<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DAIP cluster in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8195#M162</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Thanks for the answer, the checkpoint cluster itself has no dynamic ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The topology is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Router has receives the IP from the provider.&lt;/P&gt;&lt;P&gt;Behind it is the Cluster, with static IP on the Transport network. all connected over a switch( not relevant for this discussion).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The management is reachable over the internet so any incoming connection would have to be to the Public IP of the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My idea was to have the Cluster set as Dynamic and have both gateways fetch the policy, this way only outbound communication is&amp;nbsp; required like on a normal DAIP single gateway solution.&lt;/P&gt;&lt;P&gt;I wanted to test this but the Dyn option is not available on the cluster object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74988_topology.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Nov 2018 18:03:51 GMT</pubDate>
    <dc:creator>Ricardo_Gros</dc:creator>
    <dc:date>2018-11-23T18:03:51Z</dc:date>
    <item>
      <title>DAIP cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8193#M160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to figure a way to build a DAIP SMB cluster&amp;nbsp; that is centrally managed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is actually as it seems not supported because the Cluster object on management side is missing the Dynamic IP box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However i was wondering if there is really a technical reason why this does not work on a topology where the Dynamic IP sits on a 3rd party Router and the Checkpoint Cluster is behind it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as i understand the DAIP gateways will only fetch the policy and the Logging is also outbound so it would actually not be much different from a single gateway setup with DAIP on 3rd party device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has some one tried this? does this make sense?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 12:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8193#M160</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-11-23T12:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: DAIP cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8194#M161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Clustering assumes the IPs of all cluster members are fixed and on the same subnets.&lt;/P&gt;&lt;P&gt;You cannot make that assumption when the gateways get their IP via DHCP.&lt;/P&gt;&lt;P&gt;When you check DAIP, the gateway is assumed to be obtaining an IP from DHCP and will not have a fixed address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, if in reality, the cluster members are going to get a static IP from the DHCP server, then you define it in SmartDashboard with a fixed IP and do NOT set the DAIP flag in the object.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 17:13:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8194#M161</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-23T17:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: DAIP cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8195#M162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Thanks for the answer, the checkpoint cluster itself has no dynamic ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The topology is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Router has receives the IP from the provider.&lt;/P&gt;&lt;P&gt;Behind it is the Cluster, with static IP on the Transport network. all connected over a switch( not relevant for this discussion).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The management is reachable over the internet so any incoming connection would have to be to the Public IP of the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My idea was to have the Cluster set as Dynamic and have both gateways fetch the policy, this way only outbound communication is&amp;nbsp; required like on a normal DAIP single gateway solution.&lt;/P&gt;&lt;P&gt;I wanted to test this but the Dyn option is not available on the cluster object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74988_topology.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 18:03:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8195#M162</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-11-23T18:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: DAIP cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8196#M163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The assumption is that if the gateway has static IPs, it's reachable bidirectionally.&lt;/P&gt;&lt;P&gt;In the case of a truly dynamic gateway, the assumption is that it has outbound only access (and could even be behind a NAT).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Nov 2018 05:21:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8196#M163</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-25T05:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: DAIP cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8197#M164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But, in this case both are behind a NAT and have only outbound access. However on Management the Cluster object does not allow for DAIP so this cannot be configured at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My doubt was if this would&amp;nbsp; make sense to be possible in this topology.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Nov 2018 10:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8197#M164</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-11-25T10:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: DAIP cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8198#M165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the only way you can have this sort of configuration is if you manage the gateway with a SmartLSM profile.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111626" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111626"&gt;ATRG: SmartProvisioning&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Nov 2018 15:54:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8198#M165</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-25T15:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: DAIP cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8199#M166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i will look into this, thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Nov 2018 18:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DAIP-cluster/m-p/8199#M166</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-11-25T18:13:11Z</dc:date>
    </item>
  </channel>
</rss>

