<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Current VSX, 2 members, HA. Migrate to LS? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80357#M9263</link>
    <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;mentioned. You can‘t distribute one VS over both nodes.&lt;/P&gt;
&lt;P&gt;But you can create a new VS with VPN/RemoteAccess enabled. Configure them the same encryption domain and use MEP (Multiple Entry Point). With this you can use both VS for VPN and distribute these VS over both nodes. meaning VSa is running on nodeA and VSb on nodeB.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
    <pubDate>Tue, 31 Mar 2020 18:30:40 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2020-03-31T18:30:40Z</dc:date>
    <item>
      <title>Current VSX, 2 members, HA. Migrate to LS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80344#M9260</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to scale up for the increased VPN load due to corona. At this time, we believe that our last option is to migrate from HA to LS and have our VPN terminate on both firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have experience migrating from HA to LS?&amp;nbsp;&lt;/P&gt;&lt;P&gt;How does LS distribute VPN connections?&lt;/P&gt;&lt;P&gt;Do you think this is a good idea?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other thoughts?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 16:38:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80344#M9260</guid>
      <dc:creator>Terry</dc:creator>
      <dc:date>2020-03-31T16:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Current VSX, 2 members, HA. Migrate to LS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80353#M9261</link>
      <description>I have migrated a cluster a while ago, this went without any problems.&lt;BR /&gt;The load is divided per VS, so when you have 2 heavily loaded VS's with VPN's you could make sure those are split over the 2 cluster members.&lt;BR /&gt;Depending on the version you can see a lot of things with cpview, here you can see the statistics and the load per VS. &lt;BR /&gt;On the management server you can set the weight of each VS using:&lt;BR /&gt;vsx_util vsls&lt;BR /&gt;You can also assign specific VS's to a specific cluster member.&lt;BR /&gt;See the VSX admin guide for the version you have.</description>
      <pubDate>Tue, 31 Mar 2020 17:04:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80353#M9261</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-31T17:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Current VSX, 2 members, HA. Migrate to LS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80354#M9262</link>
      <description>&lt;P&gt;So you won't be able to share a single VS across two nodes. As it sounds like you expected that from original description&lt;/P&gt;
&lt;P&gt;As for other options it depends on what's hitting the roof now - CPU? Interface?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 17:28:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80354#M9262</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-03-31T17:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Current VSX, 2 members, HA. Migrate to LS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80357#M9263</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;mentioned. You can‘t distribute one VS over both nodes.&lt;/P&gt;
&lt;P&gt;But you can create a new VS with VPN/RemoteAccess enabled. Configure them the same encryption domain and use MEP (Multiple Entry Point). With this you can use both VS for VPN and distribute these VS over both nodes. meaning VSa is running on nodeA and VSb on nodeB.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 18:30:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Current-VSX-2-members-HA-Migrate-to-LS/m-p/80357#M9263</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-03-31T18:30:40Z</dc:date>
    </item>
  </channel>
</rss>

