Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mikula83
Contributor
Jump to solution

ClusterXL and Smart-1 Cloud as a management

Hello,

please let me know is it possible to have different IPs on real and VIP interfaces on outside interface if you use Smart-1 Cloud as a management server.  (Lets assume you get a public IP from ISP with mask-length 30, for examle 90.90.90.0/30, 90.90.90.2 is default gateway and 90.90.90.1 is VIP on ClusterXL outside interface, Is it possible to have private IPs on real interfaces?)

I know that it is possible when you have on-prem management server but I'm not sure when you have Smart-1 Cloud management server.

 

My next question is about licenses. If you buy Smart-1 Cloud license to manage 5 gateways and you have ClusterXL with two gateways does it consume 1 or 2 licenses?

 

Best regards,

Milan Babic

1 Solution

Accepted Solutions
Wolfgang
Authority
Authority

@Mikula83 it's not possible to manage a cluster with private IP-addresses. All nodes of the cluster must be reachable via Internet.

Configuring Cluster Addresses on Different Subnets

  • It is not possible to manage the Cluster over the Internet when the IP addresses of its members and the VIP address are configured on different subnets.In such configuration, the IP addresses of cluster members are supposed to be configured with private IP addresses (RFC 1918), and only one Cluster VIP address is supposed to be public. Private IP addresses (RFC 1918) are not allowed over the Internet. As a result, communication from the external Management Server to the private IP addresses of the physical cluster members will not be possible over the Internet for services such as SIC.
  • Quantum Smart-1 Cloud can manage Cluster Members that do have public IP addresses on the Internet. For instructions, see the Quantum Smart-1 Cloud Administration Guide.

Rregarding the licenses... a cluster of X gateways consume X gateway licenses.

View solution in original post

4 Replies
G_W_Albrecht
Legend Legend
Legend

Afaik, OnPremise and Smart-1 Cloud SMS have the same functionality except the limitations from https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-... !

Licenses to manage GWs are counted by GW - you can use HA or LS Clustering, so this is understandable, and the same is true of services that have to be bought for each GW, even if only used as Standy node in ClusterXL...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Wolfgang
Authority
Authority

@Mikula83 it's not possible to manage a cluster with private IP-addresses. All nodes of the cluster must be reachable via Internet.

Configuring Cluster Addresses on Different Subnets

  • It is not possible to manage the Cluster over the Internet when the IP addresses of its members and the VIP address are configured on different subnets.In such configuration, the IP addresses of cluster members are supposed to be configured with private IP addresses (RFC 1918), and only one Cluster VIP address is supposed to be public. Private IP addresses (RFC 1918) are not allowed over the Internet. As a result, communication from the external Management Server to the private IP addresses of the physical cluster members will not be possible over the Internet for services such as SIC.
  • Quantum Smart-1 Cloud can manage Cluster Members that do have public IP addresses on the Internet. For instructions, see the Quantum Smart-1 Cloud Administration Guide.

Rregarding the licenses... a cluster of X gateways consume X gateway licenses.

PhoneBoy
Admin
Admin

ClusterXL requires a management license for each member of the cluster (thus you need two).
If you do this with ElasticXL (requires R82), only one management license is required (for the SMO).

0 Kudos
Mikula83
Contributor

Thanks.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events