<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VRRP between Checkpoint and Forcepoint Clusters in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-between-Checkpoint-and-Forcepoint-Clusters/m-p/157036#M27215</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we are planning to extend our infrastructure to a second data center (stretched cluster). On one side we have a Checkpoint FW cluster and on the other side we have a Forcepoint FW cluster. We want to have an active/passive scenario for the Gateways. This should be achieved using VRRP. Will this work using VRRP between the 2 clusters even if they are not from the same manufacturer? VRRP(or CARP) should be an open protocol and thus should do the job?!? Has anyone experience with such a scenario?&lt;/P&gt;&lt;P&gt;Any help is highly appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Michl&lt;/P&gt;</description>
    <pubDate>Mon, 12 Sep 2022 12:18:48 GMT</pubDate>
    <dc:creator>Michl</dc:creator>
    <dc:date>2022-09-12T12:18:48Z</dc:date>
    <item>
      <title>VRRP between Checkpoint and Forcepoint Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-between-Checkpoint-and-Forcepoint-Clusters/m-p/157036#M27215</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we are planning to extend our infrastructure to a second data center (stretched cluster). On one side we have a Checkpoint FW cluster and on the other side we have a Forcepoint FW cluster. We want to have an active/passive scenario for the Gateways. This should be achieved using VRRP. Will this work using VRRP between the 2 clusters even if they are not from the same manufacturer? VRRP(or CARP) should be an open protocol and thus should do the job?!? Has anyone experience with such a scenario?&lt;/P&gt;&lt;P&gt;Any help is highly appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Michl&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 12:18:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-between-Checkpoint-and-Forcepoint-Clusters/m-p/157036#M27215</guid>
      <dc:creator>Michl</dc:creator>
      <dc:date>2022-09-12T12:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP between Checkpoint and Forcepoint Clusters</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-between-Checkpoint-and-Forcepoint-Clusters/m-p/157066#M27216</link>
      <description>&lt;P&gt;While VRRP is an open standard (RFC-2338), I don't believe any vendor actually supports mixing and matching cluster members from different vendors.&lt;/P&gt;
&lt;P&gt;A failover between say Forcepoint and Check Point, while likely handled at the Layer 3 level, will fail spectacularly for any in progress connections as there is no state sync of Layer 7 information between the different vendor solutions.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 14:30:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-between-Checkpoint-and-Forcepoint-Clusters/m-p/157066#M27216</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-12T14:30:57Z</dc:date>
    </item>
  </channel>
</rss>

