- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Geo Active-active Datacenter firewall architecture
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Geo Active-active Datacenter firewall architecture
Hi guys,
We are checkpoint costumer. Currently we have two VSX clusters in two geographic locations with production and disaster recovery site.
In near future we will change this to active-active architecture streching the network in both geographies using Cisco ACI with VxLAN.
Can you please advise us with the best scenario for firewall?
Do we need two clusters?
Can we have firewall instance in both geographies for the same networking "zone".
Regards,
Nuno
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are using a VSX Cluster with gateways at two locations, you must comply with the following ClusterXL parameters:
- maximum sync / CCP packet delay: 100 ms
- maximum sync / CCP packet lost: 0.2%
- Layer 2 connection between the locations
More read here:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nuno,
please note the requirements mentioned by Heiko.
If you can use VSLS ( Virtual System Load Sharing) with your VSX you can build a VSX cluster with 4 nodes, two in every location. With VSLS you can distribute your virtual system beetween all nodes. As an example you have 4 VS, you can run one VS on every node in your VSX-cluster.
VSLS can't be used if you are using a virtual-router in your environment.
best regards
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are using a VSX Cluster with gateways at two locations, you must comply with the following ClusterXL parameters:
- maximum sync / CCP packet delay: 100 ms
- maximum sync / CCP packet lost: 0.2%
- Layer 2 connection between the locations
More read here:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nuno,
please note the requirements mentioned by Heiko.
If you can use VSLS ( Virtual System Load Sharing) with your VSX you can build a VSX cluster with 4 nodes, two in every location. With VSLS you can distribute your virtual system beetween all nodes. As an example you have 4 VS, you can run one VS on every node in your VSX-cluster.
VSLS can't be used if you are using a virtual-router in your environment.
best regards
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content