Check Point NG VPN-1/FireWall-1: Advanced Configuration and Troubleshooting

Solutions Fast Track

Designing Your Cluster

  • Consider carefully the two things that a cluster will give you: resilience and increased capacity. If you are going for resilience, this can determine the type of equipment you put in surrounding your cluster, because the emphasis will be on maintaining the services through the cluster rather than the throughput, so you could decide that you will buy equipment that will enable you to find the cluster more easily (for example, using hubs rather than switches).

  • Choose the operating system of the cluster modules carefully. They need to be the same platform and ideally the same specification. The Nokia platform has its own load-sharing solution, so you cannot use ClusterXL on it. Solaris and Windows and Linux do not have VRRP support with Check Point cluster on them.

  • Make sure that you consider carefully where you put your management station in relation to your cluster. Are you going to manage just one cluster, or do you think you will have to manage additional clusters (or firewalls) from the same management station?

  • Decide the type of address translation solution you will want to implement and stick to it. Some of the clustering solutions will not allow you to implement certain types of address translation solutions.

Installing FireWall-1 NG FP3

  • Do not forget the installation prerequisites. Especially make sure that the times between the cluster members and the firewall management station are the same.

  • Make sure that you have a license available to you before installing.

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Cluster Software and Tools
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.