- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi all,
I am trying to test ClusterXL with VRRP as High Availability method.
I read some documents which says all I have to do in order to set it up is just to make ClusterXL cluster in a normal way, except for High Availability mode; VRRP.
I have already had one of cluster with ClusterXL in my lab, so I changed HA mode into VRRP just after I configured Advanced VRRP in GAiA Portal.
One of my coworkers told me that I can make sure HA mode by looking at the output of "cphaprob state".
I can clearly confirm the output changes before and after the configuration above.
Yet, #show vrrp returns me "VRRP not enabled".
Is this expected output in this occasion?
Both GW are managed by one SMS.
R81.20 without any JHF.
I did the following, which I believe it is how you configure VRRP in GAiA Portal:
1. In Advanced VRRP section, check Monitor Firewall State
2. Add Virtual Routers as follows
VRID: 1 Interface: eth0 VRRP Mode: VRRP Priority: 100 Hello Interval: 1 Preempt: Yes
Auto-deactivation: No Backup Addresses: None Monitored Interfaces: eth1 (delta: 10)
Priority of vRouter in standby VM is set to 99.
Any comments would be more than welcome!
Saitoh
I solved this by adding backup address as follows.
ClusterXL VIP for eth0: 10.31.10.113
vRouter 1 backup address: 10.31.10.113
Then #show vrrp returns VRRP state!
What is this "backup address" ? no idea what this address is used in VRRP function.
Saitoh
What steps you have followed?
This one?
https://support.checkpoint.com/results/sk/sk92061
And why VRRP if I may ask? See for limitations
https://support.checkpoint.com/results/sk/sk105170
All clusters I manage are ClusterXL and soon will be ElasticXL
Dear @Lesley ,
Thanks for your comments.
I followed the steps below.
One thing, I did not add backup address because I thought this is optional.
I would like to try ClusterXL over VRRP. That is why.
Yet, I still have confusing idea on this.
I thought they are the methods for making network redundant, one is universal and the other CP-exclusive, and
do not understand why you want to use them both...
Saitoh
Im with @Lesley on this one, those SKs are definitely relevantt in your case.
Andy
Dear @the_rock ,
Appreciated for your comment.
I thought I configured VRRP rightly, judging from the fact below:
When only ClusterXL enabled, #cphaprob state returns the following.
Cluster Mode: New High Availability (Primary Up)
with IGMP Membership
Number Unique Address Assigned Load State
1 (local) 192.168.0.1 100% Active
2 192.168.0.2 0% Standby
Then I changed HA mode to VRRP with Advanced VRRP settings done in GAiA Portal, the output changes.
Cluster Mode: Sync only (OPSEC) with IGMP Membership
Number Unique Address Firewall State (*)
1 (local) 192.168.0.1 Active
2 192.168.0.2 Active
(*) FW-1 monitors only the sync operation and the security policy
Use OPSEC's monitoring tool to get the cluster status
Considering the outputs, I thought it is safe to say VRRP is enabled.
However #show vrrp says VRRP not enabled.
This is not very persuasive...
Saitoh
I took routed trace on questioning cluster, and then I noticed they actually were communicating with each other, yet some necessary config might be missing.
I solved this by adding backup address as follows.
ClusterXL VIP for eth0: 10.31.10.113
vRouter 1 backup address: 10.31.10.113
Then #show vrrp returns VRRP state!
What is this "backup address" ? no idea what this address is used in VRRP function.
Saitoh
I could be mistaken, but I believe its similar to VIP in clusterXL.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 29 | |
| 15 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY