Check Point NG VPN-1/FireWall-1: Advanced Configuration and Troubleshooting

The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the concepts presented in this chapter and to assist you with real-life implementation of these concepts. To have your questions about this chapter answered by the author, browse to www.syngress.com/solutions and click on the Ask the Author form.
| 1. | Why should we seek to avoid asymmetric routing on a cluster? |
|
| 2. | Why is consistent hostname resolution so important when using clusters? |
|
| 3. | Can I manage multiple clusters from the same management station? Can they be at the same site? |
|
| 4. | I have configured earlier versions of ClusterXL and Check Point HA by editing files on the members. Is this still possible or required? |
|
| 5. | Which is the lower-cost option: Check Point ClusterXL or Nokia IPSO solutions? |
|
| 6. | Should I use Load-Sharing or HA mode ClusterXL? |
|
| 7. | Can I use the same interface for the Nokia cluster control and the Check Point state sync network ? |
|
| 8. | Can I configure the Nokia cluster or VRRP from the command line instead of using Voyager? |
|
| 9. | Will a traceroute through a Nokia cluster tell me which member in the cluster the traceroute session is going through? |
|
| 10. | When using Nokia VRRP or IPSO Clustering, why shouldn t I define the "Topology" in the FireWall-1 Gateway Cluster object ? |
|
| 11. | Why would I use VRRP when I could use Nokia clustering? |
|
| 12. | Is it possible to have multiple VRs on... |