Print Download PDF Send Feedback

Previous

Next

Check Point Software Compatibility

ClusterXL Compatibility with IPS

The following IPS features are supported by ClusterXL, with the limitations listed in the notes.

IPS Feature

Load Sharing

High Availability

Fragment Sanity Check

Yes (1, 3)

Yes (1)

Pattern Matching

Yes (2, 3)

Yes (2)

Sequence Verifier

Yes (2, 4)

Yes (2)

FTP, HTTP and SMTP Security Servers

Yes (2, 5)

Yes (2)

Notes:

  1. If there is a cluster failover when fragments are being received, the packet will be lost.
  2. Does not survive cluster failover.
  3. Requires unidirectional stickiness. This means that the same Cluster Member must receive all external packets, and the same Cluster Member must receive all internal packets, but the same Cluster Member does not have to receive both internal and external packets.
  4. Requires bidirectional connection stickiness.
  5. Uses the cluster Forwarding Layer.

ClusterXL Compatibility (Excluding IPS)

The following table presents ClusterXL Load Sharing and High Availability compatibility. Some Check Point products and features are not supported, or are only partially supported for use with ClusterXL.

Feature or Product

Feature

LS

HA

Security Management

 

No

No

Security Gateway

 

Yes

Yes

Firewall

Authentication / Security Servers

Yes (1)

Yes (1)

Firewall

ACE servers and SecurID

Yes

Yes

Firewall

Application Intelligence protocol inspection (2)

Yes (3)

Yes

Firewall

Sequence Verifier

Yes (4)

Yes (1)

Firewall

UDP encapsulation

Yes

Yes

Firewall

Suspicious Activity Monitoring (SAM)

Yes

Yes

Firewall

ISP Redundancy

Yes

Yes

VPN

Third party VPN peers

Yes

Yes

Endpoint Security Client

Software Distribution Server (SDS)

No

No

Endpoint Security Client

IP per user in Office Mode

Yes

Yes

SecureXL

 

Yes

Yes

QoS

 

Yes (4, 5)

Yes

SmartProvisioning

SmartLSM Security Gateway

No

No

Notes:

  1. If there is a cluster failover when fragments are being received, the packet will be lost.
  2. Does not survive cluster failover.
  3. Requires unidirectional stickiness. This means that the same Cluster Member must receive all external packets, and the same Cluster Member must receive all internal packets, but the same Cluster Member does not have to receive both internal and external packets.
  4. Requires bidirectional connection stickiness.
  5. Uses the cluster Forwarding Layer.