- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
I’ve got 2 appliances with R80.10 version. I need configure HA ClusterXL.
But unfortunately only one valid IP was given to our company. Behind FW we use 192.168.0.0/16, 172.16.0.0/16 and 10.0.0.0/8 subnets.
Admin guide describe to use any IP on external interfaces ( ex. 10.1.1.0/30) and configure VIP with valid IP .
How do I need to make static routes on each node?
For internal subnets I did routes, but for external I don’t know which routes I need do.
Thanks
Configuring Cluster Addresses on Different Subnets
You need to create a scopelocal route for that interface.
In CLI:
set static-route <Public-IP> nexthop gateway logical <Interface> on
set static-route <Public-IP> scopelocal on
And there is a checkbox for the same thing in Web-interface.
Configuring Cluster Addresses on Different Subnets
You need to create a scopelocal route for that interface.
In CLI:
set static-route <Public-IP> nexthop gateway logical <Interface> on
set static-route <Public-IP> scopelocal on
And there is a checkbox for the same thing in Web-interface.
Big thanks!!!!
Thanks a lot @AlekseiShelepov , you saved my day. Why on earth is this command "set static-route <Public-IP> scopelocal on" NOT mentionned in admin guide ? If you don't add this, the routes through local interface don't appear in the routing table! Incredible
I'm running into the same problem like Andrey, but I've got two 1400 series appliances with embeded gaia R77.20.75. It seems embeded gaia does not support scopelocal (sk32073). Any Idea how to solve this on embeded gaia?
Thanks!
Mario
Afaik this is supported by GAiA + ClusterXL only, not Embedded GAiA - the only two Advanced Settings for Clusters are only present in StandAlone SMBs (Cluster - Use virtual MAC and NAT - Perform cluster hide fold). And sk32073 Configuring Cluster Addresses on Different Subnets is only for GAiA and SecurePlatform.
Hi Checkmates,
Is this also support in R80.30.
We already implemented in R80.10 but we plane to upgrade to R80.30.
So kindly update if some done this in R80.30.
Thanks and Regards
Thanks for the update
CLusterXL R80.30 Administration Guide:
We done this activity withone any issue.
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 13 | |
| 10 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY