Cluster IP Addresses on Different Subnets
You can configure cluster Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. Virtual IP addresses in different subnets than the physical IP addresses of the Cluster Members.
The network "sees" the cluster as one Security Gateway Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. that operates as a network router. The network is not aware of the internal cluster structure and physical IP addresses of Cluster Members.
Advantages of using different subnets:
-
You can create a cluster in an existing subnet that has a shortage of available IP addresses.
-
You use only one Virtual IP address for the cluster. All other IP addresses can be on other subnets.
-
You can "hide" physical Cluster Members' IP addresses behind the cluster Virtual IP address. This security practice is almost the same as NAT.
Traffic sent from Cluster Members to internal or external networks is hidden behind the cluster Virtual IP addresses and cluster MAC addresses. The cluster MAC address assigned to cluster interfaces is:
Cluster Mode |
MAC Address |
---|---|
MAC address of the Active |
|
Multicast MAC address of the cluster Virtual IP Address |
|
Load Sharing Unicast |
MAC address of the Pivot |
The use of different subnets with cluster objects has some limitations - see Limitations of Cluster Addresses on Different Subnets.
Configuration:
Follow the steps in Example of Cluster IP Addresses on Different Subnets.