- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello mates,
Question:
Is FULL HA Cluster supported on vmware? This sk60443 says yes. Installation a Upgrade guide R80.40 says only CP appliances, page 134.
We've updated sk60443 so it is clear this is only supported on physical Check Point appliances.
It is not supported on Open servers or virtualized appliances at all.
You did not read sk60443 correctly: These guidelines apply to all Check Point appliances running on Gaia OS / SecurePlatform OS, as well as Virtual Appliances running vSEC Virtual Edition on Gaia OS
(Note: this article does not apply to vSEC for Amazon Web Services, vSEC for Microsoft Azure, vSEC for Google Cloud Platform, vSEC for VMware NSX, vSEC for VMware vCloud Air, vSEC for Cisco ACI, vSEC for OpenStack).
Historically, this had never been supported on OpenServer at all, only on (also virtual) appliances.
But i would put my answer like this: On VMWare, Full HA Cluster does make no sense at all !
Which Admin Guide says differently ? The sk39345 (from 03-Okt-2019) says:
Additional restrictions for ClusterXL Full High Availability configuration:
Again: For me it makes no sense to have two small appliances with NPM licenses in Fool HA configuration - it turned to be a PITA much too often...
If HA is not available in the Virtual world what is recommended for virtual gateways running on ESX?
If we have two ESX servers with the gateway on one of them, if that ESX server blows up how are the services transitioned to the other ESX server?
HA is supported, what is not is FULL HA = Standalone HA cluster
Not sure what the difference is between HA and Full HA?
Do you mean that when there are two separate gateways, one on each ESX server, similar to there being two appliances in the physical world is supported?
Is there any documentation supporting this, I find documentation on private clouds for virtual appliances is a bit sparse.
FULL HA is two standalone instalation merged to cluster
Yeah that's a link to appliances, I will be running virtual servers, so CloudGuard IAAS virtual gateways.
Its easy on physical appliances, there is a wealth of documentation for that.
And we only support this on PHYSICAL Check Point appliances (not virtual ones).
I did not notice any flaming here, neither in mine nor someone elses posts, and at least my posts were about fool mgmt ha only 8) - can you please elaborate your last sentence ?
Martin,
we too had this requirements from one of our customers end of last year and answer from local Check Point team was "It's not supported with VMware" only CheckkPoint appliances.
Wolfgang
There are several ways to install a ClusterXL for R80.30 or R80.40:
Open Server and Appliance:
- sk144293 - Check Point R80.30 or sk160736 - Check Point R80.40
CloudGuard Virtual Edition (VE) OpenStack, KVM, ESXi
- sk158292 - CloudGuard for Private Cloud images
CloudGuard for VMware NSX
- sk114518: CloudGuard for NSX
More read here:
ClusterXL Installation - OpenServer, Appliance, OpenStack, KVM, ESXi, NSX, AWS, ACI, Azure, Google
Hi Martin
Where in the SK does it state that VMWare is supported for SA? Couldn't find such a statement - can you please point it out.
Thanks
Uri
the second sentence says:
These guidelines apply to all Check Point appliances running on Gaia OS / SecurePlatform OS,
as well as Virtual Appliances running vSEC Virtual Edition on Gaia OS
from how I understand its vSEC=CloudGuard=virtual appliance
Thanks Martin
I see - however vSEC is a different product and by definition does not support FULL HA, it is not VMWare ESX
Will ask the SK team to clarify
I am happy to say that based on this feedback sk60443 is now updated. Thanks for bringing this to our attention.
Quick question.
Is Active-Active Cluster XL FW supported in Full HA Setup in r80.40?
While Management Components still remain active/standby.
NO: See sk101539 - ClusterXL Load Sharing mode limitations and important notes !
We've updated sk60443 so it is clear this is only supported on physical Check Point appliances.
It is not supported on Open servers or virtualized appliances at all.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
6 | |
5 | |
4 | |
4 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY