- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Standalone Full HA deployment currently running 80.10 but soon to be upgraded to 80.30 before the gateways are deployed into Production.
Looking to find out how to configure the gateways to failover to the backup gateway if the following conditions occur:
1. WAN or LAN interface go down
2. If the WAN or LAN interface remain up but a switch or upstream/downstream device fails which effectively result in the gateway being able to access the internet or internal network; the gateway fails over to the backup
Thanks
Thanks for the response.
Can I just clarify where you said there is no tracking mechanism, that you're referring to both 80.10 and 80.30 and not just 80.10 which I'm running now?
My 2 cents regarding point 2: Any important up- or downstream device that is not directly connected to the firewall should itself be clustered. Also, since both nodes are connected to the same vlans, a failure further up- or downstream cant be solved by switching to the backup member.
In my experience distributed setups generally work better than standalone full HA deployments, have you consided migrating the management to a seperate server?
Edit: I've found a way to implement this using sk35780 and the clusterXL_monitor_ips script
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY