Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
yeruel
Collaborator

ElasticXL with VSNext Deployment – Secondary Appliance Initial Configuration Clarification

Hello Check Point Community and Support Team,

I would appreciate confirmation regarding the deployment procedure for ElasticXL with VSNext on two Check Point 29200 Security Gateways managed by a Smart-1 700S Management Server.

Planned Deployment Architecture

Hardware:

  • 2 × Check Point 29200 Appliances (AfricTesla-FW-01 and AfricTesla-FW-02)
  • 1 × Smart-1 700S Management Server

Deployment Steps

  1. Physical installation completed (rack, power, and cabling).
  2. AfricTesla-FW-01 connected directly to AfricTesla-FW-02 using Sync1 and Sync2 interfaces.
  3. Both gateways connected to the Campus Core network.
  4. Both gateways connected to external Data/MPLS routers.
  5. Both gateways connected to the Internet firewall.
  6. Powered on AfricTesla-FW-01 and configured the management interface:
    set interface mgmt ipv4-address 10.1.0.20 netmask 255.255.255.0
    1. Accessed the WebUI and completed the First Time Wizard, enabling:
      • ElasticXL
      • VSNext
    2. Added the gateway to SmartConsole, published the configuration, installed policy, and configured:
      • Interfaces
      • Bonding
      • VLANs
      • Routing
      • VSNext objects
      • Other required settings

    Question Regarding the Second Appliance

    At this point, I plan to power on AfricTesla-FW-02 and connect only:

    • Power
    • Sync1/Sync2
    • Production network cables

    My understanding is that in ElasticXL architecture the first gateway becomes the Single Management Object (SMO) and the second appliance joins the cluster as a member.

    Therefore, I would like clarification on the following:

    1. Does AfricTesla-FW-02 require its own management IP configuration before joining the ElasticXL cluster?
    2. Do I need to run the First Time Wizard on AfricTesla-FW-02?
    3. Should ElasticXL and VSNext be enabled manually on the second appliance as well?
    4. Is the correct procedure simply:
      • Configure FW-01 completely.
      • Create and configure the ElasticXL environment.
      • Power on FW-02.
      • Connect Sync interfaces.
      • Allow FW-02 to join and synchronize automatically.

    My assumption is that only the first appliance requires the full initial configuration, while the second appliance only requires minimal bootstrap information (if any) before joining the ElasticXL cluster.

    Could someone confirm the exact on-boarding process for the second 29200 appliance in an ElasticXL + VSNext deployment?

    Thank you in advance for your guidance.

0 Kudos
11 Replies
Alex-
MVP Silver
MVP Silver

That's the idea. You don't FTW the second unit, it will appear as candidate to join the cluster from the relevant section on the WebUI or Clish. Follow the show by using the insights tool in CLI where all logs, popups and so on will indicate what's happening.

0 Kudos
Alex-
MVP Silver
MVP Silver

Also, pro tip: you shouldn't share your customer names and infrastructure diagrams on public forums.

Admins should intervene.

yeruel
Collaborator

Dear Alex,

As I understood from your point 

  • AfricTesla-FW-01 → Full FTW + ElasticXL + VSNext + SmartConsole management.
  • AfricTesla-FW-02 → Power on and connect cables only. Even not give any initial management address. 
  • FW-02 appears as a candidate.
  • Add FW-02 to the ElasticXL fabric.
  • Configuration is automatically inherited from the SMO.

    Please note that the customer AfricTesla is my imagination that doesn't existing. But I will deploy the solution to my customer. 
0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

This is correct, you don't configure anything on gateways that will join an existing EXL setup.

0 Kudos
yeruel
Collaborator

Hi Dear, I am trying on pnetlab for elasticXL, 

I have completed full on First appliance(fw1),

then trying to power up the second appliance, elasticXL second memeber is not coming as expected. 

Please provide your suggestion. Is virtual on pnet or EVG supported on for elasticXL?

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Only VMWare is supported officially for EXL on VMs. You may be able to make it work on other platforms if you hack about with your VMs following the Open Server instructions in here:

https://support.checkpoint.com/results/sk/sk183513 

0 Kudos
yeruel
Collaborator

Is elasticlXL supported on Proxmox ?

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Proxmox is KVM based, so not out of the box, no. As I say though, if you want to hack about with the Open Server configuration items in that link you might be able to get it to work for non-production purposes only.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Note that you need to connect at least one of the interfaces named Mgmt as well as one of the interfaces named Sync.

You should run sync through switches. The members should not be directly connected.

It should be possible to get ElasticXL and VSNext working under most hypervisors, but Check Point only supports it (i.e, provides help if it doesn't work) on VMware ESXi.

0 Kudos
yeruel
Collaborator

Hi Bob Zimmerman,

I have two Quantum Force 29200 appliances and I am planning to deploy ElasticXL.

For the synchronization network, I would like to confirm whether a direct sync connection between the two appliances (29200 ↔ Sync ↔ 29200) is sufficient for ElasticXL operation, or if the sync interfaces must be connected through switches.

Could you please advise on the recommended design and best practice for ElasticXL synchronization?

Thank you.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Direct connections mostly work, but you may experience weird cluster issues. The most common I see is rebooting one member (e.g, for an update) can cause the other member to believe it has failed and refuse to process any traffic, resulting in a total outage. I personally wouldn't run direct-wired sync on anything outside a lab. Running sync through switches is more reliable.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events