Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
paki
Explorer

ClusterXL using VIP address on same interface for multiple services

Hello everyone,

This is my first time posting here, so I hope I’m doing everything correctly.

I need some advice and help regarding a ClusterXL setup. I have configured HA and it is working properly, including failover.
What I would like to achieve now is to publish two services through a single interface. On that interface, each gateway (I have two in the cluster) has its own IP address, and there is also a cluster VIP.
My goal is to publish two additional services through that same interface, using the cluster VIP, so they are accessible from the outside.
I initially tried configuring Proxy ARP on each gateway, but that didn’t work. I also tried enabling VMAC on the cluster, but that didn’t help either.

What is the recommended way to publish multiple services on a single ClusterXL interface?
Does anyone have an idea how this could be implemented, or at least a suggestion on where I could find a relevant example or documentation for this scenario?

Thanks in advance 🙂

0 Kudos
2 Replies
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

It sounds like what you're looking to do is inbound destination NAT with services specified (basically, port forwarding). What services are you looking to configure here?

0 Kudos
paki
Explorer

Thanks for your reply.

The services I’m trying to publish are IPsec Site-to-Site VPN and VPN (for Remote Access).
Why would NAT be required if there is no internal server behind the gateway?
In this case, the gateway itself is the endpoint for the services.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events