<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create ClusterXL from Single Firewall - Step in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162413#M28874</link>
    <description>&lt;P&gt;Sounds like they already have external management.&lt;BR /&gt;You build the second gateway object, then create the cluster using the two existing gateways.&lt;BR /&gt;If you want to make the ClusterXL VIPs use the same IPs as the first gateway, then you should probably change it before creating the cluster object.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Nov 2022 23:49:35 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-11-17T23:49:35Z</dc:date>
    <item>
      <title>Create ClusterXL from Single Firewall - Step</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162387#M28865</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;i have an use case in my customer environment, so currently they use 5200 single for Perimeter and External firewall + smart-1 410.&lt;/P&gt;&lt;P&gt;and in this month, they will buy a new 2 firewall using 6200 for perimeter. so 5200 would use as clusterXL for external firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does anyone has idea in the easiest way how to create clusterxl on 5200 when running single firewall at beginning? do i need to scratch/fresh install to do that? thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 16:38:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162387#M28865</guid>
      <dc:creator>MtxMan</dc:creator>
      <dc:date>2022-11-17T16:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Create ClusterXL from Single Firewall - Step</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162392#M28867</link>
      <description>&lt;P&gt;I believe below is an official process:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61681" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61681&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 17:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162392#M28867</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-17T17:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Create ClusterXL from Single Firewall - Step</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162413#M28874</link>
      <description>&lt;P&gt;Sounds like they already have external management.&lt;BR /&gt;You build the second gateway object, then create the cluster using the two existing gateways.&lt;BR /&gt;If you want to make the ClusterXL VIPs use the same IPs as the first gateway, then you should probably change it before creating the cluster object.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 23:49:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162413#M28874</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-17T23:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Create ClusterXL from Single Firewall - Step</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162414#M28875</link>
      <description>&lt;P&gt;If the firewall is changing role from external / internal this sounds like it would require changes &amp;amp; down time - what is the concern about starting from scratch here?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 23:55:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162414#M28875</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-17T23:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Create ClusterXL from Single Firewall - Step</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162429#M28876</link>
      <description>&lt;P&gt;Nope, this one is to break StandAlone config and make it a distributed implementation. The topic starter is asking about how to replace a single GW with a cluster.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 08:06:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162429#M28876</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-18T08:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Create ClusterXL from Single Firewall - Step</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162433#M28880</link>
      <description>&lt;P&gt;Yup, my bad. I think what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote makes sense. I will see if I can find what TAC guy gave me last year for that for a customer who wanted to do the same.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 08:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162433#M28880</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-18T08:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Create ClusterXL from Single Firewall - Step</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162448#M28890</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/76092"&gt;@MtxMan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;As promised in my last reply, Im sending you steps TAC gave me almost 2 years ago when customer needed this done. Since it does not let me attach a file here, I pasted the actual link he sent us a reference (Version is R80.30, as thats what customer was on back then, but Im positive process is exactly the same for any version)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/48/4808360334cfd91e38eb192da36ea686/CP_R80.30_ClusterXL_AdminGuide.pdf?HashKey=1668783673_3b18bc01df1f70808798acefeb08c025&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/48/4808360334cfd91e38eb192da36ea686/CP_R80.30_ClusterXL_AdminGuide.pdf?HashKey=1668783673_3b18bc01df1f70808798acefeb08c025&amp;amp;xtn=.pdf&lt;/A&gt;&amp;nbsp; (same doc, just in pdf format)&lt;/P&gt;
&lt;P&gt;Below is exactly what TAC guy sent us and we followed it and worked fine. Its pretty much boils what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;described in layman terms.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;Process:&lt;/P&gt;
&lt;P&gt;The documentation mentions the Standalone deployment for those who have a Standalone firewall and would like to convert it to ClusterXL. In your situation, you can go straight to page 151. "Creating the ClusterXL Object"&lt;BR /&gt;&lt;BR /&gt;Computer B refers to your new firewall and Computer A is your current firewall.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Basically here are the steps:&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Install and configure the new cluster member. (Computer B)&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;make sure that the new firewall can talk to the old firewall and vice versa.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Configure the local configuration such as&amp;nbsp;authentication server,&amp;nbsp;hostname, static route, dynamic route etc.&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;In the policy, remove any references to the old firewall.&lt;/LI&gt;
&lt;LI&gt;Create a new cluster object in SmartConsole.&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Configure the interfaces, Antispoofing, Office mode etc.&amp;nbsp;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;The cluster VIP will be the old firewall local IP&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;LI&gt;Open the Cluster object and in the "Cluster Members" page, click Add, and select New Cluster Member.&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Establish SIC&lt;/LI&gt;
&lt;LI&gt;Get interface without topology&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Define a Sync interface&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;Install the policy on the cluster currently including member B only.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;On the old firewall.&amp;nbsp;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Disconnect all proposed cluster and Synchronization interfaces. New connections now open&lt;BR /&gt;through the cluster, instead of through computer 'A'.&lt;/LI&gt;
&lt;LI&gt;Change the addresses of these interfaces to some other unique IP address which is on the&lt;BR /&gt;same subnet as computer B.&lt;/LI&gt;
&lt;LI&gt;Connect each pair of interfaces of the same subnet using a dedicated network. Any hosts or&lt;BR /&gt;Security Gateways previously connected to the Security Gateway must now be connected to&lt;BR /&gt;both members, using a hub/switch.&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;Update the topology of the Security Gateway that you just added by clicking Get Topology without interface.&lt;/LI&gt;
&lt;LI&gt;In the Cluster Members page, click Add and select "Add Security Gateway to Cluster"&amp;nbsp;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Select the&amp;nbsp;old firewall&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;In the "Edit Topology" page, determine the interface type.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;Configure the Policy base. (VPN domain, rule base, NAT if needed)&lt;/LI&gt;
&lt;LI&gt;Install the policy.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 18 Nov 2022 13:03:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-ClusterXL-from-Single-Firewall-Step/m-p/162448#M28890</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-18T13:03:57Z</dc:date>
    </item>
  </channel>
</rss>

