<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: office mode network/clusterXL HA/SSLVPN/network extender in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/54137#M12540</link>
    <description>&lt;P class="tpbodytext"&gt;Office Mode addresses can be allocated from an IP pool or by a DHCP server. If addresses are allocated from an IP pool, &lt;STRONG&gt;a separate IP pool must be defined for every cluster member.&lt;/STRONG&gt; This prevents the allocation of the same IP address to different clients simultaneously.&lt;/P&gt;&lt;P class="tpbodytext"&gt;I assume I route these to my INT-VIP IP, not the respective gws.&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2019 18:01:56 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2019-05-22T18:01:56Z</dc:date>
    <item>
      <title>office mode network/clusterXL HA/SSLVPN/network extender</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/8120#M12538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With ClusterXL HA (active/standby) RE: office mode network for SSLVPN (network extender mode) - Is it recommended to define one OM network for each member in the cluster (a seperate network for each member)?&amp;nbsp; &amp;nbsp;Or is it&amp;nbsp;recommended/required to have one office mode network defined (the same one) and configured one each member?&amp;nbsp; My guess is with HA, they'll be using one gw or the other so it's preferred to define the same network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 14:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/8120#M12538</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2019-02-28T14:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: office mode network/clusterXL HA/SSLVPN/network extender</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/8121#M12539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only one OfficeMode (MAB?) subnet for the whole SSLVPN NetX VPN Users - no need to create multiply OM subnets really. I don't get your point how HA is relevant to this ... have you ever used HA in Active/Passive mode before?&lt;/P&gt;&lt;P&gt;You know what VMAC stands for? or VIP on each "clusterred" interface? You don't need to worry about multiply OM subnets. Just make one, add to the config. and off you go &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 16:47:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/8121#M12539</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-02-28T16:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: office mode network/clusterXL HA/SSLVPN/network extender</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/54137#M12540</link>
      <description>&lt;P class="tpbodytext"&gt;Office Mode addresses can be allocated from an IP pool or by a DHCP server. If addresses are allocated from an IP pool, &lt;STRONG&gt;a separate IP pool must be defined for every cluster member.&lt;/STRONG&gt; This prevents the allocation of the same IP address to different clients simultaneously.&lt;/P&gt;&lt;P class="tpbodytext"&gt;I assume I route these to my INT-VIP IP, not the respective gws.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 18:01:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/54137#M12540</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2019-05-22T18:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: office mode network/clusterXL HA/SSLVPN/network extender</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/54258#M12541</link>
      <description>&lt;P&gt;Per&amp;nbsp; c&lt;SPAN&gt;ase&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class="uiOutputText"&gt;6-0001647364&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="slds-media__body"&gt;&lt;DIV class="slds-page-header__title slds-m-right--small slds-truncate slds-align-middle"&gt;&lt;SPAN class="uiOutputText"&gt;We are both right.&amp;nbsp; For Active/Active two sepeate ip pools are recommended.&amp;nbsp; For active/standby the same pool can be used on both nodes.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="slds-page-header__title slds-m-right--small slds-truncate slds-align-middle"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="slds-page-header__title slds-m-right--small slds-truncate slds-align-middle"&gt;&lt;SPAN class="uiOutputText"&gt;Each node what has been assigned, they are in sync.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 05 Jun 2019 13:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/54258#M12541</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2019-06-05T13:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: office mode network/clusterXL HA/SSLVPN/network extender</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/54261#M12542</link>
      <description>&lt;P&gt;If you are assigning Office Mode IPs from the Pool, it makes sense to split it in two and serve half from each cluster member in HA configuration.&lt;/P&gt;
&lt;P&gt;The reason for this is that if one of the unit has leased the IP to the client and then the failover has occurred, no duplicate IPs will be leased.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2019 16:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/office-mode-network-clusterXL-HA-SSLVPN-network-extender/m-p/54261#M12542</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-23T16:54:22Z</dc:date>
    </item>
  </channel>
</rss>

