Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nenad_Odic
Contributor

mgmt ports and main Cluster VIP

Dear all ,

i have two appliances 3970 and i have them physically connected to vlan200 with their addresses so call it MGMT vlan200 ,my SMS machine is also in the same vlan but as a VM  on hyperv SET switch with vlan200 so they can  se each other and i can configure them etc.

So my question is if i create a cluster what should be my main cluster IP should i put ip adress from mgmt vlan or to put some of data vlans .

like i have bond that trunks all internal and mgmt  vlans from the switch  to a active/backup bond at checkpoint gateways.

so i have like bond1.10 20 40 50 60 200 vlan interfaces on that bond.every vlan interface is  10.vlannumber.0. 253 252 with vip 254

what will be if i have mgmt addreses for gateways and main cluster vip in like 10.10.0.254 .

it looks like in attach

thanks

0 Kudos
3 Replies
Vincent_Bacher

You should use the management VLAN IPs for management only, not as a general “main” cluster IP.

 

For traffic, each VLAN should have its own cluster VIP (as you already planned, e.g. 10.x.0.254 per VLAN).

 

If you are using VPN, it’s best to use the external/public IP (or the NATed external VIP) as the VPN endpoint. This simplifies routing, NAT, troubleshooting, and interoperability with peers.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Having MGMT as a non cluster interface has its benefits.

CCSM R77/R80/ELITE
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey brother,

So sorry I forgot to respond to you yesterday via direct message, but I assume its related to discussion we had? If so, what Vince said makes sense.

Best,
Andy
0 Kudos
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events