<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management-Server: Addition NIC or VSX-Cluster? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259196#M43825</link>
    <description>&lt;P&gt;You could perhaps cobble something together, but like Val, I would prefer to expand the management network and configure a clean setup instead of living with some makeshift crutches.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Oct 2025 08:53:46 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2025-10-07T08:53:46Z</dc:date>
    <item>
      <title>Management-Server: Addition NIC or VSX-Cluster?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259193#M43822</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have a setup of&lt;BR /&gt;- 1 Management-Server&lt;BR /&gt;- 2 Node HA-Cluster&lt;BR /&gt;- Management-Network /29 size (don't ask...)&lt;BR /&gt;1.1.1.1: Cluster IP&lt;BR /&gt;1.1.1.2: Node 1&lt;BR /&gt;1.1.1.3: Node 2&lt;BR /&gt;1.1.1.4: Management-Server&lt;/P&gt;&lt;P&gt;Obviously this leaves two IP addresses unused within the subnet. I have added a drawing to show the setup.&lt;/P&gt;&lt;P&gt;Now the situation is:&lt;BR /&gt;We need to add a 2-Node VSX-Cluster, which will be managed by the existing Management-Server. Since there is only two IP addresses left in the /29, we have patched an additional NIC and gave the Management-Server an additional IP address (2.2.2.6/28), in order to manage the VSX-Cluster via this additional network.&lt;/P&gt;&lt;P&gt;My question:&lt;BR /&gt;IMHO there are two options to go proceed:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Go with the setup described above. This is also shown in the drawing (blue color is "new"). Has anybody done this setup and are there any caviats? As far as I remember, Check Point recommends having a single Management-network that contains all CP appliances.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Resize the existing /29 to a /28, which could be done with little effort, since the second half of the future /28 only containts idrac-Cards, which could be migrated easily into a new IP space.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thank you very much in advance, appreciate your help!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 08:19:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259193#M43822</guid>
      <dc:creator>Robert135242</dc:creator>
      <dc:date>2025-10-07T08:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Management-Server: Addition NIC or VSX-Cluster?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259194#M43823</link>
      <description>&lt;P&gt;The main issue that I see with the proposed setup is that you might cut off the VSX cluster from MGMT if the wrong policy is installed on the HA cluster, routing from Net 1 to Net 2.&lt;/P&gt;
&lt;P&gt;I would indeed recommend extending the MGMT subnet to accommodate the new VSX cluster management IPs as an alternative.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 08:42:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259194#M43823</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-10-07T08:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Management-Server: Addition NIC or VSX-Cluster?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259195#M43824</link>
      <description>&lt;P&gt;But the VSX Cluster is directly connected to the network (2.2.2.0/28) where also the management-server is directly connected. So in theory, this should not be a routing/policy issue?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 08:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259195#M43824</guid>
      <dc:creator>Robert135242</dc:creator>
      <dc:date>2025-10-07T08:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Management-Server: Addition NIC or VSX-Cluster?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259196#M43825</link>
      <description>&lt;P&gt;You could perhaps cobble something together, but like Val, I would prefer to expand the management network and configure a clean setup instead of living with some makeshift crutches.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 08:53:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Management-Server-Addition-NIC-or-VSX-Cluster/m-p/259196#M43825</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-10-07T08:53:46Z</dc:date>
    </item>
  </channel>
</rss>

