- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone,
I'm new to Checkpoint and I've been trying to learn how to set up for my customer.
Currently, I'm stuck in this place (Connection diagram as shown in the attached picture). I have configured HA for LAN on Lan3, synchronizing the firewall via Lan2. I don't HA the 2 WAN inputs of the 2 Checkpoints, but let them connect directly to the IPS via Metro (my customer using Metro Wan-MPLS Layer 2). Now if I drop the channel on FW1's WAN, will FW2 automatically switch from Standby to Active?
Can someone help me with the answer to this, please.
Actually, there's an SK that covers this exact scenario and the steps needed to achieve it: https://support.checkpoint.com/results/sk/sk181841
To the best of my knowledge, only interfaces that are involved in clustering can cause a failover.
Doesn't sound like the WAN is involved in clustering, which means I would expect this to not work.
However, you might want to open a TAC case and confirm: https://help.checkpoint.com
So if I have 2 transmission channels, with this checkpoint 1590 (There is no Router and SW WAN above the FW), is there any plan to HA those 2 transmission channels? These two transmission channels use 2 different IP layers from 2 different network providers.
Find all details for how to configure a SMB HA Cluster here: sk121096: How to configure a cluster between locally managed SMB appliances
ClusterXL (on non-SMB appliances) definitely has a requirement for the WAN interfaces being on a "shared" network.
That said, clustering is a little different on the SMB appliances, which is one of the reasons I suggested checking with TAC.
I will also check internally as well.
Actually, there's an SK that covers this exact scenario and the steps needed to achieve it: https://support.checkpoint.com/results/sk/sk181841
Is this locally or centrally managed, running R81.10.10 firmware?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY