<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL policy synchronization, nat, IPS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-policy-synchronization-nat-IPS/m-p/185604#M30957</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;makes a very good point. IF its standalone, then you could introduce whats called Full HA, which is essentially 2 standalone devices in a cluster. Then, you would have 2 gateways and 2 mgmt servers in a cluster...personally, not something I would recommend, as I always found when it works, works 100% great, but when it breaks, good luck fixing it : - ). Now, if your device is just a gateway, then you can introduce a new gateway to be part of a cluster. Just run commands he gave and you will confirm for sure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jul 2023 18:11:38 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-07-04T18:11:38Z</dc:date>
    <item>
      <title>ClusterXL policy synchronization, nat, IPS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-policy-synchronization-nat-IPS/m-p/185593#M30951</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering how policy synchornization proceeds between cluster members ? Assuming I have a firewall that is being&amp;nbsp; use for years and has a lot of configured access policies, NAT rules, IPS etc. and at some stage I would like to add 2nd firewall and configure ClusterXL. Question is , will be this policy installed automatically on Cluster object ? If yes is there any way that it has to be done for example older fw with policies need to has a higher priority or it can be done only manually by adding Cluster object to manage in "manage policies" ?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 15:43:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-policy-synchronization-nat-IPS/m-p/185593#M30951</guid>
      <dc:creator>marcinw</dc:creator>
      <dc:date>2023-07-04T15:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL policy synchronization, nat, IPS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-policy-synchronization-nat-IPS/m-p/185602#M30956</link>
      <description>&lt;P&gt;The first major question is whether the system you have is a "standalone" (firewall and management server in one system) or just a firewall. Run 'fw stat' and 'fwm ver'. What do they return?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 17:39:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-policy-synchronization-nat-IPS/m-p/185602#M30956</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-07-04T17:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL policy synchronization, nat, IPS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-policy-synchronization-nat-IPS/m-p/185604#M30957</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;makes a very good point. IF its standalone, then you could introduce whats called Full HA, which is essentially 2 standalone devices in a cluster. Then, you would have 2 gateways and 2 mgmt servers in a cluster...personally, not something I would recommend, as I always found when it works, works 100% great, but when it breaks, good luck fixing it : - ). Now, if your device is just a gateway, then you can introduce a new gateway to be part of a cluster. Just run commands he gave and you will confirm for sure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 18:11:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-policy-synchronization-nat-IPS/m-p/185604#M30957</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-04T18:11:38Z</dc:date>
    </item>
  </channel>
</rss>

