- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Check Point Harmony
Highest Level of Security for Remote Users
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
Advanced Protection for
Small and Medium Business
Secure Endpoints from
the Sunburst Attack
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi All.
I have requested some function from customer about clusterXL monitoring interface.
ex)
There is a clusterXL environment > one External , two internal cluster group.
if one internal interface down on Active member, Active status dosen't have to take over to Standby machine.
It means ..this function is to disable cluster interface monitoring on specific interface?
( it's not a private interface)
Other vender like Fortinet or Juniper has this function to disable monitoring.
It's hard to understand your setup with two interfaces towards internal core. But the easiest would be to have a bond (port channel) and allow threshold of only one link required to be active for bond to be considered up.
If you are using trunk and VLANs, then you can select which VLAN's you want to monitor ClusterXL VLAN monitoring
Sorry for little confuse. Each interfaces have their own network like one external, one internal, one DMZ and each interfaces are configured cluster mode with virtual IP address.(not private mode)
but if there is function to disable cluster monitoring on a specific port. Even if some cluster interface going down on active member, cluster status has to keep Active-standby status without fail-over.
We used this file for VSX bond physical interfaces to tell cluster not to monitor them for failvers but I'm not 100% sure if it would work with regular gateways and interfaces
$FWDIR/conf/discntd.if
Someone from Checkpoint could confirm probably
Nevermore, see sk93306 ATRG: ClusterXL :
30 Mar 2015 |
|
we still don't know what SW these GWs are running so might work hah
Yes, e.g. for R75.40...
Thank you for reply. I tested what you say. but It didn't work properly. because my environment is normal clusterXL not VSX.
Then you probably will have to make interface private in order to disable cluster monitoring
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY