- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello, a customer wants to deploy a cluster node in monitor mode, is it possible to do this? if so, how?
Whilst you have the ability to set an interface as private, sk101670 lists this cluster + monitor mode as not supported.
Whilst you have the ability to set an interface as private, sk101670 lists this cluster + monitor mode as not supported.
Hi Chris,
Reading the SK you sent me, I noticed that "Support for Cluster - ClusterXL / 3rd Party cluster is not supported in Monitor Mode." However, we are planning to perform this action on a cluster node...
This makes me think that the node we are going to work on will need to be detached from the cluster. So, should we remove the "unit is a part of cluster" setting, making the other node always active?
This also makes me wonder—will a fresh install be required?
I'm a bit confused about how this should be done. I hope I explained myself clearly.
Thanks!
It's not supported if the gateway is part of a cluster only a discrete gateway or standalone.
However, if I want to, can I remove the node from the cluster (standbay one) and use that removed node (GW) to use it as a monitor?
Correct.
Generally, yes, but if you are using an -HA license on the secondary node, you can't do this since an -HA license must be used as a non-primary node for ClusterXL, not on it's own.
I don't think I understand 100%, can you please explain more?
What @PhoneBoy is saying is that if you are using HA license on clustered node and you remove it from the cluster (ie disable cluster mechanism in cpconfig and reboot) that is sill NOT enough. You would need to remove the HA license and apply regular license for eother single gw or standalone. I would just apply an eval for the time being and make sure it works the way you wanted.
Makes sense?
Andy
So the moment I remove a member from a cluster.
yes quite clear now
Will this also affect the active node license?
Another question: If I remove a node from a cluster, do I have to perform any other actions on the active node? Can it affect the active node in any way?
Anyway then I will try to do a lab to test it, although in production we have S1C
Cluster will be broken,if you do this. Yes, I would 100% test it in the lab.
Andy
But my question is: I want to be able to delete a node from a cluster. and can the deleted node be recovered somehow, as a single standalone gateway? Or can't I do that because when I did the time wizard it was checked as part of a cluster?
In the lab I tried to delete a node from a cluster, but it didn't give me any problems....
Maybe it's better if i open an TAC
i follow this guide:
Removing a Member from an Existing Cluster
Thank you very much
Thats EXACTLY what I followed in the past. Here is the key...so does not matter how you did first time wizard, if you remove it from the cluster, you simply have to run cpconfig, disable cluster membership, reboot, thats it.
Andy
okay andy and so far I'm there, and I agree with you.
Once I perform these actions, my question is, can I connect it under the same CMA, but as a single gateway? or can I not?
thakns
Worked for me when I did it in the lab before, though regular mgmt, but cant imagine that would matter.
Andy
I will try on my own and let you know me too
thank you
Thats absolutely the best thing to do, agree.
Andy
Do you know how I can get an S1C for a lab?
Not sure, honestly. Probably talk to your local SE about it.
Andy
If instead of removing the node on the Smart Console side, I physically unplug the cables and use a stick to do the reinstall (fresh install) , then install it as a new gateway, then assign new IPs to it (as if it were a new gateway), is this possible?
I hope I have explained myself.
Never tried it like that myself, but logically, sounds like would work.
Andy
As a side note, MAKE sure that if IP would match its NOT used anywhere else.
Andy
do you mean the ip that will be used for the configuration for the new GW? by new I mean the standbay on which the fresh install will be done for monitor gateway
Thats right, just make sure whatever IP is assigned is not used anywhere else.
Andy
definitely yes, thanks
No worries.
Policy install requires pushing the policy to all ClusterXL members.
If you don't remove the relevant gateway object from the cluster, this could cause an issue.
I physically unplug the cables and use a stick to do the reinstall (fresh install) , then install it as a new gateway, then assign new IPs to it (as if it were a new gateway), is this possible or not? from your side PhoneBoy
Confirm the licensing on the relevant gateway first (cplic print).
Assuming there is no -HA SKU in there, it should work.
That does not invalidate my comment about removing the gateway object from the cluster (which should be done).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
11 | |
7 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY