Configuring Cloning Groups in Gaia Clish
|
Note - When run from the cadmin account, these commands apply to all members of the Gaia Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. group. |
|
Important - After you add, configure, or delete features, run the " |
Cloning Group Modes
You can create Cloning Groups in either Manual mode, or ClusterXL mode.
Step |
Instructions |
---|---|
1 |
Set the cloning group mode to |
2 |
Set the cloning group local IP address. |
3 |
Set the cloning group password. |
4 |
Set the cloning group state to |
5 |
Optional: Set a name for the Cloning Group. |
Perform these steps on each of the Security Gateways.
Step |
Instructions |
---|---|
1 |
Set the cloning group mode to |
2 |
Set the cloning group local IP address. |
3 |
Set the cloning group password. |
4 |
Run the " |
Perform these steps on all member Security Gateways.
Step |
Instructions |
---|---|
1 |
Set the cloning group mode to |
2 |
Set the cloning group password. |
3 |
Set the cloning group state to |
CLI Syntax
Syntax
|
Parameters
Parameter |
Description |
||
---|---|---|---|
|
The IPv4 address used to synchronize shared features between members of the Cloning Group. |
||
|
The mode determines whether the Cloning Group is defined manually, or through ClusterXL. |
||
|
Name of the Cloning Group. |
||
|
Password for the administrator's (cadmin) account, used to access the Cloning Group configuration in the Gaia Portal Web interface for the Check Point Gaia operating system., or Gaia Clish The name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell).. When prompted, enter and confirm the password. |
||
|
Enables (
|
Syntax
|
Parameters
Parameter |
Description |
---|---|
|
The name of the feature to be synchronized between the members of the Cloning Group. |
The features are listed in the same order, in which they are shown in Gaia Clish when you run the "show cloning-group shared-feature
" command.
Name of Shared Feature |
Description |
---|---|
|
Configure route aggregation - create a supernet network from the combination of networks with a common routing prefix. |
|
Configure dynamic routing via the Border Gateway Protocol. |
|
Configure IPv4 DHCP Relay - relay of DHCP and BOOTP messages between clients and servers on different IPv4 Networks. |
|
Configure job scheduler - schedule automated tasks that perform actions at a specific time. |
|
Configure IPv6 DHCP Relay - relay of DHCPv6 messages between clients and servers on different IPv6 Networks. |
|
Configure DNS servers. |
|
Configure known hosts. |
|
Establish multicast group memberships via the Internet Group Management Protocol. |
|
Configure Inbound Route Filters for RIP, OSPFv2, BGP, and OSPFv3 (supports IPv4 and IPv6). |
|
Configure reachability detection of IP Addresses. |
|
Configure the time and date of the system. |
|
Configure Network Time Protocol (NTP) for synchronizing the system's clock over a network. |
|
Configure banner messages. |
|
Configure IPv4 dynamic routing via the Open Shortest-Path First v2 protocol. |
|
Configure IPv6 dynamic routing via the Open Shortest-Path First v3 protocol. |
|
Configure password and account policies. |
|
Configure email address, to which Gaia sends mail notifications. |
|
Configure how the system displays time, date and netmask. |
|
Configure session parameters, such as inactivity timeout. |
|
Configure network access to Gaia. |
|
Configure users and roles settings. |
|
Configure static ARP entries and proxy ARP entries, control dynamic ARP entries. |
|
Configure system logging settings. |
|
Configure proxy settings. |
|
Configure which hosts are allowed to connect to the cluster Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. devices. |
|
Configure policy based routing (PBR) priority rules and action tables. |
|
Configure Protocol-Independent Multicast. |
|
Configure dynamic routing prefix lists and trees. |
|
Configure route redistribution - advertisement of routing information from one protocol to another (supports IPv4 and IPv6). |
|
Configure IPv4 dynamic routing via the Routing Information Protocol. |
|
Configure IPv6 dynamic routing via the Routing Information Protocol. |
|
Configure dynamic routing route maps. |
|
Configure protocol ranks and trace (debug) options. |
|
Configure static routes. |
|
Configure static multicast routes. |
|
Configure SNMP. |
|
Configure Gaia scheduled backups. |
Syntax
|
Parameters
Parameter |
Description |
|
---|---|---|
|
The name of the feature to be deleted from the list of shared features. To see the list of the enabled Shared Features:
|
Syntax
|
Parameters
Parameter |
Description |
||
---|---|---|---|
|
The IPv4 address of the Cloning Group member, to which you join.
|
|
Syntax
|
Parameters
Parameter |
Description |
---|---|
|
The IPv4 address of the Cloning Group member that became inaccessible. |
|
Important - Use this command only for troubleshooting purposes, when the remote Cloning Group member is not accessible. A normal way to remove a member from a Cloning Group is to run the " |
|
Notes:
|
Syntax
|
Parameters
Parameter |
Description |
||
---|---|---|---|
|
The IPv4 address used to synchronize shared features between the members of the Cloning Group. |
||
|
Shows the members of the Cloning Group. |
||
|
Shows the Cloning Group mode - |
||
|
Shows the name of the Cloning Group |
||
|
Lists the shared features that are enabled to be used by all members of the Cloning Group. |
||
|
Shows the Cloning Group state - enabled, or disabled. |
||
|
Shows the status of the Cloning Group member.
|
|
When a user (local or remote) receives Cloning Group management privileges, the user can enable (or disable) the Cloning Group management mode, to create, delete, and edit Cloning Groups.
Syntax
|
Parameters
Parameter |
Description |
---|---|
|
Enables the Cloning Group management mode. |
|
Disables the Cloning Group management mode. |