<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How To's: Deploy Check Point ClusterXL and VRRP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-To-s-Deploy-Check-Point-ClusterXL-and-VRRP/m-p/97652#M7577</link>
    <description>&lt;P&gt;Hi there, in this post we're going to deploy a pair of Check Point gateways running ClusterXL and another pair running VRRP.&lt;/P&gt;&lt;P&gt;This posts, assumes you already have CMA/SMS deployed, SmartConsole installed and FTW configuration done.&lt;/P&gt;&lt;P&gt;We’ll begin adding the gateways for Site A. Most of the configuration we’ll be done using SmartConsole.&lt;/P&gt;&lt;P&gt;Login to SmartConsole, and access the pane&lt;STRONG&gt; Gateways &amp;amp; Servers &amp;gt; New &amp;gt; Gateway&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Fill the following options:&lt;/P&gt;&lt;P&gt;Name&lt;/P&gt;&lt;P&gt;IPv4 Address&lt;/P&gt;&lt;P&gt;Communication &amp;gt; Authentication &amp;gt; One-time password&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 759px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8181iA2EAFE5739CBDDD9/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 535px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8182i70ECC0914F4B8C7D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 699px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8183i1F554A6388A77AE1/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now add the licences using SmartUpdate.&lt;/P&gt;&lt;P&gt;I already explained how to add the licences in the link below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Deploying-Check-Point-Solution-R80-40/m-p/94267/highlight/true#M18657" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Deploying-Check-Point-Solution-R80-40/m-p/94267/highlight/true#M18657&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Next, let’s enable ClusterXL feature usig GAIA. Run &lt;STRONG&gt;cpconfig&amp;nbsp;&lt;/STRONG&gt;and choose option 8.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8160i6A940D83235A3E69/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Once the gateways are back online, let’s create the Cluster object. In &lt;STRONG&gt;Gateways &amp;amp; Servers pane &amp;gt; New &amp;gt; Cluster &amp;gt; Check Point Gateway Cluster Creation &amp;gt; Classic Mode&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 332px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8161i3BA833E9388D38FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;A title="Silesio C." href="http://www.linkedin.com/in/silesio-carvalho" target="_blank" rel="noopener"&gt;&amp;lt;bottom&amp;gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fill the Name and IPv4 Address in General Properties.&lt;/P&gt;&lt;P&gt;Next go to Cluster Members pane and add both Gateways by choosing &lt;STRONG&gt;Add Existing Gateway&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Accept the warning message.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8162i71329D29D54822E8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Now let’s proceed to Network Management pane.&lt;/P&gt;&lt;P&gt;Choose &lt;STRONG&gt;Get Interfaces with Topology&lt;/STRONG&gt; and accept the warning related to spoofing.&lt;/P&gt;&lt;P&gt;Change the interfaces values accordingly:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Eth0 – Network Type: Cluster &amp;gt; IPv4: 192.168.234.101/24&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Eth1 – Network Type: Sync&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Eth3 – Network Type: Cluster &amp;gt; IPv4: 203.0.113.1/24&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 736px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8163i392F32CE1983EE02/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If we look at the ClusterXL and VRRP pane, we see that by default High Availability is selected.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 672px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8164i54294A928B4EBA0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Finally let’s proceed to IPSec VPN pane, and set &lt;STRONG&gt;Link Selection&lt;/STRONG&gt; to gateway external IP address&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.png" style="width: 758px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8165i1C520646442DC9C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="9.png" alt="9.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Press ok and the cluster object will be created.&lt;/P&gt;&lt;P&gt;Let’s create a rule for testing purposes. We’ll configure Hide nat for our internal network.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8166i7BBBADA804758DF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="10.png" alt="10.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 500px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8167i867E915F265BFB9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can verify ClusterXL status in&lt;STRONG&gt; Gateways &amp;amp; Servers&lt;/STRONG&gt; pane, by selecting the cluster object and clicking monitor&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.png" style="width: 716px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8168i744D72F05AF6B718/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.png" alt="12.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Press ok and the cluster object will be created.&lt;/P&gt;&lt;P&gt;Let’s create a rule for testing purposes. We’ll configure Hide nat for our internal network.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8166i7BBBADA804758DF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="10.png" alt="10.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 500px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8167i867E915F265BFB9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can verify ClusterXL status in &lt;STRONG&gt;Gateways &amp;amp; Servers&lt;/STRONG&gt; pane, by selecting the cluster object and clicking monitor&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.png" style="width: 716px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8168i744D72F05AF6B718/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.png" alt="12.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can verify also using GAIA by running the command &lt;STRONG&gt;show cluster state&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;So far we have deployed ClusterXL for Site A, now let’s deploy VRRP for Site B.&lt;/P&gt;&lt;P&gt;The adding process will be a little different because the gateways are in a different network, the idea is to simulate a remote site.&lt;/P&gt;&lt;P&gt;Let’s make CMA accessible in external network:&lt;/P&gt;&lt;P&gt;Add a rule allowing the CMA (A_SMS) and translate CMA internal IP to an external IP. Edit CMA object, on &lt;STRONG&gt;NAT&lt;/STRONG&gt; tab, &lt;STRONG&gt;Translation Method&lt;/STRONG&gt; choose &lt;STRONG&gt;static&lt;/STRONG&gt;, Translate to IP Address IPv4 Address:&lt;STRONG&gt; 203.0.113.111&lt;/STRONG&gt;, Install on Gateway &lt;STRONG&gt;A-GW-Cluster. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8169iC63100917635E63F/image-size/large?v=v2&amp;amp;px=999" role="button" title="13.png" alt="13.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="14.png" style="width: 760px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8170i4F2461E20F249AD0/image-size/large?v=v2&amp;amp;px=999" role="button" title="14.png" alt="14.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now perform the same steps as we did before, to add the gateways.&lt;/P&gt;&lt;P&gt;Once they are added, let’s create the cluster object for Site B gateways.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="15.png" style="width: 760px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8171i7B08833C2A812547/image-size/large?v=v2&amp;amp;px=999" role="button" title="15.png" alt="15.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;First clear the &lt;STRONG&gt;ClusterXL&lt;/STRONG&gt; box in &lt;STRONG&gt;Network Security.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;A new pane will be shown as &lt;STRONG&gt;3rd Party Configuration&lt;/STRONG&gt;. Set the &lt;STRONG&gt;Cluster Mode to High Availability&lt;/STRONG&gt; and &lt;STRONG&gt;3rd Party Solution&lt;/STRONG&gt; as &lt;STRONG&gt;Check Point IPSO VRRP.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="16.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8172i83C037A413E3CEA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="16.png" alt="16.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In Network Management Pane, Get the interfaces with Topology and change the values as described below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="17.png" style="width: 764px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8173i66E80840D5FBA469/image-size/large?v=v2&amp;amp;px=999" role="button" title="17.png" alt="17.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Press Ok.&lt;/P&gt;&lt;P&gt;Add a new Policy Package and set as the Installation targets the new cluster gateway&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="18.png" style="width: 671px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8174i5F80160BF4986537/image-size/large?v=v2&amp;amp;px=999" role="button" title="18.png" alt="18.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Press OK.&lt;/P&gt;&lt;P&gt;Create some basic rules and install the policy for Site B.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="19.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8175i5BA150963FE1C75F/image-size/large?v=v2&amp;amp;px=999" role="button" title="19.png" alt="19.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Let’s configure the VRRP parameters on Site B gateways. Access web page of Site B gateways:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20.png" style="width: 741px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8176i355949C8A6BEC961/image-size/large?v=v2&amp;amp;px=999" role="button" title="20.png" alt="20.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Access the page&amp;nbsp;&lt;STRONG&gt;High Availability &amp;gt; VRRP &amp;gt; Virtual Routers &amp;gt; Add&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21.png" style="width: 745px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8177i65BFBE700421BEF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="21.png" alt="21.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On gateway B-GW-02 we’ll set a lower Priority and the Router ID has to be the same as specified in B-GW-01.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="22.png" style="width: 641px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8178iB8835B9E7E9DA625/image-size/large?v=v2&amp;amp;px=999" role="button" title="22.png" alt="22.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once it’s done, install the policy to reflect the new changes.&lt;/P&gt;&lt;P&gt;We can successfully confirm the cluster status.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="23.png" style="width: 853px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8179i6BAE651BF88337DE/image-size/large?v=v2&amp;amp;px=999" role="button" title="23.png" alt="23.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="24.png" style="width: 609px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8180iE20B97859472DF64/image-size/large?v=v2&amp;amp;px=999" role="button" title="24.png" alt="24.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope you enjoyed this post, leave your comments below and I'll see you on the next post.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Sun, 27 Sep 2020 15:55:49 GMT</pubDate>
    <dc:creator>Silesio</dc:creator>
    <dc:date>2020-09-27T15:55:49Z</dc:date>
    <item>
      <title>How To's: Deploy Check Point ClusterXL and VRRP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-To-s-Deploy-Check-Point-ClusterXL-and-VRRP/m-p/97652#M7577</link>
      <description>&lt;P&gt;Hi there, in this post we're going to deploy a pair of Check Point gateways running ClusterXL and another pair running VRRP.&lt;/P&gt;&lt;P&gt;This posts, assumes you already have CMA/SMS deployed, SmartConsole installed and FTW configuration done.&lt;/P&gt;&lt;P&gt;We’ll begin adding the gateways for Site A. Most of the configuration we’ll be done using SmartConsole.&lt;/P&gt;&lt;P&gt;Login to SmartConsole, and access the pane&lt;STRONG&gt; Gateways &amp;amp; Servers &amp;gt; New &amp;gt; Gateway&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Fill the following options:&lt;/P&gt;&lt;P&gt;Name&lt;/P&gt;&lt;P&gt;IPv4 Address&lt;/P&gt;&lt;P&gt;Communication &amp;gt; Authentication &amp;gt; One-time password&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 759px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8181iA2EAFE5739CBDDD9/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 535px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8182i70ECC0914F4B8C7D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 699px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8183i1F554A6388A77AE1/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now add the licences using SmartUpdate.&lt;/P&gt;&lt;P&gt;I already explained how to add the licences in the link below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Deploying-Check-Point-Solution-R80-40/m-p/94267/highlight/true#M18657" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Deploying-Check-Point-Solution-R80-40/m-p/94267/highlight/true#M18657&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Next, let’s enable ClusterXL feature usig GAIA. Run &lt;STRONG&gt;cpconfig&amp;nbsp;&lt;/STRONG&gt;and choose option 8.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8160i6A940D83235A3E69/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Once the gateways are back online, let’s create the Cluster object. In &lt;STRONG&gt;Gateways &amp;amp; Servers pane &amp;gt; New &amp;gt; Cluster &amp;gt; Check Point Gateway Cluster Creation &amp;gt; Classic Mode&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 332px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8161i3BA833E9388D38FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;A title="Silesio C." href="http://www.linkedin.com/in/silesio-carvalho" target="_blank" rel="noopener"&gt;&amp;lt;bottom&amp;gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fill the Name and IPv4 Address in General Properties.&lt;/P&gt;&lt;P&gt;Next go to Cluster Members pane and add both Gateways by choosing &lt;STRONG&gt;Add Existing Gateway&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Accept the warning message.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8162i71329D29D54822E8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Now let’s proceed to Network Management pane.&lt;/P&gt;&lt;P&gt;Choose &lt;STRONG&gt;Get Interfaces with Topology&lt;/STRONG&gt; and accept the warning related to spoofing.&lt;/P&gt;&lt;P&gt;Change the interfaces values accordingly:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Eth0 – Network Type: Cluster &amp;gt; IPv4: 192.168.234.101/24&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Eth1 – Network Type: Sync&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Eth3 – Network Type: Cluster &amp;gt; IPv4: 203.0.113.1/24&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 736px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8163i392F32CE1983EE02/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If we look at the ClusterXL and VRRP pane, we see that by default High Availability is selected.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 672px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8164i54294A928B4EBA0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Finally let’s proceed to IPSec VPN pane, and set &lt;STRONG&gt;Link Selection&lt;/STRONG&gt; to gateway external IP address&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.png" style="width: 758px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8165i1C520646442DC9C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="9.png" alt="9.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Press ok and the cluster object will be created.&lt;/P&gt;&lt;P&gt;Let’s create a rule for testing purposes. We’ll configure Hide nat for our internal network.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8166i7BBBADA804758DF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="10.png" alt="10.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 500px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8167i867E915F265BFB9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can verify ClusterXL status in&lt;STRONG&gt; Gateways &amp;amp; Servers&lt;/STRONG&gt; pane, by selecting the cluster object and clicking monitor&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.png" style="width: 716px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8168i744D72F05AF6B718/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.png" alt="12.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Press ok and the cluster object will be created.&lt;/P&gt;&lt;P&gt;Let’s create a rule for testing purposes. We’ll configure Hide nat for our internal network.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8166i7BBBADA804758DF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="10.png" alt="10.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 500px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8167i867E915F265BFB9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can verify ClusterXL status in &lt;STRONG&gt;Gateways &amp;amp; Servers&lt;/STRONG&gt; pane, by selecting the cluster object and clicking monitor&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12.png" style="width: 716px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8168i744D72F05AF6B718/image-size/large?v=v2&amp;amp;px=999" role="button" title="12.png" alt="12.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can verify also using GAIA by running the command &lt;STRONG&gt;show cluster state&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;So far we have deployed ClusterXL for Site A, now let’s deploy VRRP for Site B.&lt;/P&gt;&lt;P&gt;The adding process will be a little different because the gateways are in a different network, the idea is to simulate a remote site.&lt;/P&gt;&lt;P&gt;Let’s make CMA accessible in external network:&lt;/P&gt;&lt;P&gt;Add a rule allowing the CMA (A_SMS) and translate CMA internal IP to an external IP. Edit CMA object, on &lt;STRONG&gt;NAT&lt;/STRONG&gt; tab, &lt;STRONG&gt;Translation Method&lt;/STRONG&gt; choose &lt;STRONG&gt;static&lt;/STRONG&gt;, Translate to IP Address IPv4 Address:&lt;STRONG&gt; 203.0.113.111&lt;/STRONG&gt;, Install on Gateway &lt;STRONG&gt;A-GW-Cluster. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8169iC63100917635E63F/image-size/large?v=v2&amp;amp;px=999" role="button" title="13.png" alt="13.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="14.png" style="width: 760px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8170i4F2461E20F249AD0/image-size/large?v=v2&amp;amp;px=999" role="button" title="14.png" alt="14.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now perform the same steps as we did before, to add the gateways.&lt;/P&gt;&lt;P&gt;Once they are added, let’s create the cluster object for Site B gateways.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="15.png" style="width: 760px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8171i7B08833C2A812547/image-size/large?v=v2&amp;amp;px=999" role="button" title="15.png" alt="15.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;First clear the &lt;STRONG&gt;ClusterXL&lt;/STRONG&gt; box in &lt;STRONG&gt;Network Security.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;A new pane will be shown as &lt;STRONG&gt;3rd Party Configuration&lt;/STRONG&gt;. Set the &lt;STRONG&gt;Cluster Mode to High Availability&lt;/STRONG&gt; and &lt;STRONG&gt;3rd Party Solution&lt;/STRONG&gt; as &lt;STRONG&gt;Check Point IPSO VRRP.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="16.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8172i83C037A413E3CEA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="16.png" alt="16.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In Network Management Pane, Get the interfaces with Topology and change the values as described below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="17.png" style="width: 764px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8173i66E80840D5FBA469/image-size/large?v=v2&amp;amp;px=999" role="button" title="17.png" alt="17.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Press Ok.&lt;/P&gt;&lt;P&gt;Add a new Policy Package and set as the Installation targets the new cluster gateway&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="18.png" style="width: 671px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8174i5F80160BF4986537/image-size/large?v=v2&amp;amp;px=999" role="button" title="18.png" alt="18.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Press OK.&lt;/P&gt;&lt;P&gt;Create some basic rules and install the policy for Site B.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="19.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8175i5BA150963FE1C75F/image-size/large?v=v2&amp;amp;px=999" role="button" title="19.png" alt="19.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Let’s configure the VRRP parameters on Site B gateways. Access web page of Site B gateways:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20.png" style="width: 741px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8176i355949C8A6BEC961/image-size/large?v=v2&amp;amp;px=999" role="button" title="20.png" alt="20.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Access the page&amp;nbsp;&lt;STRONG&gt;High Availability &amp;gt; VRRP &amp;gt; Virtual Routers &amp;gt; Add&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21.png" style="width: 745px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8177i65BFBE700421BEF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="21.png" alt="21.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On gateway B-GW-02 we’ll set a lower Priority and the Router ID has to be the same as specified in B-GW-01.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="22.png" style="width: 641px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8178iB8835B9E7E9DA625/image-size/large?v=v2&amp;amp;px=999" role="button" title="22.png" alt="22.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once it’s done, install the policy to reflect the new changes.&lt;/P&gt;&lt;P&gt;We can successfully confirm the cluster status.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="23.png" style="width: 853px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8179i6BAE651BF88337DE/image-size/large?v=v2&amp;amp;px=999" role="button" title="23.png" alt="23.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="24.png" style="width: 609px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8180iE20B97859472DF64/image-size/large?v=v2&amp;amp;px=999" role="button" title="24.png" alt="24.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope you enjoyed this post, leave your comments below and I'll see you on the next post.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 27 Sep 2020 15:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-To-s-Deploy-Check-Point-ClusterXL-and-VRRP/m-p/97652#M7577</guid>
      <dc:creator>Silesio</dc:creator>
      <dc:date>2020-09-27T15:55:49Z</dc:date>
    </item>
  </channel>
</rss>

