Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
paki
Participant
Jump to solution

ClusterXL using VIP address on same interface for multiple services

Hello everyone,

This is my first time posting here, so I hope I’m doing everything correctly.

I need some advice and help regarding a ClusterXL setup. I have configured HA and it is working properly, including failover.
What I would like to achieve now is to publish two services through a single interface. On that interface, each gateway (I have two in the cluster) has its own IP address, and there is also a cluster VIP.
My goal is to publish two additional services through that same interface, using the cluster VIP, so they are accessible from the outside.
I initially tried configuring Proxy ARP on each gateway, but that didn’t work. I also tried enabling VMAC on the cluster, but that didn’t help either.

What is the recommended way to publish multiple services on a single ClusterXL interface?
Does anyone have an idea how this could be implemented, or at least a suggestion on where I could find a relevant example or documentation for this scenario?

Thanks in advance 🙂

1 Solution

Accepted Solutions
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

That's a very standard ClusterXL Deployment, so any of the admin guides relevant to your version would be applicable. Check the SK page for your version, they're all linked there. For example, this is the R82 page:

https://support.checkpoint.com/results/sk/sk181127 

In the Documentation section, click on View and you'll see them there, including the VPN guides.

View solution in original post

(1)
6 Replies
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

It sounds like what you're looking to do is inbound destination NAT with services specified (basically, port forwarding). What services are you looking to configure here?

paki
Participant

Thanks for your reply.

The services I’m trying to publish are IPsec Site-to-Site VPN and VPN (for Remote Access).
Why would NAT be required if there is no internal server behind the gateway?
In this case, the gateway itself is the endpoint for the services.

emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

There's no need to futz with anything at the clustering level to enable these services for the gateway cluster, it will already be working using the VIP when you enable and configure them. 

(1)
paki
Participant

Thanks for your reply.

Just to confirm my understanding:
since the VPN services are running directly on the gateway, there is no need for NAT or Proxy ARP configuration.

The ClusterXL VIP is already used as the endpoint and once the VPN blade is enabled and configured the services are automatically accessible via the VIP.

So essentially, no additional configuration at the clustering or NAT level is required for publishing these services.

One more question, I currently have the Installation and Upgrade Guide, but do you recommend any more relevant or in depth documentation specifically for this type of implementation?

Thanks in advance!

emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

That's a very standard ClusterXL Deployment, so any of the admin guides relevant to your version would be applicable. Check the SK page for your version, they're all linked there. For example, this is the R82 page:

https://support.checkpoint.com/results/sk/sk181127 

In the Documentation section, click on View and you'll see them there, including the VPN guides.

(1)
paki
Participant

Thanks for your fast replay.

I will follow your recommendation and if I have any further questions, I will post them there. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events