- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi Mates,
I have two checkpoint 6200, one as active and other as cold backup. Each role for device are as standalone (gateway and sms).
We're planning to create HA from this checkpoint, my questios are
1. Do we need separate Security Management to control this HA,
- If no need, how to achieve this?
- for SMS can we use VM despite purchasing other checkpoint device?
2. Do we need to factory reset to config Cluster XL from First Time Configuration Wizard? or just create it from Smart Console?
Regard's
Satryo
You can do what we call a Full High Availability Cluster, where both management and gateway are on both members. Details are in the install guide:
You can also run management on a separate VM if you wish, but you will need to purchase an additional management server license for this.
You will need to rebuild from scratch to move to a Full HA solution.
Better ask TAC for guidance - the procedure i wrote about is found in sk104699: How to configure a Standalone machine to become a part of a Full HA cluster, but this is not supported in R80 versions.
You can do what we call a Full High Availability Cluster, where both management and gateway are on both members. Details are in the install guide:
You can also run management on a separate VM if you wish, but you will need to purchase an additional management server license for this.
You will need to rebuild from scratch to move to a Full HA solution.
Sure, i have done this before (creating Full HA), but my question is, can we do without rebuild from scratch, and how to achieve this, ex using separate SMS
Regard's
Satryo
I don't think you can merge 2 standalone into a HA as they have different database.
As i wrote above, no merge is needed - you have a backup device with the same rulebase, or an active device with the current rulebase (that is the one i would use 😉
I wrote that one has to undergo FTW again and be designated the secondary management during installation. As planned, the primary node will the sync the database to the secondary.
You just have one defined as Primary and reset the second one, do FTW for secondary management there and other needed config; database will be synced with the primary SMS cluster node. As the rules are the same on both devices you will loose nothing...
Just to make sure, so there is no confusion, ostensibly, you want to convert full HA into 2 separate managements managing HA cluster, right?
If so, you can use below link, it details everything.
Andy
no i want to do it reverse, two standalone into HA.
Regard's
Got it...yes, so what @emmap had said is 100% right.
Sorry for my misunderstanding. And yes, you will need to rebuild, no other way around it. I know someone while back who did it without rebuilding, but it was totally unsupported, so I wont even try to explain it lol
Andy
For the context, this sk also might be helpful.
Andy
https://support.checkpoint.com/results/sk/sk60443
so i need to backup and then restore after HA up, when restoring from standalone device into HA, do it will replace HA configuration? and back to standalone. how about@G_W_Albrecht solution, only secondary being rebuild.
regard's
satryo
reagrd's
satrtyo
Better ask TAC for guidance - the procedure i wrote about is found in sk104699: How to configure a Standalone machine to become a part of a Full HA cluster, but this is not supported in R80 versions.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 18 | |
| 11 | |
| 10 | |
| 8 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY