<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is ClusterXL and VRRP ? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9553#M1271</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course. As said above, CCP is using the last octet of source mac frame as cluster ID, to distinguish between different CXL entities in the same broadcast domain.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;That parameter is hardcoded to ClusterXL settings during installation time but can be changed by adding a certain FW kernel parameter called&amp;nbsp; by clusterXL during boot and registered in fwkern.conf file.&lt;BR /&gt;&lt;BR /&gt;In version R77.30 (and up) Check Point developers decided to call this parameter ClusterID, to acknowledge its role in ClusterXL solution. It is now part of first time wizard if you are configuring a cluster member in CXL mode. It can also be changed later on with a CLISH command. Yet the nature is still the same, it is the value in the last octet of a source mac in CCP frames. the rest of octets there are all zeros.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Nov 2017 15:40:29 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2017-11-07T15:40:29Z</dc:date>
    <item>
      <title>What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9545#M1263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is different between &lt;STRONG&gt;High availability&lt;/STRONG&gt; and &lt;STRONG&gt;Load sharing&lt;/STRONG&gt; in cluster mode. ?&lt;/P&gt;&lt;P&gt;What is different between &lt;STRONG&gt;ClusterXL&lt;/STRONG&gt; and &lt;STRONG&gt;VRRP&lt;/STRONG&gt; in highavialibily ?&lt;BR /&gt;What is different between &lt;STRONG&gt;Multicast&lt;/STRONG&gt; and &lt;STRONG&gt;Uni-cast&lt;/STRONG&gt; in load sharing ?&lt;BR /&gt;What is the best method to use in checkpoint cluster environment ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 05:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9545#M1263</guid>
      <dc:creator>Prashan_Attanay</dc:creator>
      <dc:date>2017-11-07T05:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9546#M1264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161109.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161109.htm"&gt;Introduction to ClusterXL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CITE class=""&gt;&lt;A href="https://www.youtube.com/watch?v=8vMkZZZCZl4"&gt;YouTube: Understanding ClusterXL&lt;/A&gt;&lt;/CITE&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=F-CiWpTCDbI"&gt;&lt;CITE class=""&gt;YouTube: Understanding VRRP&lt;/CITE&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=b-W96sn3gdY"&gt;YouTube: Troubleshooting ClusterXL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161111.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161111.htm"&gt;High Availability and Load Sharing in ClusterXL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161111.htm#o7375" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161111.htm#o7375"&gt;Load Sharing Multicast Mode&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161111.htm#o7377" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_ClusterXL_AdminGuide/161111.htm#o7377"&gt;Load Sharing Unicast Mode&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://supportcontent.checkpoint.com/solutions?id=sk92061" title="http://supportcontent.checkpoint.com/solutions?id=sk92061"&gt;How to configure VRRP on Gaia&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39676"&gt;VRRP FAQ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://supportcontent.checkpoint.com/solutions?id=sk66527" title="http://supportcontent.checkpoint.com/solutions?id=sk66527"&gt;Recommended configuration for ClusterXL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ClusterXL is Check Point's own clustering protocol and therefore the default clustering protocol when setting up Check Point clusters. Check Point sees VRRP as a 3rd party cluster protocol. Check Points applications, such as SmartView Monitor, might not always shows correct values when using 3rd party solutions. Also you need to be aware of many SKs providing solutions that come up when using 3rd party solutions (e.g. &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36544"&gt;sk36544&lt;/A&gt;, &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43321"&gt;sk43321&lt;/A&gt;, &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98698"&gt;sk98698&lt;/A&gt; and so on.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 10:58:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9546#M1264</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-11-07T10:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9547#M1265</link>
      <description>&lt;DIV class=""&gt;
&lt;P&gt;Danny's links are great, however here are the answers to your specific questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; What is different between &lt;STRONG&gt;High availability&lt;/STRONG&gt; and &lt;STRONG&gt;Load sharing&lt;/STRONG&gt; in cluster mode. ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;High Availability is active/standby, while with ClusterXL Load Sharing all members are active.&amp;nbsp; Generally I'm not a fan of Load Sharing, but it has its uses in certain cases.&amp;nbsp; &lt;STRONG&gt;Edit: A new ClusterXL mode called Active/Active was introduced in R80.40 which is distinct and separate from ClusterXL Load Sharing.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; What is different between &lt;STRONG&gt;ClusterXL&lt;/STRONG&gt; and &lt;STRONG&gt;VRRP&lt;/STRONG&gt; in highavialibily ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They both can perform active/standby quite well, but ClusterXL is considerably easier to set up and manage.&amp;nbsp; VRRP is more prone to misconfiguration that causes cluster split-brains or routing black holes.&amp;nbsp; I recommend ClusterXL over VRRP unless one has the rare need to present more than one Cluster IP (VIP) on a single interface (which VRRP can do but ClusterXL can't), or there is some external load balancing algorithm in use (like OSPF) controlling the traffic distribution with load sharing via VRRP.&amp;nbsp; &lt;STRONG&gt;Edit: The new Active/Active ClusterXL mode introduced on R80.40 can be used to work with an external load balancing mechanism.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;gt; What is different between &lt;STRONG&gt;Multicast&lt;/STRONG&gt; and &lt;STRONG&gt;Uni-cast&lt;/STRONG&gt; in load sharing ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The MAC address of provided to systems in ARP replies that are trying to traverse an active/active firewall cluster. If low order bit of first byte in a MAC address is 1 (i.e. it is odd 01, 03, 05) the mac address is multicast, if low order bit is 0 (i.e. it is even 02, 04, 06) it is unicast.&amp;nbsp; Some switches and routers have issues properly handling multicast mac addresses which is putting it mildly.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;gt; What is the best method to use in checkpoint cluster environment ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just my opinion but ClusterXL wins hands down, although VRRP has its adherents (and I'm sure we'll be hearing from them shortly).&lt;/P&gt;
&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&lt;BR /&gt;My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt;now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank" rel="noopener"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 04 May 2020 11:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9547#M1265</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-04T11:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9548#M1266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VRRP:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cons:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Decision is per interface.. Am I master or backup, one interface at a time; potential for split brain.&lt;/LI&gt;&lt;LI&gt;No Health checking of the cluster peer(s).&lt;/LI&gt;&lt;LI&gt;If same VRRP ID is used on all interfaces, potential to confuse switch when multiple firewall interfaces connected to same switch; multiple VLANs using same VRRP MAC.&lt;/LI&gt;&lt;LI&gt;Default VRRP MAC is still effected by IGMP, same as ClusterXL CCP multicast mode. VRRP hello packets are transmitted using the VRRP MAC as the destination.&lt;/LI&gt;&lt;LI&gt;Only the Master node transmits Hello packets. No status of backup cluster member, VRRP interfaces must be monitored individually to discern if layer 2 connectivity problem exists on one or more interfaces.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ClusterXL:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pros:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Health checks peer on every physical interface&lt;/LI&gt;&lt;LI&gt;Unified interface failover; no chance of split brain&lt;/LI&gt;&lt;LI&gt;Monitors policy, daemons etc.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ClusterXL is more robust than VRRP in its monitoring of peer nodes and failover.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 14:18:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9548#M1266</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-07T14:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9549#M1267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am afraid your answer is misleading. VRRP allows elaborate health checks as part of redundancy, FW status included. If configured correctly, a virtual router fails over properly without causing a split brain.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;VRRP is de-facto standard and classic redundancy solution. It does not allow load sharing though, but you do not want to use load sharing with Check Point anyway, unless it is VSLS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ClusterXL is proprietary, with complex and sometimes rather questionable implementation details. It uses so-called magic_mac as cluster ID, and it is even called just that in R77.30 and R80.X installation wizards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do agree with your recommendation to use ClusterXL, but I know many people with enough experience that do not share this opinion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 14:49:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9549#M1267</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-11-07T14:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9550#M1268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Valeri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Magic MAC" or "Virtual MAC" is actually optional in ClusterXL, at least in 77.30.&lt;/P&gt;&lt;P&gt;From my field experience, which is by no means as extensive as yours, I've seen issues caused by VRRP/HSRP combinations that Virtual MAC can actually address better.&lt;/P&gt;&lt;P&gt;SImilarly, in older networks with complex (or downright bad)&amp;nbsp; STP implementations, Virtual MAC was a better option.&lt;/P&gt;&lt;P&gt;In the days of Nokia appliances and when ClusterXL was not mature, I would have weighted the options of which one to implement.&lt;/P&gt;&lt;P&gt;Now, with vSECs in the picture, for consistency purposes it kind-of makes sense to stick with technology that is supported across all deployment scenarios.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 15:02:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9550#M1268</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-07T15:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9551#M1269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No sir, you are mixing magic_mac with VMAC functionality in ClusterXL. these are two different things.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VMAC is described here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk50840" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk50840"&gt;How to enable ClusterXL Virtual MAC (VMAC) mode&lt;/A&gt;&amp;nbsp;&amp;nbsp;It is a feature that allows cluster members using a virtual mac when answering to ARP requests for VIP addresses. By default, physical MAC addresses are used instead, which means gracious ARP has to be sent in case of failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So-called magic_mac and magic_mac_forwarding are internal parameters of CCP used to form a ClusterXL entity. CCP is a funny protocol, and at layer 2 it uses magic_mac as a source MAC for CCP frame.&amp;nbsp; In specific scenarios magic_mac can create issues with adjacent netowrking devices. For example, if CCP is running in a multicast more and IGMP snooping is enabled on an adjacent switch, it may cause false positive IGMP issues leading to flapping interfaces on the cluster. More details about CCP are here:&amp;nbsp;&lt;A class="link-titled" href="http://dl3.checkpoint.com/paid/44/Cluster_Control_Protocol_Reference.pdf?HashKey=1510074387_eab82a4d2d0e619aaad1de9a463126d0&amp;amp;xtn=.pdf" title="http://dl3.checkpoint.com/paid/44/Cluster_Control_Protocol_Reference.pdf?HashKey=1510074387_eab82a4d2d0e619aaad1de9a463126d0&amp;amp;xtn=.pdf"&gt;http://dl3.checkpoint.com/paid/44/Cluster_Control_Protocol_Reference.pdf?HashKey=1510074387_eab82a4d2d0e619aaad1de9a4631…&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 15:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9551#M1269</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-11-07T15:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9552#M1270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for clarifying the difference.&lt;/P&gt;&lt;P&gt;I guess this is the primary reason one of the first things TAC tries when troubleshooting ClusterXL issues is to switch the CCP mode to boadcast.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you mind further explaining which of these two is affected by the "Cluster ID" parameter?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 15:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9552#M1270</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-07T15:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9553#M1271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course. As said above, CCP is using the last octet of source mac frame as cluster ID, to distinguish between different CXL entities in the same broadcast domain.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;That parameter is hardcoded to ClusterXL settings during installation time but can be changed by adding a certain FW kernel parameter called&amp;nbsp; by clusterXL during boot and registered in fwkern.conf file.&lt;BR /&gt;&lt;BR /&gt;In version R77.30 (and up) Check Point developers decided to call this parameter ClusterID, to acknowledge its role in ClusterXL solution. It is now part of first time wizard if you are configuring a cluster member in CXL mode. It can also be changed later on with a CLISH command. Yet the nature is still the same, it is the value in the last octet of a source mac in CCP frames. the rest of octets there are all zeros.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 15:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9553#M1271</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-11-07T15:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9554#M1272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK. And how is the value of the VMAC is being determined and differentiated between multiple clusters?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 15:47:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9554#M1272</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-07T15:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9555#M1273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VMAC is using magic_mac as one of the parameters, once more for the last octet. It also takes into account VSID&amp;nbsp;and has a non-zero prefix. It brief, VMAC depends but not equals to magic_mac.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once more, this link explains it perfectly and even has charts and examples:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk50840" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk50840"&gt;How to enable ClusterXL Virtual MAC (VMAC) mode&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 15:56:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9555#M1273</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-11-07T15:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9556#M1274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see that you’ve removed the “so different interfaces would have different MAC addresses available for the cluster.” &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which is no longer applicable in later releases as same VMAC is being used on all interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me if this change has any negative implications besides causing ocasional consternation for network admministrators?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 16:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9556#M1274</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-07T16:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9557#M1275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, sorry, my original response was not 100% accurate. AFAIK, the main issue with VMAC is having more than one interface with the same MAC addresses for VIP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If more than one segment is attached to th same networking device, some additional effort may be required to tackle this.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 18:28:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9557#M1275</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-11-07T18:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9558#M1276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Nov 2017 05:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9558#M1276</guid>
      <dc:creator>Prashan_Attanay</dc:creator>
      <dc:date>2017-11-08T05:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9559#M1277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Nov 2017 05:08:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9559#M1277</guid>
      <dc:creator>Prashan_Attanay</dc:creator>
      <dc:date>2017-11-08T05:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9560#M1278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a side note. If you still run IPSO you only have VRRP as an option..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But be aware that even if you run VRRP as HA protocol you are in fact using ClusterXL to take care of a lot things for you like keeping connection tables in Sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In theory you could run 2 firewalls with VRRP and not use them as cluster but as 2 individual firewalls. But I think I would not recommend unless the customer signs a waiver that the design is extremely limited in regard to failover.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Nov 2017 08:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9560#M1278</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-11-08T08:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9561#M1279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Hugo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Nov 2017 08:54:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9561#M1279</guid>
      <dc:creator>Prashan_Attanay</dc:creator>
      <dc:date>2017-11-08T08:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9562#M1280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To follow on from an above post if you are running the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPSO - VRRP Only&lt;/P&gt;&lt;P&gt;SPLAT- ClusterXL Only&lt;/P&gt;&lt;P&gt;Gaia - ClusterXL or VRRP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you think about it, VRRP is an open redundancy standard that you can run on Linux, Cisco, Fortinet etc etc ... The protocol itself is concerned with the ability to maintain successful routing paths through a single IP address (VIP) per network that you require in the event of hardware/software failure of a particular device node.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not have native checks for the core PNotes that Check Point ClusterXL defines nor does it the the ability to customise your own PNotes. It has no method for connections and NAT table synchronisation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this stage you are needing to implement ClusterXL on top of VRRP anyway as has already been highlighted to achieve state synchronisation and cluster health checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, with this being said, VRRP works very well, if configured correctly. Try not to use multiple VRID's for your interfaces as this has the potential to mean that only a single interface fails over to the secondary cluster member causing split traffic across cluster members. Additionally, each VRID has to be manually failed over - which can take upward of a few minutes to complete on a device with many interfaces as opposed to a single VRID fail over being "instant".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I typically see this deployed when:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Customer has upgraded from IPSO way back when and have simply followed the standard in place upgrades&lt;/P&gt;&lt;P&gt;2) Issues with upstream device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to sk44898 - RFC 1812 states:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;"A router MUST not believe any ARP reply that claims that the Link Layer address of another host or router is a broadcast or multicast address."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The gratuitous ARP used for ClusterXL send a Unicast IP to a Multicast Destination, breaking RFC standard.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rather than fight with ClusterXL, simply drop in VRRP config and it usually just works. I know you can use broadcast mode instead for CCP but I have heard concerns from customers over additional network resource use given the nature of broadcast traffic itself, however this one particular example was on a large subnet with many thousands of hosts. Also the mindset of security, there is a theoretical security concern over the broadcast of cluster data to every host on the subnet, again, a real world example I am citing from a customer. Personally I am not so sure I share those thoughts, but then it wasn't my network to make that decision for &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running multiple clusters on a subnet has already been established that you can use the Magic_MAC, made much easier since R77.30 I believe, where it is part of the WebUI set up. One point that has not yet been mentioned is the counter part to this with VRRP is to use simple authentication AKA a password for the cluster member to authenticate its peer against. Even if not using another Check Point cluster, I would recommend to set this as its very possible there are other none Check Point devices using VRRP in the same network segment that can and will cause you a headache upon deployment. (Speaking from experience)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to say on a final note, I find pure ClusterXL clusters easier to manage and troubleshoot as almost all config is done from Dashboard and the cphaprob tool set of commands usually get the job done very efficiently. I also prefer the fail over cli options to the clish VRRP options, but this is personal preference rather than hard fact.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 08:27:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9562#M1280</guid>
      <dc:creator>John_Tammaro1</dc:creator>
      <dc:date>2017-11-10T08:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9563#M1281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply John&lt;/P&gt;&lt;P&gt;Do we sitll have IPSO these days ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prashan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 07:17:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9563#M1281</guid>
      <dc:creator>Prashan_Attanay</dc:creator>
      <dc:date>2017-11-14T07:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: What is ClusterXL and VRRP ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9564#M1282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No IPSO was only available on Nokia IP appliances that have long since been out of production.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium;"&gt;&amp;nbsp;I still see some IP appliances in the wild but I'm pretty sure that the last renewal dates for the largest of these boxes is 2018/19 so there's not much life left in these.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Also note that IP appliances are upgradeable to Gaia OS instead of IPSO assuming that the hardware is capable. There are no 64bit IP appliances and at best you will get a dual core 4gig RAM maximum.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium;"&gt;Not really suitable in modern networking for anything other than firewalling and VPN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;With all that being said, there's a reason that IPSO is still around today. It's a very reliable OS and can be considered stable for sure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are no IPSO updates anymore. The last one I remember was the bash Shell Shock patch. Maybe some other members can confirm that ??&lt;/P&gt;&lt;P&gt;One last point, please never ever use the Flash based models. Your asking for a headache and a long weekend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 07:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-is-ClusterXL-and-VRRP/m-p/9564#M1282</guid>
      <dc:creator>John_Tammaro1</dc:creator>
      <dc:date>2017-11-14T07:31:46Z</dc:date>
    </item>
  </channel>
</rss>

