- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi All,
We have a newly delivered(May 2022) 2x1600 Spark R80.20.35 appliances that have been configured as a cluster.
My colleague that did the configuration is long time on Check Point and I have no doubt that the configuration was done as usual - to work :).
After the configuration was done, we observed that the cluster members do not sync.
Have anyone encountered that recently?
If I should post more info about the issue, please let me know and I will anonymize mentioned configs and I will post it here - but I belive that this is not related to configs or ISP.
Best wishes,
Andrei
hey,
we need more details on what/how is configured, as if they don't sync then, do they report smth wrong in SmartConsole ?
(as I've seen they support ClusterXL)
Usually the 15K series I use have a SYNC interface that you set it as synchronization and is used specifically for that, but on 1600 I don't see that, so most likely you define some of the LAN ports to be used for sync.
Ty,
PS: from here
Configuring High AvailabilityIn the Device > High Availability page you can create a cluster of two appliances for high availability. Note - You cannot create a cluster when you have a switch or bridge defined in your network settings on the appliance. If necessary, change network settings in the Device > Local Network page. After you define a cluster, you can select to Enable or Disable the cluster. The page shows the configured interfaces for monitoring or high availability enabled in a table, where you can edit them. Interface options in cluster mode:
|
You cite from Locally Managed SMBs R80.20.20 manual but ask if they report smth wrong in SmartConsole - we should better know the deployment before guessing...
Concerning the Sync Port: Both 1600 + 1800 have port 2 named as sync, 1600 with 1GbE and 1800 with 2,5 GbE.
1600 SMB appliances HA cluster are much different to GAiA clusters - you only configure the active node in detail, and after selecting the second node in FTW as standby HA node, all config will be synchronized from active node. You did not write about it, but i assume you have a locally managed SMB cluster, so this applies: sk121096: How to configure a cluster between locally managed SMB appliances
Depending on the deployment scenario there is R80.20.40 available now with some clustering enhancements.
I would suggest to upgrade to R80.20.40 asap !
Centrally or locally managed SMBs ?
Locally managed.
Update:
1. We performed upgrade to R80.20.40 and the issue persisted.
2. We went back to R80.20.35 and recreated the cluster from scratch + adding specific policies to allow traffic between cluster members and the sync issue was solved. That specific policies where there from the first time, so that was not the issue.
I have no clue what was that. The procedure of setup was the same in both Cluster setup configurations...same order for steps.
As long as you do follow sk121096How to configure a cluster between locally managed SMB appliances sync should work. Afaik specific policies to allow traffic between cluster members are only needed in Strict Mode.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY