The Cluster Gateway Properties window contains many different ClusterXL properties, as well as other properties related to Security Gateway and Software Blades functionality. This section includes only the properties and procedures directly related to ClusterXL.
Configuration Steps |
To configure the general properties of a cluster:
This is the main IPv4 address of the cluster object.
This is the main IPv6 address of the cluster object.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support pure IPv6 addresses.
Go to the ClusterXL and VRRP pane and configure the applicable settings.
Go to the 3rd Party Configuration pane and configure the applicable settings.
To add a new Cluster Member to the Cluster object:
The Cluster Members Properties window opens.
The Management Server must be able to connect to the Cluster Member at this IPv4 address. This IPv4 address can be an internal, or external. You can use a dedicated management interface on the Cluster Member.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
The Management Server must be able to connect to the Cluster Member at this IPv6 address. This IPv6 address can be an internal, or external. You can use a dedicated management interface on the Cluster Member.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
Enter the same key you entered during First Time Configuration Wizard on each Cluster Member.
To add an existing Security Gateway as a Cluster Member to the Cluster object:
Before doing these steps, we recommend exporting a complete management database with migrate export
command.
If you add <Name_of_Security_Gateway_object> to the cluster, it will be converted to a cluster member. Some settings will be lost. The following settings will still remain: -SIC -VPN -NAT (except for IP Pools) In order to revert the conversion, session must be discarded. Are you sure you want to continue? |
To delete an existing Cluster Member:
Before doing these steps, we recommend exporting a complete management database with migrate export
command.
Important - This Cluster Member object will be deleted from the cluster object and from the management database.
IPv6 Considerations
To activate IPv6 functionality for an interface, define an IPv6 address for the applicable interface on each Cluster Member and in the cluster object. All interfaces configured with an IPv6 address must also have a corresponding IPv4 address. If an interface does not require IPv6, only the IPv4 definition address is necessary.
Note - You must configure synchronization interfaces with IPv4 addresses only. This is because the synchronization mechanism works using IPv4 only. All IPv6 information and states are synchronized using this interface.
The available network types (network objectives) are:
Network Type |
Description |
---|---|
Cluster |
An interface that connects to an internal or external network. |
Cluster + Sync |
A cluster interface that also works as a Synchronization interface. We do not recommend this configuration because it adds the Delta Sync traffic to the interface. |
Sync |
An interface used exclusively for cluster state synchronization. |
Private |
An interface that is not part of the cluster. ClusterXL does not monitor the state of this interface. As a result, there is no cluster failover if a fault occurs with this interface. This option is recommended for the management interface. |
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
Important - You must define a corresponding IPv4 address for every IPv6 address. This release does not support the configuration of only IPv6 addresses.
See also: Configuring Cluster Addresses on Different Subnets.
ExternalZone
, InternalZone
)Detect
, Prevent
)Important - Schedule a maintenance window, because changing the synchronization interface can impact the traffic.
To change the IPv4 address on the synchronization interface on Cluster Members:
Use Gaia Portal, or Gaia Clish.
To change the synchronization interface on Cluster Members to a new interface:
Use Gaia Portal, or Gaia Clish.