Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

How many firewall nodes can you have in a Checkpoint CLUSTERXL enironment

Posted on 2014-12-04
1
Medium Priority
?
653 Views
Last Modified: 2014-12-19
We currently have an Active/Standby Checkpoint Clusterxl Firewall setup in our main data facility.  We have two buildings and have recently built a secondary DR data center in the building.   We originally were just going to move the 2nd inactive firewall to the other building - (all interfaces are on vlans that are trunked between buildings.  so private, public, dmz, and heartbeat are all on seperate vlans available in both buildings.)

After some thought, moving the secondary firewall we will lose the resiliency in the primary site.  Assuming the vlans were up between the sites, this should be able to serve off the secondary firewall in the secondary site, but have since decided to purchase another firewall instead and add it to the clusterxl.

questions are:
1.  how many firewall appliances checkpoint 4600 running GAI can I put in a clusterxl environment?
2.  Can I set a priority or weight of what appliances should be elected as active if the heartbeat (sync channel fails).  My understanding is that if the sync channel fails.. the nodes determine which is to be active.   If the fiber goes dark between our buildings (our vlan trunk).  Both building would in essence think they are capable of running the active firewall.   If one building is destroyed, I need to have a mechanism for telling how to elect the active firewall.

any information, setup or config recommendations....
0
Comment
Question by:rdelrosario
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 12

Accepted Solution

by:
Fidelius earned 2000 total points
ID: 40482517
Hello

1. If full state synchronization is used in Security Gateway, the recommended maximum number of nodes is 4 regardless of the clustering mechanism used.
Source: sk81300

2. From ( Cluster XL Admin Guide R77 page 20 ): In a High Availability cluster, each member is assigned a priority. The highest priority member serves as the Security Gateway in normal circumstances. If this member fails, control is passed to the next highest priority member. If that member fails, control is passed to the next member, and so on.

Also there is good explanation on page 10.

To set priority (page 25):  Member priorities correspond to the order in which they appear in the Cluster Members page of the Cluster Properties window. The top-most member has the highest priority. You can modify this ranking at any time.

Cluster priority
Regards!
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question