A Cloning Group is a collection of Gaia Security Gateways that synchronize their OS configurations and settings for a number of shared features, for example DNS or ARP.
Cloning Groups are configured from the Security Gateway Portal.
To create a new Cloning Group:
Step |
Description |
---|---|
1 |
In your web browser, connect to the Gaia Portal on a Security Gateway. |
2 |
Click System Management > Cloning Group. |
3 |
Click Start Cloning Group Creation Wizard. The Cloning Group Creation Wizard opens. |
4 |
Select Create a new Cloning Group. The New Gaia Cloning Group window opens.
|
5 |
In the Shared Features screen, select features to clone to other members of the Cloning Group. Pay attention to the features you want to clone. For example, you might not want to clone static routes to Security Gateways that are members of a cluster. |
6 |
Click Next for the Wizard Summary and then click Finish. |
You can select any of these Shared Features:
Shared Feature |
Description |
---|---|
SNMP |
Configure SNMP. |
Banner Messages |
Configure banner messages. |
Job Scheduler |
Schedule automated tasks that perform actions at a specific time. |
DNS |
Configure DNS servers. |
ARP |
Configure static ARP entries and proxy ARP entries, control dynamic ARP entries. |
System Logging |
Configure system logging settings. |
Host Access Control |
Configure which hosts are allowed to connect to the cluster devices. |
Proxy Settings |
Configure proxy settings. |
Host Address Assignment |
Configure known hosts. |
NTP |
Configure Network Time Protocol for synchronizing the system's clock over a network. |
Password Policy |
Configure password and account policies. |
Time |
Configure the time and date of the system. |
Network Access |
Configure network access to Gaia. |
Display Format |
Configure how the system displays time, date and netmask. |
Mail Notification |
Configure email address, to which Gaia sends mail notifications. |
Inactivity timeout |
Configure session parameters, such as inactivity timeout. |
Users and Roles |
Configure users and roles settings. |
Static Routes |
Configure static routes. |
DHCP Relay |
Configure relay of DHCP and BOOTP messages between clients and servers on different IPv4 Networks. |
IPv6 DHCP Relay |
Configure relay of DHCPv6 messages between clients and servers on different IPv6 Networks. |
BGP |
Configure dynamic routing via the Border Gateway Protocol. |
IGMP |
Establish multicast group memberships via the Internet Group Management Protocol. |
PIM |
Configure Protocol-Independent Multicast. |
Static Multicast Routes |
Configure static multicast routes. |
RIP |
Configure IPv4 dynamic routing via the Routing Information Protocol. |
RIPng |
Configure IPv6 dynamic routing via the Routing Information Protocol. |
OSPF |
Configure IPv4 dynamic routing via the Open Shortest-Path First v2 protocol. |
IPv6 OSPF |
Configure IPv6 dynamic routing via the Open Shortest-Path First v3 protocol. |
Route Aggregation |
Create a supernet network from the combination of networks with a common routing prefix. |
Inbound Route Filters |
Configure Inbound Route Filters for RIP, OSPFv2, BGP, and OSPFv3 (supports IPv4 and IPv6). |
IP Reachability Detection |
Configure reachability detection of IP Addresses. |
Route Redistribution |
Configure advertisement of routing information from one protocol to another (supports IPv4 and IPv6). |
Route Map |
Configure dynamic routing route maps. |
Prefix Lists and Trees |
Configure dynamic routing prefix lists and trees. |
Routing Options |
Configure protocol ranks and trace (debug) options. |
Policy Based Routing |
Configure policy based routing (PBR) priority rules and action tables. |
Scheduled Backups |
Configure Gaia scheduled backups. |
To manage the Cloning Group:
Step |
Description |
---|---|
1 |
Sign out of the Gaia Portal. |
2 |
Sign in to the same Gaia Portal using the cadmin account and password. (Alternatively, log in to the Gaia Portal on the Security Gateway using the cadmin credentials.) Important - No unique URL or IP address is needed to access the Cloning Group Portal or Clish command line. Use the URL or IP address of the member Security Gateway. |
3 |
In System Management > Cloning Group, select features from the Shared Features. |
4 |
Click Set Shared Features. The shared features are propagated to all members of the group. If, for example, you then configure a primary DNS server on one member of the Cloning Group, and DNS is one of the Shared Features, then the DNS settings are propagated to all members of the group. The DNS settings in the Portal of each member are grayed out. |
A user that gets cloning group administration privileges (CloningGroupManagement RBA role), can manage specific Cloning Groups features granted by the administrator and grant Cloning Group capabilities to other users, including remote users. When these privileges are assigned, the Group Mode button shows in Portal.
To manage a Cloning Group as an assigned administrator:
Step |
Description |
---|---|
1 |
In your web browser, connect to the Gaia Portal on a Cloning Group member Security Gateway. |
2 |
At the top, click Group Mode. The Security Gateway switches to Cloning Group management mode. |
To join a Cloning Group:
Step |
Description |
---|---|
1 |
In your web browser, connect to the Gaia Portal on a Security Gateway. |
2 |
In System Management > Cloning Group, click Start Cloning Group Creation Wizard. The Cloning Group Wizard opens. |
3 |
Select Join an existing Cloning Group. |
4 |
The Join Existing Cloning Group window opens.
|
5 |
Click Finish. |
To create a Cloning Group that follows ClusterXL:
Select this option if the gateway is a member of a ClusterXL.
Note - If you select this option, you have to select it for all the members of the cluster.
Step |
Description |
---|---|
1 |
In your web browser, connect to the Gaia Portal on a Security Gateway. |
2 |
In System Management > Cloning Group, click Start Cloning Group Creation Wizard. The Cloning Group Creation Wizard opens. |
3 |
Select Cloning Group follows ClusterXL.
|
4 |
Click Next for the Wizard Summary and then click Finish. |
5 |
Repeat Steps 1-4 for all members of the cluster. |
Cloning Groups can also be managed in Gaia Clish. When run from the cadmin account, these commands apply to all members of the Gaia group.
You can create Cloning Groups in manual, or in ClusterXL mode.
To create the first Cloning Group member in Manual mode:
Step |
Description |
---|---|
1 |
Set the cloning group mode to |
2 |
Set the cloning group local IP address |
3 |
Set the cloning group password |
4 |
Set the cloning group state to |
5 |
Optional: Set a name for the Cloning Group |
To add other Security Gateways to the Cloning Group in Manual mode:
On each of those Security Gateways:
Step |
Description |
---|---|
1 |
Set the cloning group mode to |
2 |
Set the cloning group local IP address |
3 |
Set the cloning group password |
4 |
Run the |
To create Cloning Group members in ClusterXL mode:
On all member Security Gateways:
Step |
Description |
---|---|
1 |
Set the cloning group mode to |
2 |
Set the cloning group password |
3 |
Set the cloning group state to |
To create a Cloning Group:
|
Parameter |
Description |
---|---|
|
The IPv4 address used to synchronize shared features between members of the Cloning Group. |
|
The mode determines whether the Cloning Group is defined manually, or through ClusterXL. |
|
Name of the Cloning Group. |
|
Password for the administrator's (cadmin) account, used to access the Cloning Group configuration in the Gaia Portal, or Gaia Clish. When prompted, enter and confirm the password. |
|
Turns the Cloning Group feature on or off. |
To add Shared Features:
|
Parameter |
Description |
---|---|
<Feature> |
The name of the feature to be synchronized between the members of the Cloning Group. |
Where:
Name of Shared Feature |
Description |
---|---|
|
Configure route aggregation - create a supernet network from the combination of networks with a common routing prefix. |
|
Configure dynamic routing via the Border Gateway Protocol. |
|
Configure IPv4 DHCP Relay - relay of DHCP and BOOTP messages between clients and servers on different IPv4 Networks. |
|
Configure job scheduler - schedule automated tasks that perform actions at a specific time. |
|
Configure IPv6 DHCP Relay - relay of DHCPv6 messages between clients and servers on different IPv6 Networks. |
|
Configure DNS servers. |
|
Configure known hosts. |
|
Establish multicast group memberships via the Internet Group Management Protocol. |
|
Configure Inbound Route Filters for RIP, OSPFv2, BGP, and OSPFv3 (supports IPv4 and IPv6). |
|
Configure reachability detection of IP Addresses. |
|
Configure the time and date of the system. |
|
Configure Network Time Protocol (NTP) for synchronizing the system's clock over a network. |
|
Configure banner messages. |
|
Configure IPv4 dynamic routing via the Open Shortest-Path First v2 protocol. |
|
Configure IPv6 dynamic routing via the Open Shortest-Path First v3 protocol. |
|
Configure password and account policies. |
|
Configure email address, to which Gaia sends mail notifications. |
|
Configure how the system displays time, date and netmask. |
|
Configure session parameters, such as inactivity timeout. |
|
Configure network access to Gaia. |
|
Configure users and roles settings. |
|
Configure static ARP entries and proxy ARP entries, control dynamic ARP entries. |
|
Configure system logging settings. |
|
Configure proxy settings. |
|
Configure which hosts are allowed to connect to the cluster devices. |
|
Configure policy based routing (PBR) priority rules and action tables. |
|
Configure Protocol-Independent Multicast. |
|
Configure dynamic routing prefix lists and trees. |
|
Configure route redistribution - advertisement of routing information from one protocol to another (supports IPv4 and IPv6). |
|
Configure IPv4 dynamic routing via the Routing Information Protocol. |
|
Configure IPv6 dynamic routing via the Routing Information Protocol. |
|
Configure dynamic routing route maps. |
|
Configure protocol ranks and trace (debug) options. |
|
Configure static routes. |
|
Configure static multicast routes. |
|
Configure SNMP. |
|
Configure Gaia scheduled backups. |
To delete Shared Features:
|
Parameter |
Description |
---|---|
<Feature> |
The name of the feature to be deleted from the list of shared features. To see the list of the enabled Shared Features, enter:
|
To join a Cloning Group:
|
Parameter |
Description |
---|---|
<Cloning Group IPv4 address> |
The IPv4 address of the Cloning Group member, to which you join. Note - This option is not available if you are logged into the cadmin account. |
To remove a member from a Cloning Group:
|
To remove an inaccessible Cloning Group member:
|
Parameter |
Description |
---|---|
<IPv4 address of Member> |
The IPv4 address of the Cloning Group member that became inaccessible. |
Use this command only for troubleshooting purposes, when the remote Cloning Group member is not accessible. A normal way to remove a member from a Cloning Group is to run the
command on that member.leave cloning-group
Notes:
To view Cloning Group configuration:
|
Parameter |
Description |
---|---|
|
The IPv4 address used to synchronize shared features between the members of the Cloning Group. |
|
Shows the members of the Cloning Group. |
|
Shows the Cloning Group mode - |
|
Shows the name of the Cloning Group |
|
Lists the shared features that are enabled to be used by all members of the Cloning Group. |
|
Shows the Cloning Group state - enabled, or disabled. |
|
Shows the status of the Cloning Group member. Note - This option is not available if you are logged into the cadmin account. |
To re-synchronize a Cloning Group:
|
When a user (local or remote) receives Cloning Group management privileges, he can turn the Cloning Group management mode on, to create, delete, and edit Cloning Groups.
To turn on the Cloning Group management mode:
|
Parameter |
Description |
---|---|
|
Enables the Cloning Group management mode. |
|
Disables the Cloning Group management mode. |