- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: When will checkpoint support the Load Sharing ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When will checkpoint support the Load Sharing mode in either R80.20 and R80.30?
Dear Check Point Team,
Regarding the known issue with ClusterXL R80.20 and above does not support Load Sharing mode. Therefore, SmartConsole blocks such a configuration with a warning message.
I would like to know when it will be fixed and become to support like an R80.10.
Regards,
Sarm
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Scroll up in this checkmates post and see response from the R&D leader from October. The solution is available already part of GA jumbo's and you can read all about it in sk162637
Version | Take |
R80.20 | Jumbo HF take 117 and above |
R80.30 kernel 2.6.18/3.10 | Jumbo HF take 76 and above |
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Even with the correct version/JHF, you must apply the steps in sk162637 to enable the functionality in SmartConsole.
This includes the steps for enabling it on a specific SmartConsole installation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I once copied a passage from @PhoneBoy answer:
CUT>>>
Load Sharing has a few limitations, see:
- ClusterXL Load Sharing mode limitations and important notes
- Security features do not work in Asymmetric Routing scenario (which can come up in a Load Sharing scenario)
The amount of sync traffic required for ClusterXL Load Sharing significantly limits its scalability, particularly as you get into 3 and 4 node clusters.
It also reduces overall cluster resiliency in the case where one member fails, particularly if you are utilizing the load sharing cluster at or near capacity.
Given the above, I usually advocate for buying right-sized appliances for an HA configuration versus buying smaller appliances using load sharing.
And, in fact, this is what the vast majority of our customers do.
Maestro solves a lot of these limitations and improves scalability dramatically over ClusterXL Load Sharing.
<<<CUT
I also think Maestro is the future technology.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In r80.20 /.30 we introduced new limitation on load sharing with VPN (Due to maestro code main train unification, we took the maestro side and broken the main train side. Since the usage is low, it was the best tradeoff among the alternatives).
Due to the type of limitation, we decided to block the whole feature temporarily till we will make it clearer (so user can understand what is working). We are now in the process of enabling the large part of load sharing that does work, on r80.30. If you need this more urgently, contact our solution center to get assistance till we complete the publication of it (as its artificially blocked).
Load sharing with vpn is still blocked (this requires development) and we will bring it back but in future release (most cases i saw that did use load sharing, didnt need the vpn aspect so the above should cover the vast majority).
Dorit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You mean the Load sharing with vpn is still blocking or as whole Load sharing configuration.
Thank you in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
today: all load sharing is blocked except maestro
working to certify: enabling load sharing without vpn on R80.30 (can be done now if urgent contact us)
later after more development: load sharing with vpn
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Dorit,
Thank you for clarification.
However, can you estimate the time that the Load Sharing mode will be back in R80.20 and R80.30?
As I know if the customer wants to use this functionality they need to implement with R80.10, right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am quite implicit above: if you need non-vpn load sharing, you can get it now over r80.30 if you can contact us or wait to get it published publicly
If you need vpn load sharing, we still need to develop so it will be on later release
If you are not clear, i recommend you will work w our local sales to further understand
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Dorit,
I got it now. Thanks for clarification again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I link to the hyperlink you provided "It's been discussed here"
And found some comment from PhoneBoy, he said that checkpoint plan to bring it back later this year. Not sure if this true!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Please refer to sk162637 regarding the support of ClusterXL Load Sharing mode in R80.20 and above.
Regards,
Guy Elyashiv | Group Manager – Clustering & Multitenancy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the new and informative SK, is there some reason that the lifting of the ClusterXL Load Sharing restriction is not shown in the "list of resolved issues" for the R80.20 and R80.30 Jumbo HFA takes?
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Technically, load sharing vpn is still limited, ... so in order to avoid mistakes and the ui is technically still blocked (unless you open it).
Therefore you need to read the sk to open the ui and the release notes direct you to the sk
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have been waiting for a supported release that works with Cluster Load Sharing.
This is a major reason while we are evaluating other Firewall Solutions. I have been told many times by support that load sharing is not a recommended solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Scroll up in this checkmates post and see response from the R&D leader from October. The solution is available already part of GA jumbo's and you can read all about it in sk162637
Version | Take |
R80.20 | Jumbo HF take 117 and above |
R80.30 kernel 2.6.18/3.10 | Jumbo HF take 76 and above |
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It still doesn't solve the problem because it supports ClusterXL Load Sharing WITHOUT Ipsec VPN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Indeed
(1) Very small percentage used VPN w load sharing which is why we allowed this limitation in the first place
(2) This part (the VPN w load sharing) required more complicated resolution vs the Maestro / scalable platform VPN. Therefore we gave priority to integrating the high end into the maintrain at the cost of not supporting load sharing w VPN in the short term
(3) We have a function called solution center that helps us resolve such missing pieces when they impact the business, by driving formal commitment to complete certain functionality by a certain date (they will deliver a formal commitment). Please leverage your local sales team or contact @PhoneBoy off line to get assistance
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As mentionend before, you currently can use either VSX VSLS or Maestro to overcome this limitation !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As for support for Load Sharing + VPN, it is available in a customer release for R80.40.
Please engage your local Check Point office to obtain this release.
It's planned to include this functionality in a future release (after R81).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All,
It seems load sharing has been disabled and i have checked with R80.40, R81 and R81.10 with HFA installed
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Even with the correct version/JHF, you must apply the steps in sk162637 to enable the functionality in SmartConsole.
This includes the steps for enabling it on a specific SmartConsole installation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you follow all the instructions in the SK?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Chris,
FYI, we are using R80.4 with Take 173
1. Sticky already enabled.
Possible to advise what other steps are needed?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you already set the environment variable per sk162637 to get access to the configuration?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Also, steps below have been done.
- Edit the cpm.sh file:
- On a Security Management Server:
vi $FWDIR/scripts/cpm.sh - Go to the end of the file and find the last line:
exec $JAVA_HOME/bin/java ... - Above that last line add this new line:
export ENABLE_CLUSTER_LOAD_SHARING_R80_20=1
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What about the client side steps for SmartConsole?
