site-to-site VPN cluster. Does the below note from this SK mean that I will not be able to initialize SIC using the method described in this SK? Could I NAT the member external interfaces to the static external IP to be used in the VIP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;"It is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;not&lt;/EM&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;possible to manage over the Internet the Cluster when IP addresses Addresses of its members and the VIP address are configured on different subnets.&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 14px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;In such configuration, the IP addresses of cluster members are supposed to be configured with private IP addresses (&lt;/SPAN&gt;&lt;A href="https://tools.ietf.org/html/rfc1918" style="color: #905690; background-color: #ffffff; text-decoration: none; font-size: 14px;" target="_blank"&gt;RFC 1918&lt;/A&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;), and only one Cluster VIP address is supposed to be public.&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 14px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Private IP addresses (&lt;/SPAN&gt;&lt;A href="https://tools.ietf.org/html/rfc1918" style="color: #905690; background-color: #ffffff; text-decoration: none; font-size: 14px;" target="_blank"&gt;RFC 1918&lt;/A&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;) are&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;not&lt;/EM&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;allowed over the Internet.&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 14px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;As a result, communication from the external Management Server to the private IP addresses of the physical cluster members will&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;not&lt;/EM&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;be possible over the Internet for services such as SIC."&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 22:02:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33011#M2626</guid>
      <dc:creator>Kevin_Orrison</dc:creator>
      <dc:date>2018-02-28T22:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with Single Public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33012#M2627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The note from the SK means that you will not be able to manage this cluster remotely. If the Management Server is local to this cluster then you will be fine. The reasoning for this is explained by RFC 1918.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 22:10:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33012#M2627</guid>
      <dc:creator>KernelGordon</dc:creator>
      <dc:date>2018-02-28T22:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with Single Public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33013#M2628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the SMS is in the data center. You're saying with this "different subnet for VIP" configuration I won't be able to centrally manage the remote site firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 22:15:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33013#M2628</guid>
      <dc:creator>Kevin_Orrison</dc:creator>
      <dc:date>2018-02-28T22:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster with Single Public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33014#M2629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's correct. A SMS will not be able to manage Cluster over the Internet if that cluster is configured according to &lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&amp;quot;" rel="nofollow"&gt;sk32073&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2018 00:45:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-with-Single-Public-IP/m-p/33014#M2629</guid>
      <dc:creator>KernelGordon</dc:creator>
      <dc:date>2018-03-01T00:45:42Z</dc:date>
    </item>
  </channel>
</rss>

