- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Vsec Cluster in a Private Cloud
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
			
				
					
						
							Vsec Cluster in a Private Cloud
						
					
					
				
			
		
	
		
	
	
	
	
	
	
	
	
			
					
				
		
	
Hello,
We are using a private cloud which is based on Openstack. I wanted to know about the procedure of setting up a Vsec Cluster and if it is same with Azure or not? ... Please help how to proceed.
- Tags:
- vsec cluster
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We do have unicast sync, but I guess that's only for public cloud versions at the moment (e.g. AWS, Azure).
Lack of ClusterXL support for OpenStack is mentioned in the limitations of the vSEC for OpenStack R80.10 Administration Guide.
That means: no clustering at the moment.
Unicast sync is planned for R80.20, which would allow this to work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To the best of my knowledge, setting up a cluster in OpenStack is the same as for physical gateways or in VMware in Network Mode (not with NSX).
ClusterXL R80.10 (Part of Check Point Infinity) Administration Guide
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Daemon,
Thanks for your answer. Does it use multicasting or broadcasting for the state synchronization?... There is a limitation in cloud which does not allow to do it and we should find another way to sync the nodes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We do have unicast sync, but I guess that's only for public cloud versions at the moment (e.g. AWS, Azure).
Lack of ClusterXL support for OpenStack is mentioned in the limitations of the vSEC for OpenStack R80.10 Administration Guide.
That means: no clustering at the moment.
Unicast sync is planned for R80.20, which would allow this to work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah. Thanks for this useful information. Is there any update when we will have the R80.20? We really need this Unicast Sync.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Timelines for the release of R80.20 are not finalized, but you are welcome to use the public EA.
That said, I'm not sure if this feature is present in the current public EA or not.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Is there any limitation with for vSec HA clusters on R80.30 for :
1- VMware ESX private cloud
2- IBM Cloud
Thanks,
Herold
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am trying to deploy a cluster of gateways on that are in vmware and am unable to get them to cluster correctly. This is on R80.30 so I am thinking they have nothing on this yet. Cany anyone confirm this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nick,
You need to make sure all port security on the FW interfaces is turned off. If you do not, it for sure will not work.
 
					
				
				
			
		


 
					
				
		
 
		
			 
					
				
		
 
					
				
		
 
					
				
		
 
		
			 
					
				 
		
		
		
		
		
	
			 
					
				 
		
			