<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Clustering standalone units, recommended? in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36960#M97093</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was what the general consensus is on clustering standalone units, so with management + gateway on the same appliance. Or perhaps not even clustering, but the idea of standalone units as a whole.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're dealing mostly the customer who buy the 4000 and 5000-series appliances and we've had the feeling, from day one of stepping into the CheckPoint partner playing field, that standalone setups are supported, but never mentioned. With every proposal that we've done together with CheckPoint, it was always assumed that, no matter what, a separate management server was the way to go. To tell you the truth, I didn't know that a HA setup with 2 standalone units was even supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What gives? What are your experiences with standalone units, HA or not?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Mar 2018 16:55:22 GMT</pubDate>
    <dc:creator>Michel_B</dc:creator>
    <dc:date>2018-03-21T16:55:22Z</dc:date>
    <item>
      <title>Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36960#M97093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was what the general consensus is on clustering standalone units, so with management + gateway on the same appliance. Or perhaps not even clustering, but the idea of standalone units as a whole.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're dealing mostly the customer who buy the 4000 and 5000-series appliances and we've had the feeling, from day one of stepping into the CheckPoint partner playing field, that standalone setups are supported, but never mentioned. With every proposal that we've done together with CheckPoint, it was always assumed that, no matter what, a separate management server was the way to go. To tell you the truth, I didn't know that a HA setup with 2 standalone units was even supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What gives? What are your experiences with standalone units, HA or not?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 16:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36960#M97093</guid>
      <dc:creator>Michel_B</dc:creator>
      <dc:date>2018-03-21T16:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36961#M97094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My opinion - say no to standalone setups with Check Point (unless it is not an SMB device).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some time ago I implemented a setup of two 4800 appliances with increased RAM working in Full HA (FW + Mgmt) on R77.30 version of software. As I remember, some NGFW blades were enabled - IPS and Application Control. Something around 50 - 100 rules and standard profiles without much tuning.&lt;/P&gt;&lt;P&gt;Every time when policy was installed there were drops of traffic (very short, but visible with simple ping), because&amp;nbsp;policy verification and compilation is quite a resource-demanding operation. The setup ended up with node 1 acting as active FW and node 2 as active management server. Not enough space on HDD to store logs for a longer time, log Indexing (SmartLog) was not really possible.&lt;/P&gt;&lt;P&gt;It also adds complexity to software upgrades and maintenance. Higher risks of ruining management database. Higher risks of some security issues. More time and troubles to restore a gateway from a backup. Snapshots might be not possible to make because there would be no enough space.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, if there are much more powerful appliances you can try the setup. It would be interesting to know how it would perform, just for fun. But I think that anyone who buys some 15000-23000 appliances already has a server, most probably even MDS. Right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I would definitely not recommend standalone setup with R80.10 - management server will eat all RAM and CPU that you have. Although, there is this&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120131" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120131"&gt;sk120131&lt;/A&gt;&amp;nbsp;which assumes that everything would be fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 19:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36961#M97094</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-03-21T19:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36962#M97095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would avoid standalone deployments in all but the smallest of environments, especially Full HA (standalone setup in a cluster)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 04:58:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36962#M97095</guid>
      <dc:creator>Iain_Keir1</dc:creator>
      <dc:date>2018-03-22T04:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36963#M97096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the comments so far, this is exactly the kind of input I'm looking for and it annoys me&amp;nbsp;that this is something most CheckPoint representatives are so hesitant to come forward with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason for asking about these kind of setups is that we have more customers willing to buy a unit for a rather simple setup, with say a 3200 or 5200 which includes a gateway+management license in one. But when they want to separate these, they suddenly have to pay for a, rather expensive, management server license.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 07:40:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36963#M97096</guid>
      <dc:creator>Michel_B</dc:creator>
      <dc:date>2018-03-22T07:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36964#M97097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A _jive_internal="true" data-userid="45132" data-username="aleks65d64154-3014-4796-9c66-6b9f4aeee8e8" href="https://community.checkpoint.com/people/aleks65d64154-3014-4796-9c66-6b9f4aeee8e8"&gt;Aleksei&lt;/A&gt; for me spoke true words &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Full Managment HA out of my experience is not the stablest deployment - management sync alone made heavy headaches from time to time, and to have the active node together with the primary management is no good idea at all &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I would rather go for SMS in a VM together with an appliance cluster...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 08:29:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36964#M97097</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-22T08:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36965#M97098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is a true statement that should be directed to the sales people only - i am glad to assist in technical questions or help with known bugs, but i have nothing to do with license bundling and pricing...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 13:42:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36965#M97098</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-22T13:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36966#M97099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The same is true for me, but I was just trying to explain where this was coming from. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 13:46:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36966#M97099</guid>
      <dc:creator>Michel_B</dc:creator>
      <dc:date>2018-03-22T13:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36967#M97100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As an addition, find here the most important SKs dealing with Full HA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sk54160 How to Configure Management HA&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sk60443 How to install Full HA cluster on Check Point appliances&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sk93585_How to convert two Standalone machines into a Full-HA environment&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sk104699 How to configure a Standalone machine to become a part of a Full HA cluster&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sk39345 Management High Availability restrictions&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sk39740 How to configure management HA when the Primary and Secondary management servers are on separate networks? &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sk25164 SmartEvent / SmartReporter is not supported in High Availability environment&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 09:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36967#M97100</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-23T09:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Clustering standalone units, recommended?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36968#M97101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is definitely possible. I've build this and noticed that especially the CPU is having a heavy load when using this configuration. Also keep in mind that rebooting a GW can take a long time because of the CPU load. The CPU load is spiking mainly when accessing the management console and accessing logging. My technical advice would also be to have a management server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2018 13:28:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Clustering-standalone-units-recommended/m-p/36968#M97101</guid>
      <dc:creator>Tom_Heesmans</dc:creator>
      <dc:date>2018-03-28T13:28:03Z</dc:date>
    </item>
  </channel>
</rss>

