Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
surajshinde
Contributor

New Check Point Manager implementation.

Dear Team,

We have purchased new VM based check point Manager to achieve CP management  server redundancy . Currently we have one CP Manager in production at one location (Mumbai City , in Maharashtra State) whereas we want to place or new CP Manager in another location(Chennai City, TamilNadu State).

How we can achieve this?

Current CP Manager manages around 20 GWs and connect with it ILL.

Please suggest best.

0 Kudos
11 Replies
Ruan_Kotze
Advisor

The management HA documentation would be a good starting point.

This video also gives a nice overview.

 

0 Kudos
surajshinde
Contributor

Thank you Ruan_Kotze,

Both CP Managers are different location and different subnet. 

0 Kudos
_Val_
Admin
Admin

It does not matter. Make sure the connectivity between them works, follow the documentation above.

0 Kudos
genisis__
Advisor

I would also add, ensure there is enough bandwidth and the latency not high.

0 Kudos
_Val_
Admin
Admin

Not critical, but nice to have.

0 Kudos
genisis__
Advisor

Agreed.

surajshinde
Contributor

Thank you All. It works fine. 

But one challenge i am facing, We have test failover and when primary Check Point Manager down in that case we need to manual Active secondary Check Point manager then it act with read/write permission. 

Once primary came UP in that case both act as Active-Active. Is there any way to do this automatic. 

0 Kudos
genisis__
Advisor

I think what you talking about is when you get a collision message, in this case you have to do a full sync manually  ie. from Secondary to Primary (assuming the secondary was made active, and you have actually made changes).

 

0 Kudos
surajshinde
Contributor

Is there any way to achieve  automatic switch the mode Active to standby and Standby to Active between both Manager.

0 Kudos
PhoneBoy
Admin
Admin

By design, failover for Management HA is designed to be a manual process.
It's not like ClusterXL where failover happens automatically.

0 Kudos
PhoneBoy
Admin
Admin

Worth noting a couple things: Management HA requires a second management license and  Management HA is no substitute for proper backups.
Provided you’ve taken appropriate backups, you can rebuild your management server if necessary.

See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
And: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos