Configuring the Cluster Object and Members
Overview
You can use one of these procedures to define a cluster object and its members:
- - Lets you quickly create a new cluster and configure some basic cluster properties:
- Cluster properties and Virtual IP addresses
- Properties and Topology of Cluster Members
- Synchronization interfaces and IP addresses
- - Opens the window, where you manually create a cluster and configure its properties.
The window lets you:
- Manually create a new cluster
- Enable and configure Software Blades for the cluster
- Configure other cluster properties that you cannot configure with the wizards
- Change the properties of an existing cluster
Using the Wizard Mode
This version includes two wizards:
- Check Point Appliances and Open Servers
- Check Point Small Office Appliances
Wizard for Check Point Appliances or Open Servers
The is recommended for all Check Point Appliances (for example, 23800) except Small Office, and for Open Server platforms.
To create a new cluster using Wizard Mode:
- In SmartConsole, click menu.
- In window, click .
- In the window:
- In the field, enter unique name for the cluster object.
- In the , enter the unique Cluster Virtual IPv4 addresses for this cluster. This is the main IPv4 address of the cluster object.
- In the , enter the unique Cluster Virtual IPv6 addresses for this cluster. This is the main IPv6 address of the cluster object.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support pure IPv6 addresses.
- In the field, select the applicable option and click :
- In the window do these steps for each Cluster Member and click :
We assume you create a new cluster object from the scratch.
- Click to configure each Cluster Member.
- In the field, enter unique name for the Cluster Member object.
- In the , enter the unique Cluster Virtual IPv4 addresses for this Cluster Member. This is the main IPv4 address of the Cluster Member object.
- In the , enter the unique Cluster Virtual IPv6 addresses for this Cluster Member. This is the main IPv6 address of the Cluster Member object.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support pure IPv6 addresses.
- In the and fields, enter a one-time password that you entered in First Time Configuration Wizard during the installation of this Cluster Member.
- Click .
Management Server will try to establish SIC with each Cluster Member. The field should show .
- Click .
- In the window, define a network type (network role) for each cluster interface and define the Cluster Virtual IP addresses.
The wizard automatically calculates the subnet for each cluster network and assigns it to the applicable interface on each Cluster Member. The calculated subnet shows in the upper section of the window.
The available network objectives are:
Click .
- In the window, click .
After you complete the wizard, we recommend that you open the cluster object and complete the configuration:
- Define Anti-Spoofing properties for each interface
- Change the Topology settings for each interface, if necessary
- Define the Network Type
- Configure other Software Blades, features and properties as necessary
Wizard for Small Office Appliances
The wizard is recommended for these Centrally Managed Check Point appliances:
- 1100 appliances
- 1200R appliances
- 1400 appliances
To create a new Small Office cluster using Wizard Mode:
- In SmartConsole, click menu.
- In window, click .
- In the window:
- Enter a unique name for the cluster object.
- Select the correct hardware type.
- Click .
- In the window:
- Enter the member name and IPv4 addresses for each Cluster Member.
- Enter the one-time password for SIC trust.
- Click .
- Management Server will try to establish SIC with the Primary Cluster Member.
- In the page, configure the Cluster Virtual IPv4 address.
- Define the Cluster Virtual IPv4 addresses for the other cluster interfaces.
- Click ,and then to complete the wizard.
After you complete the wizard, we recommend that you open the cluster object and complete the configuration:
- Define Anti-Spoofing properties for each interface
- Change the Topology settings for each interface, if necessary
- Define the Network Type
- Configure other Software Blades, features and properties as necessary
Using the Manual Configuration
The window contains many different ClusterXL properties, as well as other properties related to Security Gateway and Software Blades functionality. This section includes only the properties and procedures directly related to ClusterXL.
Configuring General Properties
To configure the general properties of a cluster:
- In the field, enter a unique name for this cluster object.
- In the field, enter the unique Cluster Virtual IPv4 addresses for this cluster.
This is the main IPv4 address of the cluster object.
- In the field, enter the unique Cluster Virtual IPv6 addresses for this cluster.
This is the main IPv6 address of the cluster object.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support pure IPv6 addresses.
- In the field, select the correct hardware platform.
- In the field, select the correct Check Point version.
- In the field, select the correct operating system.
- Configure the desired cluster type:
- Enable other Network Security Software Blades as necessary.
Adding a New Cluster Member to the Cluster Object
To add a new Cluster Member to the Cluster object:
- In SmartConsole, open the cluster object.
- Go to the page.
- Click .
The window opens.
- Click the tab.
- In the field, enter a Cluster Member name.
- In the field, enter a physical IPv4 addresses.
The Management Server must be able to connect to the Cluster Member at this IPv4 address. This IPv4 address can be an internal, or external. You can use a dedicated management interface on the Cluster Member.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
- In the field, enter a physical IPv6 address, if you need to use IPv6.
The Management Server must be able to connect to the Cluster Member at this IPv6 address. This IPv6 address can be an internal, or external. You can use a dedicated management interface on the Cluster Member.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
- Click , and initialize Secure Internal Communication (SIC) trust.
Enter the same key you entered during First Time Configuration Wizard on each Cluster Member.
- Click the tab to configure the applicable NAT settings.
- Click the tab to configure the applicable VPN settings.
- Click .
Adding an Existing Security Gateway as a Cluster Member to the Cluster Object
To add an existing Security Gateway as a Cluster Member to the Cluster object:
Before doing these steps, we recommend exporting a complete management database with migrate export
command.
- In SmartConsole, open the cluster object.
- Go to the page.
- Click .
- Select a Security Gateway from the list and click .
- Read the warning is displayed and click :
If you add <Name_of_Security_Gateway_object> to the cluster, it will be converted to a cluster member.
Some settings will be lost.
The following settings will still remain:
-SIC
-VPN
-NAT (except for IP Pools)
In order to revert the conversion, session must be discarded.
Are you sure you want to continue?
|
- In the list of Cluster Members, select the new Cluster Member and click .
- Click the tab to configure the applicable NAT settings.
- Click the tab to configure the applicable VPN settings.
- Click .
Deleting a Cluster Member from Cluster Object
To delete an existing Cluster Member:
Before doing these steps, we recommend exporting a complete management database with migrate export
command.
- In SmartConsole, open the cluster object.
- Go to the page.
- Click .
- Click .
Important - This Cluster Member object will be deleted from the cluster object and from the management database.
Working with Cluster Topology
IPv6 Considerations
To activate IPv6 functionality for an interface, define an IPv6 address for the applicable interface on each Cluster Member and in the cluster object. All interfaces configured with an IPv6 address must also have a corresponding IPv4 address. If an interface does not require IPv6, only the IPv4 definition address is necessary.
Note - You must configure synchronization interfaces with IPv4 addresses only. This is because the synchronization mechanism works using IPv4 only. All IPv6 information and states are synchronized using this interface.
- In SmartConsole, open the cluster object.
- Go to page.
- Select a cluster interface and click .
- From the left navigation tree, click page:
- In the section, configure these settings for Cluster Virtual Interface:
The available network types (network objectives) are:
Network Type
|
Description
|
|
An interface that connects to an internal or external network.
|
|
A cluster interface that also works as a Synchronization interface.
We do not recommend this configuration because it adds the Delta Sync traffic to the interface.
|
|
An interface used exclusively for cluster state synchronization.
|
|
An interface that is not part of the cluster. ClusterXL does not monitor the state of this interface. As a result, there is no cluster failover if a fault occurs with this interface. This option is recommended for the management interface.
|
- - Virtual IPv4 address assigned to this Cluster Virtual Interface
- - Virtual IPv6 address assigned to this Cluster Virtual Interface
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
- In the section, click and configure these settings:
- Physical IPv4 address and Mask Length assigned to the applicable physical interface on each Cluster Member
- Physical IPv6 address and Mask Length assigned to the applicable physical interface on each Cluster Member
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
See also: Configuring Cluster Addresses on Different Subnets.
- In the section, click and configure these settings:
- - one of these: ,
- - one of these: , (
ExternalZone
, InternalZone
) - - whether to perform the Anti-Spoofing, and how to do it (
Detect
, Prevent
)
- From the left navigation tree, click page:
- In the section, configure these settings:
- - rate limit for inbound traffic
- - rate limit for outbound traffic
- In the section, configure the applicable classes.
- From the left navigation tree, click page:
- In the section, configure the applicable settings for dropping multicast packets
- In the section, configure the names of applicable interfaces
- Click .
Completing the Cluster Definition
- Configure other Software Blades and options in the cluster object as required (NAT, VPN, Remote Access, and other advanced options).
- Install the Access Control Policy on this cluster object.
Changing the Synchronization Interface
Important - Schedule a maintenance window, because changing the synchronization interface can impact the traffic.
To change the IPv4 address on the synchronization interface on Cluster Members:
- On each Cluster Member, change the IPv4 address on the Sync interface.
Use Gaia Portal, or Gaia Clish.
- In SmartConsole, open the cluster object.
- In the window, click page.
- Click.
- Make sure the settings are correct.
- Select the Sync interface and click .
- From the left navigation tree, click page.
- In the section, in the field, select .
- Click .
- In SmartConsole, install the Access Control Policy on this cluster object.
To change the synchronization interface on Cluster Members to a new interface:
- On each Cluster Member, configure a new interface that you will use as a new Sync interface.
Use Gaia Portal, or Gaia Clish.
- On each Cluster Member, delete the IPv4 address from the old Sync interface.
- Use Gaia Portal, or Gaia Clish.
- In SmartConsole, open the cluster object.
- In the window, click page.
- Click.
- Make sure the settings are correct.
- Right-click on the old Sync interface and click .
- Select the new interface and click .
- From the left navigation tree, click page.
- In the section, in the field, select .
- Click .
- In SmartConsole, install the Access Control Policy on this cluster object.