Do these steps before you start to define a Virtual Router (VRRP Group):
Step |
Description |
---|---|
1 |
Synchronize the system time on all Security Gateways to be included in this Virtual Router. Best Practice - We recommend that you enable NTP (Network Time Protocol) on all Security Gateways. You can also manually change the time and time zone on each Security Gateway to match the other members. |
2 |
Optional: Add host names and IP address pairs to the host table on each Security Gateway. This lets you use host names as an alternative to IP addresses or DNS servers. |
Best Practice - If you use the Spanning Tree protocol on Cisco switches connected to Check Point VRRP clusters, we recommend that you enable PortFast. PortFast sets interfaces to the Spanning Tree forwarding state, which prevents them from waiting for the standard forward-time interval.
If you use switches from a different vendor, we recommend that you use the equivalent feature for that vendor. If you use the Spanning Tree protocol without PortFast, or its equivalent, you may see delays during VRRP failover.
When you log into Gaia for the first time after installation, you must use the First Time Configuration Wizard to the initial configuration steps. To use VRRP Virtual Routers (clusters), you must first enable VRRP clustering in the First Time Configuration Wizard.
To enable VRRP clustering:
cpconfig
on the Security Gateway. Select Enable cluster membership for this gateway
to enable Firewall synchronization.Note - This is the most common use and does not support active/active mode. You must configure VRRP so that the same cluster member is the VRRP master on all interfaces. Dynamic routing configuration must match on each cluster member.
OR:
Note - This is useful when each cluster member is required to be the VRRP master at the same time. You can configure two VRRP Virtual Routers on the same interface. Each cluster member can be the VRRP master for a different VRID on the same interface while it backs up the other. This configuration can also help run VRRP in a High-Availability pair with a device from another vendor. Disable the VRRP monitoring of the Firewall when you use this configuration. It is enabled by default but not supported with this configuration. Also, only Static Routes are supported with this configuration.
y
when prompted.Do this procedure for each Virtual Router member.
When you complete this procedure for each VRRP member, do these steps in the Gaia Portal:
When you complete these procedures, define your Virtual Routers using the Gaia Portal or the Gaia Clish.
This section includes shows you how to configure the global settings. Global settings apply to all Virtual Routers.
Configure these VRRP global settings:
Step |
Description |
---|---|
1 |
In the navigation tree, click one of these:
|
2 |
In the VRRP Global Settings section:
|
3 |
Click Apply Global Settings. |
Configuration Notes:
Gaia starts to monitor the firewall after the cold start delay completes. This can cause some problems:
This section includes the basic procedure for configuring a Virtual Router using the Gaia Portal.
To add a new Virtual Router:
Step |
Description |
---|---|
1 |
In the navigation tree, click High Availability > VRRP. |
2 |
Configure the VRRP Global Settings. |
3 |
In the Virtual Routers section, click Add. |
4 |
In the Add Virtual Router window, configure these parameters:
|
5 |
In the Backup Addresses section, click Add. Configure these parameters in the Add Backup Address window:
Click OK. The new VMAC mode shows in the in the Backup Address table. |
6 |
To remove a Backup Address, select an address and click Delete. The address is removed from the Backup Address table. |
7 |
Click Save. |
The Security Gateway Cluster Creation window opens
Source |
Destination |
VPN |
Services & |
Action |
Firewalls (Group) |
|
|
|
|
Where:
Alternatively, you can create a Network object to show all multicast network IP destinations with these values:
MCAST.NET
224.0.0.0
240.0.0.0
You can use one rule for all multicast protocols you agree to accept, as shown in this example:
Source |
Destination |
VPN |
Services & |
Action |
All Cluster |
fwcluster-object |
|
|
|
To learn more about maximizing network performance and redundancy, see: