Do these steps before you start to define a Virtual Router (VRRP Group):
Step |
Description |
---|---|
1 |
Synchronize the system time on all Security Gateways to be included in this Virtual Router. Best Practice - We recommend that you enable NTP (Network Time Protocol) on all Security Gateways. You can also manually change the time and time zone on each Security Gateway to match the other members. |
2 |
Optional: Add host names and IP address pairs to the host table on each Security Gateway. This lets you use host names as an alternative to IP addresses or DNS servers. |
Best Practice - If you use the Spanning Tree protocol on Cisco switches connected to Check Point VRRP clusters, we recommend that you enable PortFast. PortFast sets interfaces to the Spanning Tree forwarding state, which prevents them from waiting for the standard forward-time interval.
If you use switches from a different vendor, we recommend that you use the equivalent feature for that vendor. If you use the Spanning Tree protocol without PortFast, or its equivalent, you may see delays during VRRP failover.
When you log into Gaia for the first time after installation, you must use the First Time Configuration Wizard to the initial configuration steps. To use VRRP, you must first enable VRRP clustering in the First Time Configuration Wizard.
To enable VRRP clustering:
Note - Perform this procedure for each VRRP Cluster Member.
Step |
Description |
---|---|
1 |
Install Gaia using the instructions in the R80.20 Installation and Upgrade Guide. |
2 |
On the First Time Configuration Wizard Products page, select Security Gateway. Do not select Security Management. The standalone environment (Security Gateway and Security Management Server) is not supported for VRRP. |
3 |
Select Unit is part of a cluster. |
4 |
Select VRRP Cluster from the list. |
5 |
Continue with the next steps in the wizard. |
6 |
When prompted to reboot the Security Gateway, click Cancel. Do not reboot. |
7 |
Do one of these steps:
|
8 |
Enter |
9 |
Reboot the Security Gateway. |
When you complete this procedure for each VRRP member, do these steps in the Gaia Portal:
Step |
Description |
---|---|
1 |
In the navigation tree, click High Availability > VRRP. |
2 |
Refer to the VRRP Global Settings section. |
3 |
If the Disable All Virtual Routers option is currently selected, clear it. |
4 |
Click Apply Global Settings. |
When you complete these procedures, define your Virtual Routers using the Gaia Portal or the Gaia Clish.
This section includes shows you how to configure the global settings. Global settings apply to all Virtual Routers.
Configure these VRRP global settings:
Step |
Description |
---|---|
1 |
In the navigation tree, click one of these:
|
2 |
In the VRRP Global Settings section:
|
3 |
Click Apply Global Settings. |
Configuration Notes:
Gaia starts to monitor the firewall after the cold start delay completes. This can cause some problems: