Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
StackCap43382
Collaborator
Collaborator

VSX + VSLS Patching: Disaster Recovery when things go wrong?

In a situation where there is VSX CLuster (VSLS) and one of the members fail resulting in an RMA, what is the established process of introducing the replacement?

In normal ClusterXL HA cluster you just ISO/blink the RMA & restore from a backup/snapshot and push policy. Even with no backup its easy to restore with info from the other member/Cluster Object.

For VSX I might be overthinking it but VSX recovering from a snapshot seems over simplistic.

VSX Supports GAIA snapshots and as per sk98068 Snapshots can be placed onto the RMA as long as its the same Appliance:
https://support.checkpoint.com/results/sk/sk98068

So my question is for VSX+VSLS if a member fails can it just be recovered from the snapshot and policy pushed to it like a normal firewall or do we need to remove the old member and add the new member via vsx_util?
https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_VSX_AdminGuide/Topics-VSXG/W...

Given that the majority of the config is pushed from the manager, only the bonds and management interface needs to be configured prior to add a new member, either recovery option seems valid,

Regards.

 

EDIT:

How to back up and restore VSX gateway
https://support.checkpoint.com/results/sk/sk100395

"The only exception is if the configuration of the VSX Gateway / VSX cluster object was not changed since the backup file was collected from the Management Server."

SO if the GAIA SNAPSHOT was taken before the failure and the MGMT configuration was not changed then the snapshot is a valid method.

 

 

CCSME, CCTE, CCME, CCVS
0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events