Dears,
I am in process of migrating[Not upgrading] Checkpoint firewall from One Data Center to Another Data Center. Source DC has Checkpoint where VRRP has been configured. I want to plan those CP firewalls to another DC with ClusterXL [VSX firewalls].
With my limited knowledge of VRRP, there should be VMAC on VRRP IP will be burn[If I am not wrong there should be some calculation to arrive VMAC] where that will be learned in downstream switch, and downstream servers will have that VIP as gateway. So the traffic flow hits the sw then fwd the packet to ACTIVE CP FW. Is my understanding correct?
On the other hand, in Cluster VSX all Cluster members will have the same IP address, [Note CLuster in HA mode] how MAC will learn how the server will reach out to ACTIVE cluster members. Admin guide document says Active member will do ARP response...
And How should I do this migration [VRRP IP to Cluster VSX] without changing the gateway at the server side?
should I create a virtual interface on VSX cluster[my target DC fw] with that VRRP IP address?