- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Dear Check Point Team,
Regarding the known issue with ClusterXL R80.20 and above does not support Load Sharing mode. Therefore, SmartConsole blocks such a configuration with a warning message.
I would like to know when it will be fixed and become to support like an R80.10.
Regards,
Sarm
In r80.20 /.30 we introduced new limitation on load sharing with VPN (Due to maestro code main train unification, we took the maestro side and broken the main train side. Since the usage is low, it was the best tradeoff among the alternatives).
Due to the type of limitation, we decided to block the whole feature temporarily till we will make it clearer (so user can understand what is working). We are now in the process of enabling the large part of load sharing that does work, on r80.30. If you need this more urgently, contact our solution center to get assistance till we complete the publication of it (as its artificially blocked).
Load sharing with vpn is still blocked (this requires development) and we will bring it back but in future release (most cases i saw that did use load sharing, didnt need the vpn aspect so the above should cover the vast majority).
Dorit
Scroll up in this checkmates post and see response from the R&D leader from October. The solution is available already part of GA jumbo's and you can read all about it in sk162637
Version | Take |
R80.20 | Jumbo HF take 117 and above |
R80.30 kernel 2.6.18/3.10 | Jumbo HF take 76 and above |
As for support for Load Sharing + VPN, it is available in a customer release for R80.40.
Please engage your local Check Point office to obtain this release.
It's planned to include this functionality in a future release (after R81).
I once copied a passage from @PhoneBoy answer:
CUT>>>
Load Sharing has a few limitations, see:
The amount of sync traffic required for ClusterXL Load Sharing significantly limits its scalability, particularly as you get into 3 and 4 node clusters.
It also reduces overall cluster resiliency in the case where one member fails, particularly if you are utilizing the load sharing cluster at or near capacity.
Given the above, I usually advocate for buying right-sized appliances for an HA configuration versus buying smaller appliances using load sharing.
And, in fact, this is what the vast majority of our customers do.
Maestro solves a lot of these limitations and improves scalability dramatically over ClusterXL Load Sharing.
<<<CUT
I also think Maestro is the future technology.
In r80.20 /.30 we introduced new limitation on load sharing with VPN (Due to maestro code main train unification, we took the maestro side and broken the main train side. Since the usage is low, it was the best tradeoff among the alternatives).
Due to the type of limitation, we decided to block the whole feature temporarily till we will make it clearer (so user can understand what is working). We are now in the process of enabling the large part of load sharing that does work, on r80.30. If you need this more urgently, contact our solution center to get assistance till we complete the publication of it (as its artificially blocked).
Load sharing with vpn is still blocked (this requires development) and we will bring it back but in future release (most cases i saw that did use load sharing, didnt need the vpn aspect so the above should cover the vast majority).
Dorit
today: all load sharing is blocked except maestro
working to certify: enabling load sharing without vpn on R80.30 (can be done now if urgent contact us)
later after more development: load sharing with vpn
Hi Dorit,
Thank you for clarification.
However, can you estimate the time that the Load Sharing mode will be back in R80.20 and R80.30?
As I know if the customer wants to use this functionality they need to implement with R80.10, right?
I am quite implicit above: if you need non-vpn load sharing, you can get it now over r80.30 if you can contact us or wait to get it published publicly
If you need vpn load sharing, we still need to develop so it will be on later release
If you are not clear, i recommend you will work w our local sales to further understand
Hi Dorit,
I got it now. Thanks for clarification again.
Hi,
Please refer to sk162637 regarding the support of ClusterXL Load Sharing mode in R80.20 and above.
Thanks for the new and informative SK, is there some reason that the lifting of the ClusterXL Load Sharing restriction is not shown in the "list of resolved issues" for the R80.20 and R80.30 Jumbo HFA takes?
Technically, load sharing vpn is still limited, ... so in order to avoid mistakes and the ui is technically still blocked (unless you open it).
Therefore you need to read the sk to open the ui and the release notes direct you to the sk
We have been waiting for a supported release that works with Cluster Load Sharing.
This is a major reason while we are evaluating other Firewall Solutions. I have been told many times by support that load sharing is not a recommended solution.
Scroll up in this checkmates post and see response from the R&D leader from October. The solution is available already part of GA jumbo's and you can read all about it in sk162637
Version | Take |
R80.20 | Jumbo HF take 117 and above |
R80.30 kernel 2.6.18/3.10 | Jumbo HF take 76 and above |
It still doesn't solve the problem because it supports ClusterXL Load Sharing WITHOUT Ipsec VPN.
Indeed
(1) Very small percentage used VPN w load sharing which is why we allowed this limitation in the first place
(2) This part (the VPN w load sharing) required more complicated resolution vs the Maestro / scalable platform VPN. Therefore we gave priority to integrating the high end into the maintrain at the cost of not supporting load sharing w VPN in the short term
(3) We have a function called solution center that helps us resolve such missing pieces when they impact the business, by driving formal commitment to complete certain functionality by a certain date (they will deliver a formal commitment). Please leverage your local sales team or contact @PhoneBoy off line to get assistance
As mentionend before, you currently can use either VSX VSLS or Maestro to overcome this limitation !
As for support for Load Sharing + VPN, it is available in a customer release for R80.40.
Please engage your local Check Point office to obtain this release.
It's planned to include this functionality in a future release (after R81).
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY