- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi Team,
We have SMB firewalls in ACTIVE/ACTIVE mode. We need to change it to ACTIVE/STANDBY. May i know how we can change this? Does it require downtime at all?
Regards,
Sanjay S
SMB firewalls do have no active/active = load sharing mode at all - see sk178604: Check Point R81.10.X for 1500, 1600, and 1800 appliance Known Limitations and Resolved Iss... and refer to sk115868 !
Yes you should plan for downtime.
Refer below for locally managed:
Why do you suggest downtime although ClusterXL Loadsharing does not exist on SMBs ? Also the suggested link does not work - use https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Conf...
Did you review the guide and look at the changes required for a cluster?
Whilst we dont have enough information one or more devices require reconfiguration here.
Active/Active could also imply independent devices for some...
This depends all on the steps already done, but currently cluster XL can not be in load sharing mode...
We agree, the original post doesn't mention Cluster XL 🙂
@Sanjay_S Please clarify your existing configuration and appliance model.
Hi Chris,
The device model is Checkpoint 1550, R80.20.20.
Cluster Mode: High Availability (Active Up, Bridge Mode) with IGMP Membership
Both the devices are in ACTIVE/ACTIVE state.
Just want to change this to ACTIVE/STANDBY Mode.
I think it is pretty straight forward in the normal Gaia, just going into cpconfig and changing the cluster config. But not sure about this.
Just going through the SKs shared above.
Thanks @G_W_Albrecht @Chris_Atkinson
The guide provided won't apply to your current state.
You currently have an unsupported configuration (sk159772 / sk121096) so conversion without downtime cannot be guaranteed, least not without prior testing.
I would suggest to update to a newer firmware - R80.20.20 is outdated ! Is this SMB locally managed ? High Availability (Active Up, Bridge Mode) with IGMP Membership is OK. https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Conf...
SMB CLI has no cpconfig command, see Admin Guide, this is Embedded GAiA.
Can you please help me on a quick question here?
I can't find anywhere the configuration option for Active-Up or Primary-Up for a centrally managed SMB cluster (1600).
Where is it?? Is it possible to configure this? If not, what is the default mode??
Thing is that I have different behaviors on two different 1600 clusters...
One does switch to primary when it's up with (Member state has been changed after returning from ACTIVE/ACTIVE scenario (remote cluster member TESTFW1 has higher priority)
And the other 1600 cluster just stays on whichever member is active at any time..!!
So there must be a configuration option for this behavior somewhere... where is it???? 😛
Just follow the steps listed here:
With SMB GWs, you have an active node that is up all the time. When it fails, standby node comes up.
thanks,
I am not trying to configure new clusters here.
I am talking about existing clusters and specifically looking for the feature that is available for normal GAIA clusters:
Is something similar available for SMB??
If not, what is the default behavior upon recovery? does it switch to higher priority member or stays as is??
In GAiA, both nodes are configured, but with SMB, only the active node is ! The standby member is synced from the first, active node - also see Converting an Existing Quantum Spark Appliance to a Cluster. Afaik after failover it would switch to promary as active again if it is available.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
14 | |
3 | |
3 | |
2 | |
2 | |
1 | |
1 |
Wed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Thu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyWed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Thu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY