Do these steps before you start to define a Virtual Router (VRRP Group):
Step |
Description |
---|---|
1 |
Synchronize the system time on all Security Gateways to be included in this Virtual Router. Best Practice - We recommend that you enable NTP (Network Time Protocol) on all Security Gateways. You can also manually change the time and time zone on each Security Gateway to match the other members. |
2 |
Optional: Add host names and IP address pairs to the host table on each Security Gateway. This lets you use host names as an alternative to IP addresses or DNS servers. |
Best Practice - If you use the Spanning Tree protocol on Cisco switches connected to Check Point VRRP clusters, we recommend that you enable PortFast. PortFast sets interfaces to the Spanning Tree forwarding state, which prevents them from waiting for the standard forward-time interval.
If you use switches from a different vendor, we recommend that you use the equivalent feature for that vendor. If you use the Spanning Tree protocol without PortFast, or its equivalent, you may see delays during VRRP failover.
When you log into Gaia for the first time after installation, you must use the First Time Configuration Wizard to the initial configuration steps. To use VRRP Virtual Routers (clusters), you must first enable VRRP clustering in the First Time Configuration Wizard.
To enable VRRP clustering:
cpconfig
on the Security Gateway. Select Enable cluster membership for this
gateway
to enable State synchronization.Note - This is the most common use and does not support active/active mode. You must configure VRRP so that the same cluster member is the VRRP master on all interfaces. Dynamic routing configuration must match on each cluster member.
OR:
Note - This is useful when each cluster member is required to be the VRRP master at the same time. You can configure two VRRP Virtual Routers on the same interface. Each cluster member can be the VRRP master for a different VRID on the same interface while it backs up the other. This configuration can also help run VRRP in a High-Availability pair with a device from another vendor. Disable the VRRP monitoring of the Firewall when you use this configuration. It is enabled by default but, but not supported with this configuration. In addition, only Static Routes are supported with this configuration.
y
when prompted.Do this procedure for each Virtual Router member.
When you complete this procedure for each VRRP member, do these steps in the Gaia Portal:
When you complete these procedures, define your Virtual Routers using the Gaia Portal or the Gaia Clish.
This section includes shows you how to configure the global settings. Global settings apply to all Virtual Routers.
Configure these VRRP global settings:
Step |
Description |
---|---|
1 |
In the navigation tree, click one of these:
|
2 |
In the VRRP Global Settings section:
|
3 |
Click Apply Global Settings. |
Configuration Notes:
Gaia starts to monitor the firewall after the cold start delay completes. This can cause some problems: