Solved

How many firewall nodes can you have in a Checkpoint CLUSTERXL enironment

Posted on 2014-12-04
1
531 Views
Last Modified: 2014-12-19
We currently have an Active/Standby Checkpoint Clusterxl Firewall setup in our main data facility.  We have two buildings and have recently built a secondary DR data center in the building.   We originally were just going to move the 2nd inactive firewall to the other building - (all interfaces are on vlans that are trunked between buildings.  so private, public, dmz, and heartbeat are all on seperate vlans available in both buildings.)

After some thought, moving the secondary firewall we will lose the resiliency in the primary site.  Assuming the vlans were up between the sites, this should be able to serve off the secondary firewall in the secondary site, but have since decided to purchase another firewall instead and add it to the clusterxl.

questions are:
1.  how many firewall appliances checkpoint 4600 running GAI can I put in a clusterxl environment?
2.  Can I set a priority or weight of what appliances should be elected as active if the heartbeat (sync channel fails).  My understanding is that if the sync channel fails.. the nodes determine which is to be active.   If the fiber goes dark between our buildings (our vlan trunk).  Both building would in essence think they are capable of running the active firewall.   If one building is destroyed, I need to have a mechanism for telling how to elect the active firewall.

any information, setup or config recommendations....
0
Comment
Question by:rdelrosario
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 12

Accepted Solution

by:
Fidelius earned 500 total points
ID: 40482517
Hello

1. If full state synchronization is used in Security Gateway, the recommended maximum number of nodes is 4 regardless of the clustering mechanism used.
Source: sk81300

2. From ( Cluster XL Admin Guide R77 page 20 ): In a High Availability cluster, each member is assigned a priority. The highest priority member serves as the Security Gateway in normal circumstances. If this member fails, control is passed to the next highest priority member. If that member fails, control is passed to the next member, and so on.

Also there is good explanation on page 10.

To set priority (page 25):  Member priorities correspond to the order in which they appear in the Cluster Members page of the Cluster Properties window. The top-most member has the highest priority. You can modify this ranking at any time.

Cluster priority
Regards!
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are times where you would like to have access to information that is only available from a different network. This network could be down the hall, or across country. If each of the network sites have access to the internet, you can create a ne…
Hello to you all, I hear of many people congratulate AWS (Amazon Web Services) on how easy it is to spin up and create new EC2 (Elastic Compute Cloud) instances, but then fail and struggle to connect to them using simple tools such as SSH (Secure…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question