Hi there, in this post, we're going to add a secondary management server, allowing us to have High Availability solution. The server will be deployed in the same subnet as the primary one and with the same hardware specifications, like disk size, memory and cpu.
During FTW (First Time Wizard), there are some options that we need to enable
In the next pages set the parameters according to your scenario.
Management Connection
Device Information
Date and Time Settings
In Installation Type choose Security Gateway and/or Security Management
Once the installation ends, we’ll add it in smart console.
Access the Gateways and Servers tab, in Gateways and Servers toolbar select New > More > Check Point Host
Fill the required information and activate Network Policy Management in the Management tab.
Establish SIC with the primary CMA by clicking in Communication button and providing the SIC key.
Press Ok and publish the changes.
Install the license file and make sure the new CMA (standby) has the same hotfixes installed has the primary one.
You can check this by accessing GAIA portal, in Upgrade (CPUSE) > Status and Actions
Now the standby server will be initialized and the database information synchronized with the primary server.
The synchronization status should complete successfully.
We can confirm high availability status by accessing Menu > High Availability
Hope you enjoyed this post, leave your comments below and I'll see you on the next post.
References:
https://sc1.checkpoint.com/documents/R80.40/SmartEndpoint_OLH/EN/Content/Topics-EPSG/Management-High-Availability.htm