- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Secondary Azure management server
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Secondary Azure management server
Hi,
We are creating a secondary R81.10 management server in Azure. ( We will be upgrading entire environment next year to R82)
The primary server was built using Azure marketplace. marketplace
Per docs we are building the secondary server with the same marketplace app.
In this doc here it says to select Secondary server when creating the server. : Overview of Management High Availability
(Video shows R80 but is on the R81 Doc.)
But the first time setup wizard does not seem to run on first login and there are no options in the marketplace tool to select Secondary.
In the Smart Console the Secondary button is greyed out:
Can we just proceeded with syncing the servers with both servers set as primary ?
Primary and Secondary both have the latest hotfix installed.
There also does not seem to be anywhere to set a SIC key. I am guessing this would be available if this was a secondary server.
Also. the new secondary management server seems to take the public IP address by default.
Is this safe to change to the private post install ?
thanks
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No. Two Primary management server cannot sync and offer management HA.
When you deploy the image from the marketplace you need to choose Configure Manually under CloudGuard Advanced settings > Installation Type
Then you can run the FTW on the new server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No. Two Primary management server cannot sync and offer management HA.
When you deploy the image from the marketplace you need to choose Configure Manually under CloudGuard Advanced settings > Installation Type
Then you can run the FTW on the new server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to add a few notes:
You shared an R81 guide. It is best to use the R81.10 guides in your case. I don't think that you will see a difference in the case of management HA but it's still best to use the version specific documentation.
https://support.checkpoint.com/results/sk/sk170416 <-- Administration Guides
The Management HA for Azure solution deployment does not seem to be well documented and you are not the first to find fall into that trap.
I will ask for the documents to be updated.
Other references:
https://support.checkpoint.com/results/sk/sk173705
https://support.checkpoint.com/results/sk/sk54160
https://support.checkpoint.com/results/sk/sk132192
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Brilliant. Thanks for the quick reply !
Yes the docs seem to go around in circles sometimes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It happens 🙂
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You're welcome.
I've sent some feedback in about that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Don is 100% correct, you need to follow what he posted in his first response, and he stated, you can NOT sync two primary servers, that was never possible and Im sure it never will be.
Andy


