- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hello Check Point Community and Support Team,
I would appreciate confirmation regarding the deployment procedure for ElasticXL with VSNext on two Check Point 29200 Security Gateways managed by a Smart-1 700S Management Server.
Hardware:
At this point, I plan to power on AfricTesla-FW-02 and connect only:
My understanding is that in ElasticXL architecture the first gateway becomes the Single Management Object (SMO) and the second appliance joins the cluster as a member.
Therefore, I would like clarification on the following:
My assumption is that only the first appliance requires the full initial configuration, while the second appliance only requires minimal bootstrap information (if any) before joining the ElasticXL cluster.
Could someone confirm the exact on-boarding process for the second 29200 appliance in an ElasticXL + VSNext deployment?
Thank you in advance for your guidance.
That's the idea. You don't FTW the second unit, it will appear as candidate to join the cluster from the relevant section on the WebUI or Clish. Follow the show by using the insights tool in CLI where all logs, popups and so on will indicate what's happening.
Also, pro tip: you shouldn't share your customer names and infrastructure diagrams on public forums.
Admins should intervene.
Dear Alex,
As I understood from your point
This is correct, you don't configure anything on gateways that will join an existing EXL setup.
Only VMWare is supported officially for EXL on VMs. You may be able to make it work on other platforms if you hack about with your VMs following the Open Server instructions in here:
Is elasticlXL supported on Proxmox ?
Proxmox is KVM based, so not out of the box, no. As I say though, if you want to hack about with the Open Server configuration items in that link you might be able to get it to work for non-production purposes only.
Note that you need to connect at least one of the interfaces named Mgmt as well as one of the interfaces named Sync.
You should run sync through switches. The members should not be directly connected.
It should be possible to get ElasticXL and VSNext working under most hypervisors, but Check Point only supports it (i.e, provides help if it doesn't work) on VMware ESXi.
Hi Bob Zimmerman,
I have two Quantum Force 29200 appliances and I am planning to deploy ElasticXL.
For the synchronization network, I would like to confirm whether a direct sync connection between the two appliances (29200 ↔ Sync ↔ 29200) is sufficient for ElasticXL operation, or if the sync interfaces must be connected through switches.
Could you please advise on the recommended design and best practice for ElasticXL synchronization?
Thank you.
Direct connections mostly work, but you may experience weird cluster issues. The most common I see is rebooting one member (e.g, for an update) can cause the other member to believe it has failed and refuse to process any traffic, resulting in a total outage. I personally wouldn't run direct-wired sync on anything outside a lab. Running sync through switches is more reliable.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Mon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY