- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- HA
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HA
Hi
am new to Checkpoint Firewall. Can any one assist me on this.
I have two Isp routers which are interconnected with two Checkpoint Firewall.
In this case; both WAN link implementations by HSRP Protocal are active / active and must be load-sharing mode only.
By the way, CPoint firewall have 2 gateways to the provider router [VIP1 (active to router1), VIP2 (active to router2)] and choose the gateway to the internet via VIP1 or VIP2.
And the solution would be as follows
- Router run hsrp (2 VIP gateway)
- firewall select gateway
- active/active links in load-sharing mode
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Read more here "ClusterXL R80.40 Administration Guide":
Introduction to ClusterXL^
Active-Active Mode in ClusterXL
Check Point ClusterXL aktive/aktive limitations:
vpn - not supported.
Threat Emulation - not supported.
