- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi All,
We have 4 cluster members, can we make the cluster member status as Active, Standby, Backup, Backup? Is this achievable?
Regards,
Sanjay S
Not dealt with many clusters with more then two nodes, but using ClusterXL I believe the states are Active/Standby only. In order to define the failover order you would then set the priority order in SmartConsole > Cluster Object > Cluster Members
Im 99.99% sure its ONLY active/standby, but maybe someone from R&D can confirm 100% : )
I believe Active/Standby/Backup applied to VSX and perhaps VRRP.
Applies to VSX only.
VRRP is just specific priorities (highest one is active).
I think a more important question is: why?
What is it you’re trying to achieve with a four member cluster?
Surely it’s possible to do, but it seems like an awful lot of excess hardware for only a minimal gain in redundancy.
And if what you’re trying to do is a four member cluster across two sites, there are a lot of other issues you need to address.
Hi PhoneBoy,
We have 2 sites and placing 2 firewalls in each location and clustering all 4 of them. We need to prefer the 1st site to be active and only when both the firewalls in 1st has issues then the traffic should fail to 2nd site.
This does sounds like my original suggestion of priorities, assuming standard gateway cluster.
Remember that clustering assumes there are multiple shared Layer 2 segments between all the gateways with the same IP address space, particularly on the Internet side of the equation.
Between sites, this is rarely the case.
You need a clear picture of the entire network to understand what all the various traffic flows are and what it will actually take for a failover to occur.
Most likely, a four node cluster is NOT the solution in this case.
I agree, and in fact we are going to two of the gateways from the cluster as there is no benefit. I would just have the servers sitting in the rack as cold standbys if anything.
As Vlad has rightly said below, it would be better to have two separate HA cluster, at least you would then have utilisation of two of the nodes.
For the love of everything, do not do it 🙂 IMHO, better to invest time in the configuration of the routing failover between sites and have an HA cluster in each site.
With VSLS yes, in SGW mode no.
To complement PhoneBoy’s answer there is a clustering solution that could work in this case. It’s Check Point Maestro. With Maestro you can have several gateways active on one site and standby on another.
I was thinking about that as well, but ultimately it may not be a cost viable solution, but its certainly a good option, technically.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 4 | |
| 4 | |
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaThu 04 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E9: READY OR NOT: Securing the AI Enterprise 1/5 - AI Agent SecurityAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY