Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
surajshinde
Contributor

New Check Point Manager implementation.

Dear Team,

We have purchased new VM based check point Manager to achieve CP management  server redundancy . Currently we have one CP Manager in production at one location (Mumbai City , in Maharashtra State) whereas we want to place or new CP Manager in another location(Chennai City, TamilNadu State).

How we can achieve this?

Current CP Manager manages around 20 GWs and connect with it ILL.

Please suggest best.

11 Replies
Ruan_Kotze
Advisor

The management HA documentation would be a good starting point.

This video also gives a nice overview.

 

surajshinde
Contributor

Thank you Ruan_Kotze,

Both CP Managers are different location and different subnet. 

_Val_
Admin
Admin

It does not matter. Make sure the connectivity between them works, follow the documentation above.

genisis__
Mentor Mentor
Mentor

I would also add, ensure there is enough bandwidth and the latency not high.

_Val_
Admin
Admin

Not critical, but nice to have.

surajshinde
Contributor

Thank you All. It works fine. 

But one challenge i am facing, We have test failover and when primary Check Point Manager down in that case we need to manual Active secondary Check Point manager then it act with read/write permission. 

Once primary came UP in that case both act as Active-Active. Is there any way to do this automatic. 

genisis__
Mentor Mentor
Mentor

I think what you talking about is when you get a collision message, in this case you have to do a full sync manually  ie. from Secondary to Primary (assuming the secondary was made active, and you have actually made changes).

 

surajshinde
Contributor

Is there any way to achieve  automatic switch the mode Active to standby and Standby to Active between both Manager.

PhoneBoy
Admin
Admin

By design, failover for Management HA is designed to be a manual process.
It's not like ClusterXL where failover happens automatically.

PhoneBoy
Admin
Admin

Worth noting a couple things: Management HA requires a second management license and  Management HA is no substitute for proper backups.
Provided you’ve taken appropriate backups, you can rebuild your management server if necessary.

See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
And: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events