- CheckMates
- :
- Products
- :
- General Topics
- :
- CheckPoint Cluster Failover Query
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CheckPoint Cluster Failover Query
Hello CP Experts -
I have 2 CheckPoints 5100 in HA. Currently firewall fail-over takes place if primary firewall gets down physically. Now I want to setup in a way that if my WAN interface IP on primary firewall gets unreachable it will shift the traffic flow on the secondary firewall, Means my primary firewall need to be up physically but just due to its WAN interface gets unreachable it should make a route of all network traffic to secondary firewall and on Secondary firewall an alternate ISP starts Natting and making the internet reachable.
I hope I cleared my question. Looking forward for positive reply in this regards.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unless both gateways share the same subnet on all interfaces, have a shared IP, and can reach each other on all interfaces, you won't be able to cluster.
The shared IP would have to be reachable on both ISPs, which is not likely the case.
Also a cluster has to have exact the same policy (including NAT) on all members, which is not what you're asking for.
Bottom line: this won't work as a cluster.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Further, since this thread is in English, I am moving it to the proper space: General Product Topics
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, just a quick question, but if you have already an alternate ISP why not connect this to both gateways and have ISP redundancy on both gateways ? So on both gateways (active/passive) both ISP's are connected and in or load sharing mode or in Primary/Backup mode. I think that would make a bit more sense.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From the second edition of my book:
Question: We suffered an upstream network failure that did not occur on the network/VLAN directly adjacent to the firewall. There was not a failover to the standby member (who had a working network path further upstream) because ClusterXL could not detect this indirect upstream network failure. Can we configure ClusterXL to monitor some upstream IP addresses, and cause a failover to occur when they can no longer be reached?
Answer: Yes! See sk35780: How to configure $FWDIR/bin/clusterXL_monitor_ips script to run automatically on Gaia / Sec....
--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello everyone thank you for your responses. Further I need to design like this to have both Firewalls in active mode and need to have a failover to the cluster firewall if the WAN link gets unreachable.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can have both Firewalls in active mode and use two ISPs with ISP redundancy
