- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
We have 4 cluster members, can we make the cluster member status as Active, Standby, Backup, Backup? Is this achievable?
Regards,
Sanjay S
Not dealt with many clusters with more then two nodes, but using ClusterXL I believe the states are Active/Standby only. In order to define the failover order you would then set the priority order in SmartConsole > Cluster Object > Cluster Members
Im 99.99% sure its ONLY active/standby, but maybe someone from R&D can confirm 100% : )
I believe Active/Standby/Backup applied to VSX and perhaps VRRP.
Applies to VSX only.
VRRP is just specific priorities (highest one is active).
I think a more important question is: why?
What is it you’re trying to achieve with a four member cluster?
Surely it’s possible to do, but it seems like an awful lot of excess hardware for only a minimal gain in redundancy.
And if what you’re trying to do is a four member cluster across two sites, there are a lot of other issues you need to address.
Hi PhoneBoy,
We have 2 sites and placing 2 firewalls in each location and clustering all 4 of them. We need to prefer the 1st site to be active and only when both the firewalls in 1st has issues then the traffic should fail to 2nd site.
This does sounds like my original suggestion of priorities, assuming standard gateway cluster.
Remember that clustering assumes there are multiple shared Layer 2 segments between all the gateways with the same IP address space, particularly on the Internet side of the equation.
Between sites, this is rarely the case.
You need a clear picture of the entire network to understand what all the various traffic flows are and what it will actually take for a failover to occur.
Most likely, a four node cluster is NOT the solution in this case.
I agree, and in fact we are going to two of the gateways from the cluster as there is no benefit. I would just have the servers sitting in the rack as cold standbys if anything.
As Vlad has rightly said below, it would be better to have two separate HA cluster, at least you would then have utilisation of two of the nodes.
For the love of everything, do not do it 🙂 IMHO, better to invest time in the configuration of the routing failover between sites and have an HA cluster in each site.
With VSLS yes, in SGW mode no.
To complement PhoneBoy’s answer there is a clustering solution that could work in this case. It’s Check Point Maestro. With Maestro you can have several gateways active on one site and standby on another.
I was thinking about that as well, but ultimately it may not be a cost viable solution, but its certainly a good option, technically.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 21 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY