<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migration to ClusterXL with alias interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232904#M45041</link>
    <description>&lt;P&gt;As you are probably aware, ClusterXL does not support interface aliases.&lt;BR /&gt;However, &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Aliases.htm" target="_self"&gt;ElasticXL (in R82) does support aliases&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;A network diagram will go a long way towards helping you solve this issue, as will a detailed explanation of why interfaces aliases are "needed."&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2024 15:42:20 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-11-15T15:42:20Z</dc:date>
    <item>
      <title>Migration to ClusterXL with alias interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232902#M45039</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Good&lt;/SPAN&gt; &lt;SPAN class=""&gt;afternoon&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;The&lt;/SPAN&gt; &lt;SPAN class=""&gt;client&lt;/SPAN&gt;&lt;SPAN&gt; has &lt;/SPAN&gt;&lt;SPAN class=""&gt;an&lt;/SPAN&gt; &lt;SPAN class=""&gt;NGFW&lt;/SPAN&gt;&lt;SPAN&gt; of &lt;/SPAN&gt;&lt;SPAN class=""&gt;an&lt;/SPAN&gt; &lt;SPAN class=""&gt;unknown&lt;/SPAN&gt; &lt;SPAN class=""&gt;vendor&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;supports&lt;/SPAN&gt; &lt;SPAN class=""&gt;alias&lt;/SPAN&gt; &lt;SPAN class=""&gt;interfaces&lt;/SPAN&gt;&lt;SPAN&gt; based &lt;/SPAN&gt;&lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;cluster&lt;/SPAN&gt; &lt;SPAN class=""&gt;technology&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The &lt;/SPAN&gt;&lt;SPAN class=""&gt;external&lt;/SPAN&gt; &lt;SPAN class=""&gt;addresses&lt;/SPAN&gt; &lt;SPAN class=""&gt;look&lt;/SPAN&gt; &lt;SPAN class=""&gt;like&lt;/SPAN&gt;&lt;SPAN&gt; this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;eth0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;eth0:1 1.1.1.1/26 (VIP) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;eth0:1 1.1.1.2/26 (Node1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;eth0:1 1.1.1.3/26 (Node2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;eth0:2 1.1.1.4/26 (VIP) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;eth0:2 1.1.1.5/26 (Node1) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;eth0:2 1.1.1.6/26 (Node2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;and etc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Users&lt;/SPAN&gt; &lt;SPAN class=""&gt;access&lt;/SPAN&gt; &lt;SPAN class=""&gt;resources&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;addresses&lt;/SPAN&gt; &lt;SPAN class=""&gt;1.1.1.1&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;1.1.1.3&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;1.1.1.7&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;so&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN class=""&gt;Aliases&lt;/SPAN&gt; &lt;SPAN class=""&gt;cannot&lt;/SPAN&gt;&lt;SPAN&gt; be &lt;/SPAN&gt;&lt;SPAN class=""&gt;transferred&lt;/SPAN&gt; &lt;SPAN class=""&gt;due&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;restrictions&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; The &lt;/SPAN&gt;&lt;SPAN class=""&gt;separation&lt;/SPAN&gt;&lt;SPAN&gt; of the vlans will &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;work&lt;/SPAN&gt; &lt;SPAN class=""&gt;due&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;inability&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;use&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;same&lt;/SPAN&gt; &lt;SPAN class=""&gt;address&lt;/SPAN&gt; &lt;SPAN class=""&gt;space&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;several&lt;/SPAN&gt; &lt;SPAN class=""&gt;vilan&lt;/SPAN&gt; &lt;SPAN class=""&gt;interfaces&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I&lt;/SPAN&gt;&lt;SPAN&gt;'ve been &lt;/SPAN&gt;&lt;SPAN class=""&gt;racking&lt;/SPAN&gt; &lt;SPAN class=""&gt;my&lt;/SPAN&gt; &lt;SPAN class=""&gt;brain&lt;/SPAN&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;SPAN class=""&gt;how&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;transfer&lt;/SPAN&gt;&lt;SPAN&gt; this &lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;CheckPoint&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you &lt;/SPAN&gt;&lt;SPAN class=""&gt;have&lt;/SPAN&gt; &lt;SPAN class=""&gt;any&lt;/SPAN&gt; &lt;SPAN class=""&gt;ideas&lt;/SPAN&gt;&lt;SPAN class=""&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 15:32:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232902#M45039</guid>
      <dc:creator>okatsladz454</dc:creator>
      <dc:date>2024-11-15T15:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Migration to ClusterXL with alias interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232903#M45040</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Routing and NAT but there may not be enough information here to say this would work conclusively for you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Basically separate the subnets used for connectivity versus the addresses offering / publishing services.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 15:40:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232903#M45040</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-11-15T15:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Migration to ClusterXL with alias interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232904#M45041</link>
      <description>&lt;P&gt;As you are probably aware, ClusterXL does not support interface aliases.&lt;BR /&gt;However, &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Aliases.htm" target="_self"&gt;ElasticXL (in R82) does support aliases&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;A network diagram will go a long way towards helping you solve this issue, as will a detailed explanation of why interfaces aliases are "needed."&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 15:42:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232904#M45041</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-15T15:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Migration to ClusterXL with alias interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232923#M45046</link>
      <description>&lt;P&gt;You can create Proxy ARP for this instead of interfaces probably.&lt;/P&gt;
&lt;P&gt;You create eth0 as Cluster interface with 1.1.1.1 as ClusterXL IP and whatever for physical IP of each cluster member, if you still have free IP in the /26 otherwise use private IP with local-scope, there is an SK for that.&lt;/P&gt;
&lt;P&gt;You can then add on each cluster member Proxy ARP matching eth0 for the physical address which will make it that ETH0 will answer for 1.1.1.1, 1.1.1.2 and so on, on the active member.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 21:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-to-ClusterXL-with-alias-interface/m-p/232923#M45046</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-11-15T21:16:26Z</dc:date>
    </item>
  </channel>
</rss>

