- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
I am creating an ElasticXL cluster. My question is: which interfaces need to be connected between the gateways? Only the SYNC interface, or which ones?
And what do I need to configure on the second member? Is it enough to just have the SYNC interface connected and that’s it? Will it appear automatically?
I’ve tried it, but the second gateway does not appear for me to add it.
For ElasticXL, you need a minimum of four interfaces on each gateway that are connected to the same Layer 2 network, covering Internal, External, Management, and Sync.
This is shown in the documentation: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ScalablePlatforms_AdminGuide...
I believe you need another data interface as well, sync is not enough.
Can it be any interface and be in the same segment?
I believe so, yes. Im not sadly elasticxl expert by any means, so maybe someone else can confirm for sure, but I think it can be any interface in L2 domain.
Okay, currently I'm using a back-to-back cable, meaning a cable between them so they can connect, but unfortunately my main computer isn't detecting it.
Make sure its same VLAN segment and L2 domain.
For ElasticXL, you need a minimum of four interfaces on each gateway that are connected to the same Layer 2 network, covering Internal, External, Management, and Sync.
This is shown in the documentation: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ScalablePlatforms_AdminGuide...
So, if I wanted to create a lab and create an Elastic XL, I couldn't? Only with a back-to-back cable? Do I absolutely need four interfaces?
What would the interfaces be?
A-Management interface
B-External interface
C-Synchronization interface
D-Internal interface
You need four different L2 network segments.
They can be VLANs, though you usually do not put your sync on a VLAN.
And yes, those are what the segments are for.
You create your first gateway as an EXL cluster gateway. Connect up the interfaces you want to connect to your network, there's presumably an internal interface (that could also be the management interface, magg1) and an external interface. SIC it to management, get a policy on there, make sure it all works.
Install the second gateway. Don't do the FTW, just have it freshly installed. Connect the Sync interface back to back with the first gateway. Connect the other interfaces to the same network segments as the first gateway. Each gateway in an EXL cluster is a semi-independent node on the network, requiring connectivity on the same interfaces to the same networks, much the same as a CXL cluster. In fact, cable it exactly the same as you would a CXL cluster. Then the second gateway will be available from the Cluster interface in the WebUI of the first gateway under Pending Gateways. You can add it to the cluster there.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY