- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear CheckMates,
I am a little bit confused.
In CP_R81.10_RemoteAccessVPN_AdminGuide.pdf it is discribed on page 75 in the section "IP Pool versus DHCP" to use different subnets for office mode IP ranges, when using a cluster.
Is this correct?
Do I need different office mode IP subnets for each cluster member?
Best regards,
Christian
There's been some similar discussion in the past: https://community.checkpoint.com/t5/Remote-Access-VPN/office-mode-network-clusterXL-HA-SSLVPN-networ...
Will request that we clarify the documentation some and report back here.
The pool should be configured for each cluster member:
Dear Chris,
Many thanks for your quick answer. Could you please clarify, must it be the same pool an both members or must it be different pools.
Best regards,
Christian
Hmm, I've often used the same IP pool for both cluster members (typically ClusterXL HA) without issue. Maybe I should pay closer attention to the documentation😁
You don't state whether you are worried about cluster members attempting to hand out the same IP to different clients, but I'm assuming that is a concern? Client VPN connections are synchronised between cluster members so that to me implies Office Mode leases are also synchronised (will test this in my lab to be sure).
I also used the same subnet for office mode on both members in the past - without any problems 😀 - but I was wondering about the sentense in thr RemoteAccess Guide...
There's been some similar discussion in the past: https://community.checkpoint.com/t5/Remote-Access-VPN/office-mode-network-clusterXL-HA-SSLVPN-networ...
Will request that we clarify the documentation some and report back here.
Yes, you should use the same. Think about it this way...say your master member c**** out and you can only use the other one. When users try to connect, they would not get proper IP address, which could cause connectivity issues.
Makes sense?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY