<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure External interface in Clusterxl in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4356#M53</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically you treat each VLAN as if it were a physical interface.&lt;/P&gt;&lt;P&gt;This means:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In Gaia, after adding the&amp;nbsp;relevant VLANs to eth1, configure the networking for each VLAN as appropriate.&lt;UL&gt;&lt;LI&gt;Note it's generally not best practice for the physical (non VLAN) interface to&amp;nbsp;have an IP once you start using VLANs on a given physical interface.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;In SmartConsole, gateway and cluster objects, you will see each VLAN show up as an independent interface when you do a Get Topology. Configure each VLAN as appropriate. Ensure each VLAN has a cluster IP.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note also about the following limitation when using VLANs with ClusterXL:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61323" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61323"&gt;Monitoring of VLAN interfaces in ClusterXL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Sep 2017 03:28:06 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-09-27T03:28:06Z</dc:date>
    <item>
      <title>How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4349#M46</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please help to understand how to configure internet facing interface in #Clusterxl and also &lt;SPAN&gt;Clusterxl &lt;/SPAN&gt;with ISP redundancy&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario&amp;nbsp;1: Clusterxl high availability 14 Public IP from ISP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario&lt;SPAN&gt;&amp;nbsp;2 :&amp;nbsp; &lt;SPAN&gt;C&lt;/SPAN&gt;&lt;SPAN&gt;lusterxl high availability 14 Public IP from 2 separate&amp;nbsp;ISP ( #ISP_Redundancy )&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/tag/isp redundancy/tg-p"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;Thank you .&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;isp redundancy‌ &lt;A href="https://community.checkpoint.com/t5/tag/clusterxl/tg-p"&gt;&lt;/A&gt;‌ &lt;A href="https://community.checkpoint.com/t5/tag/Interface/tg-p"&gt;&lt;/A&gt;‌&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 03:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4349#M46</guid>
      <dc:creator>Javad_Nicou</dc:creator>
      <dc:date>2017-07-25T03:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4350#M47</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming your ISP allocated you a /28 (14 addresses after you exclude the network and broadcast), you're going to need 3 IP addresses: one for each cluster member, and one for the VIP for ClusterXL.&lt;/P&gt;&lt;P&gt;I presume the ISP's default router will also take one of those IP addresses (as the default route).&lt;/P&gt;&lt;P&gt;Both cluster members will be configured to use that default route.&lt;/P&gt;&lt;P&gt;In any case, this along with the ISP Redundancy requirement should&amp;nbsp;be a fairly standard configuration covered by the Product Documentation:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/html_frameset.htm"&gt;ClusterXL R80.10 (Part of Check Point Infinity)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have specific questions after reading the docs and can provide more details about your proposed configuration, feel free to ask.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 06:15:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4350#M47</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-07-25T06:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4351#M48</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much Dameon .&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jul 2017 05:56:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4351#M48</guid>
      <dc:creator>Javad_Nicou</dc:creator>
      <dc:date>2017-07-27T05:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4352#M49</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have followed your instruction but not sure about default gateway and static NAT . Also, I am confused about the ISP redundancy faileover , The faileover will happen in the same Firewall or faileover to standby firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default Gateway :&lt;/P&gt;&lt;P&gt;For each member what default gateway should configure? (ClusterXL mode)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT :&lt;/P&gt;&lt;P&gt;For static NAT to a web server ( static NAT to one of the IP of /28 NOT firewall IP ) do I need to create alias for each IP address and assign to Firewall external address ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How should I configure static NAT for clusterxl in ISP redundancy ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2017 05:30:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4352#M49</guid>
      <dc:creator>Javad_Nicou</dc:creator>
      <dc:date>2017-09-21T05:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4353#M50</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISP Redundancy is local to the specific gateway.&lt;/P&gt;&lt;P&gt;In a cluster it should be configured on both members.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The default route should be your primary ISPs next hop IP (again, configured on both members).&lt;/P&gt;&lt;P&gt;For NAT, you do not need to create that static IP as an alias, you merely need to make a rule in the NAT rulebase.&lt;/P&gt;&lt;P&gt;You can have multiple public IPs (for the different ISP links) for your webserver.&lt;/P&gt;&lt;P&gt;This specific example is covered in the documentation:&amp;nbsp;&lt;A class="link-titled" href="http://downloads.checkpoint.com/dc/download.htm?ID=12314" title="http://downloads.checkpoint.com/dc/download.htm?ID=12314"&gt;How To Configure ISP Redundancy&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2017 07:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4353#M50</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-21T07:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4354#M51</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if Default gateway configured as primary and primary Internet failed how firewall will handle the secondary ISP route ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;(in cluster object I have enabled the USO redundancy as primary/backup mode with next hop IP address but not sure I have to add default gateway or not in gui static route or not )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also,The static NAT to my web server is not working without creating an aliases !!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 00:15:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4354#M51</guid>
      <dc:creator>Javad_Nicou</dc:creator>
      <dc:date>2017-09-22T00:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4355#M52</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured cluster in R80.10&amp;nbsp; distributed configuration. our ISP switch port is trunk mode. how will i configure trunk in external interface. i read if i add vlan 10 in eth1 . trunk is automatic added in eth1. my problem isn't working in external trunk port interface. how will i configure trunk in cluster external interfaces&amp;nbsp; ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 02:54:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4355#M52</guid>
      <dc:creator>dorj_erdeneochi</dc:creator>
      <dc:date>2017-09-27T02:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4356#M53</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically you treat each VLAN as if it were a physical interface.&lt;/P&gt;&lt;P&gt;This means:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In Gaia, after adding the&amp;nbsp;relevant VLANs to eth1, configure the networking for each VLAN as appropriate.&lt;UL&gt;&lt;LI&gt;Note it's generally not best practice for the physical (non VLAN) interface to&amp;nbsp;have an IP once you start using VLANs on a given physical interface.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;In SmartConsole, gateway and cluster objects, you will see each VLAN show up as an independent interface when you do a Get Topology. Configure each VLAN as appropriate. Ensure each VLAN has a cluster IP.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note also about the following limitation when using VLANs with ClusterXL:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61323" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61323"&gt;Monitoring of VLAN interfaces in ClusterXL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 03:28:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4356#M53</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-27T03:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4357#M54</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/59133_Statebank cluster topology.png" style="width: 620px; height: 348px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for answer. This is my topology. i need configure trunk in checkpoint. below is what i did.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Assign VLAN on both checkpoint eth1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Put default gateway to ISP 1.1.1.4&lt;/P&gt;&lt;P&gt;3. did Get topology and configured network to external in eth1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. WG is watchguard firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; problem is: could not ping from Checkpoint to WG and ISP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;is my topology correct for this cluster?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 05:01:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4357#M54</guid>
      <dc:creator>dorj_erdeneochi</dc:creator>
      <dc:date>2017-09-27T05:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4358#M55</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A VLAN trunk only works if &lt;STRONG&gt;both ends&lt;/STRONG&gt;&amp;nbsp;are configured the same way.&lt;/P&gt;&lt;P&gt;If you plug the WatchGuard interface with a Trunk into a switch port, then that switch port &lt;STRONG&gt;must&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Support VLANs&lt;/LI&gt;&lt;LI&gt;Be configured as a trunk with the same VLANs as the WatchGuard&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Same with both Check Point devices, both on the WatchGuard side of things and on the Cisco side of things.&lt;/P&gt;&lt;P&gt;Also, on the gateway topology, the interface that should be marked as external is eth1.10 (the VLAN interface) not eth1 (the physical one).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a separate note, load sharing configurations (while supported) are generally not advised.&lt;/P&gt;&lt;P&gt;If the cluster members exceed 50% utilization and one node fails, the other member will become overloaded (which may cause a complete outage).&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 05:44:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4358#M55</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-27T05:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure External interface in Clusterxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4359#M56</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for answer. I understood from your answer that trunk port is work.&amp;nbsp; maybe i missed some configuration . can you say me some check list configuration for this&amp;nbsp; topology ? can you give phone number ? i have a some question cluster in checkpoint R80.10 ? is it possible ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 06:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-configure-External-interface-in-Clusterxl/m-p/4359#M56</guid>
      <dc:creator>dorj_erdeneochi</dc:creator>
      <dc:date>2017-09-27T06:35:34Z</dc:date>
    </item>
  </channel>
</rss>

