<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint HA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224237#M43050</link>
    <description>&lt;P&gt;I don't think you can merge 2 standalone into a HA as they have different database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Aug 2024 05:58:29 GMT</pubDate>
    <dc:creator>just13pro</dc:creator>
    <dc:date>2024-08-22T05:58:29Z</dc:date>
    <item>
      <title>Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224222#M43037</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two checkpoint 6200, one as active and other as cold backup. Each role for device are as standalone (gateway and sms).&lt;/P&gt;&lt;P&gt;We're planning to create HA from this checkpoint, my questios are&lt;/P&gt;&lt;P&gt;1. Do we need separate Security Management to control this HA,&lt;/P&gt;&lt;P&gt;- If no need, how to achieve this?&lt;/P&gt;&lt;P&gt;- for SMS can we use VM despite purchasing other checkpoint device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Do we need to factory reset to config Cluster XL from First Time Configuration Wizard? or just create it from Smart Console?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard's&lt;/P&gt;&lt;P&gt;Satryo&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 02:36:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224222#M43037</guid>
      <dc:creator>satryo_id</dc:creator>
      <dc:date>2024-08-22T02:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224225#M43040</link>
      <description>&lt;P&gt;You can do what we call a Full High Availability Cluster, where both management and gateway are on both members. Details are in the install guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Full-HA-Cluster-on-Check-Point-Appliances.htm?TocPath=Installing%20a%20ClusterXL%2C%20VSX%20Cluster%2C%20VRRP%20Cluster%7CFull%20High%20Availability%20Cluster%20on%20Check%20Point%20Appliances%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Full-HA-Cluster-on-Check-Point-Appliances.htm?TocPath=Installing%20a%20ClusterXL%2C%20VSX%20Cluster%2C%20VRRP%20Cluster%7CFull%20High%20Availability%20Cluster%20on%20Check%20Point%20Appliances%7C_____0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can also run management on a separate VM if you wish, but you will need to purchase an additional management server license for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need to rebuild from scratch to move to a Full HA solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 02:52:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224225#M43040</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-08-22T02:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224226#M43041</link>
      <description>&lt;P&gt;Sure, i have done this before (creating Full HA), but my question is, can we do without rebuild from scratch, and how to achieve this, ex using separate SMS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard's&lt;/P&gt;&lt;P&gt;Satryo&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 02:58:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224226#M43041</guid>
      <dc:creator>satryo_id</dc:creator>
      <dc:date>2024-08-22T02:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224237#M43050</link>
      <description>&lt;P&gt;I don't think you can merge 2 standalone into a HA as they have different database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 05:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224237#M43050</guid>
      <dc:creator>just13pro</dc:creator>
      <dc:date>2024-08-22T05:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224242#M43051</link>
      <description>&lt;P&gt;You just have one defined as Primary and reset the second one, do FTW for secondary management there and other needed config; database will be synced with the primary SMS cluster node. As the rules are the same on both devices you will loose nothing...&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 09:06:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224242#M43051</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-22T09:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224254#M43058</link>
      <description>&lt;P&gt;Just to make sure, so there is no confusion, ostensibly, you want to convert full HA into 2 separate managements managing HA cluster, right?&lt;/P&gt;
&lt;P&gt;If so, you can use below link, it details everything.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/td-p/167314" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/td-p/167314&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 11:59:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224254#M43058</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-22T11:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224276#M43071</link>
      <description>&lt;P&gt;no i want to do it reverse, two standalone into HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard's&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 14:06:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224276#M43071</guid>
      <dc:creator>satryo_id</dc:creator>
      <dc:date>2024-08-22T14:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224278#M43073</link>
      <description>&lt;P&gt;Got it...yes, so what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;had said is 100% right.&lt;/P&gt;
&lt;P&gt;Sorry for my misunderstanding. And yes, you will need to rebuild, no other way around it. I know someone while back who did it without rebuilding, but it was totally unsupported, so I wont even try to explain it lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 14:09:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224278#M43073</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-22T14:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224279#M43074</link>
      <description>&lt;P&gt;For the context, this sk also might be helpful.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk60443" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk60443&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 14:12:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224279#M43074</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-22T14:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224307#M43091</link>
      <description>&lt;P&gt;As i wrote above, no merge is needed - you have a backup device with the same rulebase, or an active device with the current rulebase (that is the one i would use &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I wrote that one has to undergo FTW again and be designated the secondary management during installation. As planned, the primary node will the sync the database to the secondary.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 15:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224307#M43091</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-22T15:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224357#M43110</link>
      <description>&lt;P&gt;so i need to backup and then restore after HA up, when restoring from standalone device into HA, do it will replace HA configuration? and back to standalone. how about&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp; solution, only secondary being rebuild.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regard's&lt;/P&gt;&lt;P&gt;satryo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;reagrd's&lt;/P&gt;&lt;P&gt;satrtyo&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 06:11:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224357#M43110</guid>
      <dc:creator>satryo_id</dc:creator>
      <dc:date>2024-08-23T06:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224358#M43111</link>
      <description>&lt;P&gt;Better ask TAC for guidance - the procedure i wrote about is found in &lt;A href="https://support.checkpoint.com/results/sk/sk104699" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk104699: How to configure a Standalone machine to become a part of a &lt;STRONG&gt;Full&lt;/STRONG&gt; &lt;STRONG&gt;HA&lt;/STRONG&gt; cluster&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;, but this is not supported in R80 versions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 08:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-HA/m-p/224358#M43111</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-23T08:22:21Z</dc:date>
    </item>
  </channel>
</rss>

