- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Good day All,
I have two Spark 2530 appliance (running R82.00.00 gaia embedded) in a cluster. I have only two public IPs in a mask range of /30 from our ISP provider. Can we achieve ClusterXL with only these two public IPs??
In the ClusterXL admin guide section "Cluster IP Addresses on Different Subnets" page 191. The instructions references "Network management" and this option is not available in our Spark 2530 cluster deployment. Does that mean we cannot achieve Clustering with only two IPs on 2530 appliances??
Is the cluster locally managed or is it managed via central management with a security management server (SMS)?
See the R82.00.X admin guide here: https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/AdminGuides_Centrally_Managed...
A cluster with a single public IP is supported on SMB appliances from R81.10.05.
https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_FAQ/Content/Topics/Cluster.htm
Is the cluster locally managed or is it managed via central management with a security management server (SMS)?
See the R82.00.X admin guide here: https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/AdminGuides_Centrally_Managed...
Just an addition to the document, do not use non private IP-addresses for the interface, but use some from RFC1918 unlike the example.
Thanks much. I did try this for the most part. I was having trouble when i selected "get interfaces with topology", It automatically placed a dummy IP address in and was reading my "WAN" interface as internal. But i did not have all settings as prescribe in the guide. So i will try this and advise later in the week.
Thanks again to u and Chris
The Cluster is managed by a Smart-1 SMS appliance
Are management and cluster at the same location? Then it should work:
"Important Note - The management must be internal or have an internal interface, and the SIC is established internally."
As an update. This does not work for me. Maybe my situation is different.
Issue
ISP provided only two public IPs
Steps Taken:
The documentation advise that this was possible. should i open a Check support ticket?
Yes, if the system is not letting you configure something as the documentation suggests it should, please raise a ticket.
Hello All,
This is not supported on GAIA embedded platform. which means our SMB spark appliance is not compatible with thsi feature.
we have to enable the "scopelocal" feature and this is not supported. see SK32073
Excerpt:
"scopelocal" is not supported on Gaia Embedded. Hence, this feature is not supported for SMB.
https://support.checkpoint.com/results/sk/sk32073
A cluster with a single public IP is supported on SMB appliances from R81.10.05.
https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_FAQ/Content/Topics/Cluster.htm
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Thu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY