- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
With ClusterXL HA (active/standby) RE: office mode network for SSLVPN (network extender mode) - Is it recommended to define one OM network for each member in the cluster (a seperate network for each member)? Or is it recommended/required to have one office mode network defined (the same one) and configured one each member? My guess is with HA, they'll be using one gw or the other so it's preferred to define the same network.
Only one OfficeMode (MAB?) subnet for the whole SSLVPN NetX VPN Users - no need to create multiply OM subnets really. I don't get your point how HA is relevant to this ... have you ever used HA in Active/Passive mode before?
You know what VMAC stands for? or VIP on each "clusterred" interface? You don't need to worry about multiply OM subnets. Just make one, add to the config. and off you go ![]()
Per case 6-0001647364
Only one OfficeMode (MAB?) subnet for the whole SSLVPN NetX VPN Users - no need to create multiply OM subnets really. I don't get your point how HA is relevant to this ... have you ever used HA in Active/Passive mode before?
You know what VMAC stands for? or VIP on each "clusterred" interface? You don't need to worry about multiply OM subnets. Just make one, add to the config. and off you go ![]()
Office Mode addresses can be allocated from an IP pool or by a DHCP server. If addresses are allocated from an IP pool, a separate IP pool must be defined for every cluster member. This prevents the allocation of the same IP address to different clients simultaneously.
I assume I route these to my INT-VIP IP, not the respective gws.
Per case 6-0001647364
If you are assigning Office Mode IPs from the Pool, it makes sense to split it in two and serve half from each cluster member in HA configuration.
The reason for this is that if one of the unit has leased the IP to the client and then the failover has occurred, no duplicate IPs will be leased.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY