Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marko_Keca
Contributor

VRRP between VSs on different VSX clusters

Hello all,

Is it possible to use VRRP on Check Point between VSs on different VSX clusters?

Reason:

We have 2 datacenters. Each has its own VSX cluster, managed from different CMA. Behind Check Point is NSX stretched deployment, and NSX management VLAN is L3 terminated on one of VSs. We would like to use VRRP address for default gateway in NSX management, so if one cluster/DC fails, we will not lose management connectivity to other site, and other site will be able to communicate with witness server (on separate location).

So basically we don't want to use it as clustering method. We want only benefit of sharing Virtual IP between two separate VSs for default gateway.

 

Thanks in advance!

Regards
--
Marko

 

0 Kudos
5 Replies
Bob_Zimmerman
Authority
Authority

This is not possible.

Separately, spanning a layer 2 domain between datacenters is a really bad idea from an availability design perspective. Complicated low levels lead to problems which are extremely hard to debug at higher levels.

0 Kudos
PhoneBoy
Admin
Admin

VRRP is not supported on VSX.

0 Kudos
Marko_Keca
Contributor

Thank you all for the answers!

Would it be possible if we have two non-VSX clusters?

Regards,
--
Marko

0 Kudos
PhoneBoy
Admin
Admin

Gaia supports VRRP for non-VSX, but it's primarily tied to ClusterXL.
Not sure this will work the way you expect.
It's definitely not a good design, as @Bob_Zimmerman pointed out.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

For a list of supported features on VSX please refer sk79700

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events