- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I was what the general consensus is on clustering standalone units, so with management + gateway on the same appliance. Or perhaps not even clustering, but the idea of standalone units as a whole.
We're dealing mostly the customer who buy the 4000 and 5000-series appliances and we've had the feeling, from day one of stepping into the CheckPoint partner playing field, that standalone setups are supported, but never mentioned. With every proposal that we've done together with CheckPoint, it was always assumed that, no matter what, a separate management server was the way to go. To tell you the truth, I didn't know that a HA setup with 2 standalone units was even supported.
What gives? What are your experiences with standalone units, HA or not?
My opinion - say no to standalone setups with Check Point (unless it is not an SMB device).
Some time ago I implemented a setup of two 4800 appliances with increased RAM working in Full HA (FW + Mgmt) on R77.30 version of software. As I remember, some NGFW blades were enabled - IPS and Application Control. Something around 50 - 100 rules and standard profiles without much tuning.
Every time when policy was installed there were drops of traffic (very short, but visible with simple ping), because policy verification and compilation is quite a resource-demanding operation. The setup ended up with node 1 acting as active FW and node 2 as active management server. Not enough space on HDD to store logs for a longer time, log Indexing (SmartLog) was not really possible.
It also adds complexity to software upgrades and maintenance. Higher risks of ruining management database. Higher risks of some security issues. More time and troubles to restore a gateway from a backup. Snapshots might be not possible to make because there would be no enough space.
Of course, if there are much more powerful appliances you can try the setup. It would be interesting to know how it would perform, just for fun. But I think that anyone who buys some 15000-23000 appliances already has a server, most probably even MDS. Right?
And I would definitely not recommend standalone setup with R80.10 - management server will eat all RAM and CPU that you have. Although, there is this sk120131 which assumes that everything would be fine.
I would avoid standalone deployments in all but the smallest of environments, especially Full HA (standalone setup in a cluster)
Thanks for the comments so far, this is exactly the kind of input I'm looking for and it annoys me that this is something most CheckPoint representatives are so hesitant to come forward with.
The reason for asking about these kind of setups is that we have more customers willing to buy a unit for a rather simple setup, with say a 3200 or 5200 which includes a gateway+management license in one. But when they want to separate these, they suddenly have to pay for a, rather expensive, management server license.
That is a true statement that should be directed to the sales people only - i am glad to assist in technical questions or help with known bugs, but i have nothing to do with license bundling and pricing...
The same is true for me, but I was just trying to explain where this was coming from. ![]()
Aleksei for me spoke true words 😉 Full Managment HA out of my experience is not the stablest deployment - management sync alone made heavy headaches from time to time, and to have the active node together with the primary management is no good idea at all
.
I would rather go for SMS in a VM together with an appliance cluster...
As an addition, find here the most important SKs dealing with Full HA:
sk54160 How to Configure Management HA
sk60443 How to install Full HA cluster on Check Point appliances
sk93585_How to convert two Standalone machines into a Full-HA environment
sk104699 How to configure a Standalone machine to become a part of a Full HA cluster
sk39345 Management High Availability restrictions
sk39740 How to configure management HA when the Primary and Secondary management servers are on separate networks?
sk25164 SmartEvent / SmartReporter is not supported in High Availability environment
It is definitely possible. I've build this and noticed that especially the CPU is having a heavy load when using this configuration. Also keep in mind that rebooting a GW can take a long time because of the CPU load. The CPU load is spiking mainly when accessing the management console and accessing logging. My technical advice would also be to have a management server.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 17 | |
| 12 | |
| 11 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Thu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY