<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cluster over differnt geo location with different ISPs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cluster-over-differnt-geo-location-with-different-ISPs/m-p/138550#M24676</link>
    <description>&lt;P&gt;Hello everyone.&lt;/P&gt;&lt;P&gt;i want to know what is the best practice of the following&lt;/P&gt;&lt;P&gt;we implementing "Live DR", so we connecting Main site with DR Site by Layer2 in all internal vlans. and also the cluster FW will be 3rd and maybe also 4th members at the DR Site. so Internet/Dmz Cluster will be ni Main and in DR Site.&lt;/P&gt;&lt;P&gt;my quesion is about the Isp's side/Default route site.&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the best practice here?&lt;/P&gt;&lt;P&gt;do i have to do Layer 2 Line between Isps between sites (to my knowledge it's must for the cluster), or can i use different ISPs, or same ISPs but with different lines (and also different&amp;nbsp; public IP subnets)&lt;/P&gt;&lt;P&gt;and let's assume i have L2 between ISPs between sites, what will happend if the Internal Sync /other vlans disconnected between sites, and GWs become active together in Main Site and DR Site, so the ISP will see the same VIP alive in both sites, and it won't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;how it's usually implemented ?&lt;/P&gt;&lt;P&gt;i attached draw for general architecture.&lt;/P&gt;</description>
    <pubDate>Sun, 16 Jan 2022 14:57:19 GMT</pubDate>
    <dc:creator>Amir_Arama</dc:creator>
    <dc:date>2022-01-16T14:57:19Z</dc:date>
    <item>
      <title>Cluster over differnt geo location with different ISPs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-over-differnt-geo-location-with-different-ISPs/m-p/138550#M24676</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;&lt;P&gt;i want to know what is the best practice of the following&lt;/P&gt;&lt;P&gt;we implementing "Live DR", so we connecting Main site with DR Site by Layer2 in all internal vlans. and also the cluster FW will be 3rd and maybe also 4th members at the DR Site. so Internet/Dmz Cluster will be ni Main and in DR Site.&lt;/P&gt;&lt;P&gt;my quesion is about the Isp's side/Default route site.&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the best practice here?&lt;/P&gt;&lt;P&gt;do i have to do Layer 2 Line between Isps between sites (to my knowledge it's must for the cluster), or can i use different ISPs, or same ISPs but with different lines (and also different&amp;nbsp; public IP subnets)&lt;/P&gt;&lt;P&gt;and let's assume i have L2 between ISPs between sites, what will happend if the Internal Sync /other vlans disconnected between sites, and GWs become active together in Main Site and DR Site, so the ISP will see the same VIP alive in both sites, and it won't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;how it's usually implemented ?&lt;/P&gt;&lt;P&gt;i attached draw for general architecture.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 14:57:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-over-differnt-geo-location-with-different-ISPs/m-p/138550#M24676</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2022-01-16T14:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster over differnt geo location with different ISPs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-over-differnt-geo-location-with-different-ISPs/m-p/138568#M24677</link>
      <description>&lt;P&gt;Do you have your own ISP independent public IP addressing?&lt;/P&gt;
&lt;P&gt;I would be using dynamic routing &amp;amp; routers / perhaps layer-3 switches external to the Firewall.&lt;/P&gt;
&lt;P&gt;You are correct that regardless of the number of cluster members involved Layer-2 connectivity is required.&lt;/P&gt;
&lt;P&gt;Redundant &amp;amp; diverse paths between sites are recommended in general for such a design.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 03:42:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-over-differnt-geo-location-with-different-ISPs/m-p/138568#M24677</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-17T03:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster over differnt geo location with different ISPs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-over-differnt-geo-location-with-different-ISPs/m-p/138704#M24691</link>
      <description>&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;Yes i have independend ISP ip addresses.&lt;/P&gt;&lt;P&gt;So you are saying to strech layer 2 between sites of the network between external fw interface to a routers/link proof like.&lt;/P&gt;&lt;P&gt;And then use dynamic routes that will inject default route to the fws. And so each fw can also use other site isp's if it's own are down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 08:20:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-over-differnt-geo-location-with-different-ISPs/m-p/138704#M24691</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2022-01-18T08:20:49Z</dc:date>
    </item>
  </channel>
</rss>

