Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Kasuntha95
Explorer
Jump to solution

Firewall migration from Active/Active to Active/Passive

Hi Guys,

Can somebody share if you have any experience in migrating Checkpoint Cluster environment from Active/Active to Active/Passive.

What Areas need to focus. I m not planning to do any change to existing gateways. Need to migrate them with Active/Passive cluster setup.

Thanks.

0 Kudos
1 Solution

Accepted Solutions
_Val_
Admin
Admin

This should be the easiest one yet. Change the cluster mode in the SmartConsole and push the policy. That should be enough, and I would not expect any caveats on the way. 

View solution in original post

0 Kudos
2 Replies
_Val_
Admin
Admin

This should be the easiest one yet. Change the cluster mode in the SmartConsole and push the policy. That should be enough, and I would not expect any caveats on the way. 

0 Kudos
the_rock
MVP Gold
MVP Gold

Personally, I always found active/passive is better and here is why I say that. You may think, well if its active/active, firewalls will simultaneously share the traffic, which is indeed true, but lots of times, randomly, specific connections may get dropped and not be processed at all.

In active passive scenario, that literally never happens, since you always have 1 active member and if any issues, it will failover to 2nd one. 

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events