<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35283#M2876</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Migration is successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steps are as per below:&lt;/P&gt;&lt;P&gt;1. Disconnection the network cables from Backup VRRP cluster in IPSO-390 appliance.&lt;/P&gt;&lt;P&gt;2. Connect the cables to Backup VRRP cluster at 5600 - Gaia appliance.&lt;/P&gt;&lt;P&gt;3. Reset SIC and fw unloadlocal and SIC is established at backup VRRP cluster.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; And, perform above 1-3 steps in Master VRRP cluster at 5600 - Gaia.&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; And then, Get topology, version at cluster object.&lt;/P&gt;&lt;P&gt;6.&amp;nbsp; Push down the policies to Cluster object. but Push policies is failed.&lt;/P&gt;&lt;P&gt;7. But, manage to resolve the issue after follow-up as per below kb. And, all of VRRP cluster are up and running and policies are able to push down the cluster object also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71724_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119212" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119212"&gt;VRRP cluster members are in "Backup/Backup" state&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, everyone in this post!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 21 Oct 2018 08:59:18 GMT</pubDate>
    <dc:creator>Myo_Min_Zaw</dc:creator>
    <dc:date>2018-10-21T08:59:18Z</dc:date>
    <item>
      <title>In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35278#M2871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together? Initial setup is both of IPSO-390 appliances are VRRP cluster? During migration, take out one IPSO-390 appliances and connect with ne 5600 Gaia R77.30 gateway and form for VRRP cluster, that is possible approach?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 03:53:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35278#M2871</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-10-15T03:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35279#M2872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only identical hardware may be used in a cluster.&lt;/P&gt;&lt;P&gt;The IP390 and 5600 are NOT identical hardware.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 11:41:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35279#M2872</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-15T11:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35280#M2873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon, Thanks a lot for your confirmation.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 12:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35280#M2873</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-10-15T12:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35281#M2874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that is to say the cluster itself will work, vrrp will work between different OS's even. Your scenario to replace the IP390's by 5600's will work just fine. The only thing is when you switch from the 390 to the 5600 you will not have session table synchronization, therefore you will loose all running connections.&lt;/P&gt;&lt;P&gt;VRRP will just do what you need it to do, keep the downtime to a bare minimum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clustering on the Checkpoint level is not available in this case, but is not really required, you just want be sure to be able to move the IP's over to the new member as soon as you change the priority.&lt;/P&gt;&lt;P&gt;One advise, make use of the command &lt;EM&gt;&lt;STRONG&gt;set vrrp disable-all-routers on&lt;/STRONG&gt;&amp;nbsp;&lt;/EM&gt;on the new members during the migration so they will not take over until you are ready.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 18:09:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35281#M2874</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-10-16T18:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35282#M2875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Maarten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your input and great explanation also. Well noted with thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 04:34:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35282#M2875</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-10-17T04:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35283#M2876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Migration is successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steps are as per below:&lt;/P&gt;&lt;P&gt;1. Disconnection the network cables from Backup VRRP cluster in IPSO-390 appliance.&lt;/P&gt;&lt;P&gt;2. Connect the cables to Backup VRRP cluster at 5600 - Gaia appliance.&lt;/P&gt;&lt;P&gt;3. Reset SIC and fw unloadlocal and SIC is established at backup VRRP cluster.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; And, perform above 1-3 steps in Master VRRP cluster at 5600 - Gaia.&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; And then, Get topology, version at cluster object.&lt;/P&gt;&lt;P&gt;6.&amp;nbsp; Push down the policies to Cluster object. but Push policies is failed.&lt;/P&gt;&lt;P&gt;7. But, manage to resolve the issue after follow-up as per below kb. And, all of VRRP cluster are up and running and policies are able to push down the cluster object also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71724_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119212" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119212"&gt;VRRP cluster members are in "Backup/Backup" state&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, everyone in this post!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Oct 2018 08:59:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35283#M2876</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-10-21T08:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35284#M2877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;cpconfig should have been run directly after the FTW and make sure clustering is enabled.&lt;/P&gt;&lt;P&gt;Also make sure that the priority is lower than the current active member and vrrp disable-all-virtual-routers is set to on.&lt;/P&gt;&lt;P&gt;Step 4 Get topology for the replaced member&lt;/P&gt;&lt;P&gt;Step 5 Push policy (uncheck the box for all members to install or not install at all)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Step 6 issue: &lt;EM&gt;set vrrp&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;disable-all-virtual-routers&amp;nbsp;off&lt;/EM&gt; on the new member&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;check state of VRRP (all backup) and cphaprob stat (active/active) to see how clustering is doing&lt;/P&gt;&lt;P&gt;If all is well continue:&lt;/P&gt;&lt;P&gt;Step 7 Switch over to the other member by raising priority on the 5600&lt;/P&gt;&lt;P&gt;Step 8 Check state of VRRP and cphaprob stat to see how clustering is doing&lt;/P&gt;&lt;P&gt;If all is well repeat step 1 to 6 on the other member.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will give you a minimal downtime (sort-of zero downtime)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Oct 2018 21:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35284#M2877</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-10-21T21:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35285#M2878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Maarten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well noted with thanks. Thanks great for your tips also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Myo Min Zaw&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 01:33:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35285#M2878</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-10-22T01:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: In VRRP cluster, IPSO-390 Voyager and 5600 Gaia R77.30 appliances together</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35286#M2879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We strongly prefer ClusterXL in HA mode over VRRP.&lt;/P&gt;&lt;P&gt;So in that case you would have a big bang moment in your transition.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/In-VRRP-cluster-IPSO-390-Voyager-and-5600-Gaia-R77-30-appliances/m-p/35286#M2879</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-10-26T08:42:46Z</dc:date>
    </item>
  </channel>
</rss>

