Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

How many firewall nodes can you have in a Checkpoint CLUSTERXL enironment

Posted on 2014-12-04
1
473 Views
Last Modified: 2014-12-19
We currently have an Active/Standby Checkpoint Clusterxl Firewall setup in our main data facility.  We have two buildings and have recently built a secondary DR data center in the building.   We originally were just going to move the 2nd inactive firewall to the other building - (all interfaces are on vlans that are trunked between buildings.  so private, public, dmz, and heartbeat are all on seperate vlans available in both buildings.)

After some thought, moving the secondary firewall we will lose the resiliency in the primary site.  Assuming the vlans were up between the sites, this should be able to serve off the secondary firewall in the secondary site, but have since decided to purchase another firewall instead and add it to the clusterxl.

questions are:
1.  how many firewall appliances checkpoint 4600 running GAI can I put in a clusterxl environment?
2.  Can I set a priority or weight of what appliances should be elected as active if the heartbeat (sync channel fails).  My understanding is that if the sync channel fails.. the nodes determine which is to be active.   If the fiber goes dark between our buildings (our vlan trunk).  Both building would in essence think they are capable of running the active firewall.   If one building is destroyed, I need to have a mechanism for telling how to elect the active firewall.

any information, setup or config recommendations....
0
Comment
Question by:rdelrosario
1 Comment
 
LVL 12

Accepted Solution

by:
Fidelius earned 500 total points
ID: 40482517
Hello

1. If full state synchronization is used in Security Gateway, the recommended maximum number of nodes is 4 regardless of the clustering mechanism used.
Source: sk81300

2. From ( Cluster XL Admin Guide R77 page 20 ): In a High Availability cluster, each member is assigned a priority. The highest priority member serves as the Security Gateway in normal circumstances. If this member fails, control is passed to the next highest priority member. If that member fails, control is passed to the next member, and so on.

Also there is good explanation on page 10.

To set priority (page 25):  Member priorities correspond to the order in which they appear in the Cluster Members page of the Cluster Properties window. The top-most member has the highest priority. You can modify this ranking at any time.

Cluster priority
Regards!
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question