- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
We're looking of changing from our HA passive-active setup to active active. Unsure if we will go multicast or unicast yet.
I've been looking for any documentation on changing modes, and what considerations we should have, but have not found any. lots of information is available for setting them up from scratch.
Anyone have any experience with doing this kind of change, or have any resources I can look at?
*Edit* - Meant to put this in the management board, not general topics. woops. Can we move the post?
I‘ve switched between HA and LS every now and then without experiencing any issues. Just schedule a maintenance timeframe, switch the ClusterXL mode, perform a policy installation, watch your cluster nodes in SmartView Monitor, do a reboot of the cluster nodes that don‘t change to the new state directly, check your network connections and update your documentation.
Alternative: Wait until R80.40 reaches GA and try the all new ClusterXL Active/Active mode.
David,
as @Danny @wrote it‘s no problem.
But If you want to run in multicast mode you have to check your switch/router environment.
As an example CISCO-routers need static ARP entries for your multicast-MACs, Nortel/Avaya-Switches needs some configuration to allow packets to multicast MACs......CISCO Nexus needs too configuration. There are a lot of sk articles regarding ClusterXL running in multicast mode.
I would prefer unicast mode, it’s not load balanced 50/50 but normally this works without the need of any changes on the attached switch/router environment.
Wolfgang
Hi Wolfgang, as noted we will have to take precautions with multicast mode. We are currently changing our core routers so this is the perfect time for us to consider multicast mode. The benefits seem slight, but may prove useful over unicast
More to ClusterXL read here:
Hi Heiko,
I love these kind of cheat sheets, thank you for providing!
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY