Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jcisneros
Participant
Jump to solution

Elastic XL

I am creating an ElasticXL cluster. My question is: which interfaces need to be connected between the gateways? Only the SYNC interface, or which ones?

And what do I need to configure on the second member? Is it enough to just have the SYNC interface connected and that’s it? Will it appear automatically?

I’ve tried it, but the second gateway does not appear for me to add it.

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

For ElasticXL, you need a minimum of four interfaces on each gateway that are connected to the same Layer 2 network, covering Internal, External, Management, and Sync. 
This is shown in the documentation: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ScalablePlatforms_AdminGuide...

View solution in original post

9 Replies
the_rock
MVP Diamond
MVP Diamond

I believe you need another data interface as well, sync is not enough.

Best,
Andy
0 Kudos
jcisneros
Participant

Can it be any interface and be in the same segment?

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I believe so, yes. Im not sadly elasticxl expert by any means, so maybe someone else can confirm for sure, but I think it can be any interface in L2 domain.

Best,
Andy
0 Kudos
jcisneros
Participant

Okay, currently I'm using a back-to-back cable, meaning a cable between them so they can connect, but unfortunately my main computer isn't detecting it.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Make sure its same VLAN segment and L2 domain.

Best,
Andy
0 Kudos
PhoneBoy
Admin
Admin

For ElasticXL, you need a minimum of four interfaces on each gateway that are connected to the same Layer 2 network, covering Internal, External, Management, and Sync. 
This is shown in the documentation: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ScalablePlatforms_AdminGuide...

jcisneros
Participant

So, if I wanted to create a lab and create an Elastic XL, I couldn't? Only with a back-to-back cable? Do I absolutely need four interfaces?

What would the interfaces be?

A-Management interface

B-External interface

C-Synchronization interface

D-Internal interface

0 Kudos
PhoneBoy
Admin
Admin

You need four different L2 network segments.
They can be VLANs, though you usually do not put your sync on a VLAN.
And yes, those are what the segments are for.

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

You create your first gateway as an EXL cluster gateway. Connect up the interfaces you want to connect to your network, there's presumably an internal interface (that could also be the management interface, magg1) and an external interface. SIC it to management, get a policy on there, make sure it all works. 

Install the second gateway. Don't do the FTW, just have it freshly installed. Connect the Sync interface back to back with the first gateway. Connect the other interfaces to the same network segments as the first gateway. Each gateway in an EXL cluster is a semi-independent node on the network, requiring connectivity on the same interfaces to the same networks, much the same as a CXL cluster. In fact, cable it exactly the same as you would a CXL cluster. Then the second gateway will be available from the Cluster interface in the WebUI of the first gateway under Pending Gateways. You can add it to the cluster there.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 05 Mar 2026 @ 12:00 PM (SGT)

    2026 Threat Landscape Briefing - APAC

    Thu 05 Mar 2026 @ 03:00 PM (CET)

    2026 Threat Landscape Briefing - EMEA

    Thu 05 Mar 2026 @ 11:00 AM (EST)

    Tips and Tricks 2026 #1: MCP Servers

    Thu 05 Mar 2026 @ 02:00 PM (EST)

    2026 Threat Landscape Briefing -AMER
    CheckMates Events