Preparing a VRRP Cluster
Configuring Network Switches
![Closed](transparent.gif)
|
Best Practice - If you use the Spanning Tree protocol on Cisco switches connected to Check Point VRRP clusters, we recommend that you enable PortFast. It sets interfaces to the Spanning Tree forwarding state, which prevents them from waiting for the standard forward-time interval. |
If you use switches from a different vendor, we recommend that you use the equivalent feature for that vendor. If you use the Spanning Tree protocol without PortFast, or its equivalent, you may see delays during VRRP failover.
Preparing VRRP Cluster Members
![Closed](transparent.gif)
Step |
Instructions |
||
---|---|---|---|
1 |
Install the VRRP Cluster See the R81 Installation and Upgrade Guide > Chapter Installing a ClusterXL, VSX Cluster, VRRP Cluster > Section Installing a VRRP Cluster.. |
||
2 |
Synchronize the system time on the VRRP Cluster Members.
You can also manually change the time and time zone on each Security Gateway In this case, you must synchronize member times to within a few seconds. |
||
3 |
Optional: Add host names and IP address pairs to the host table on each Security Gateway (see Hosts). This lets you use host names as an alternative to IP addresses or DNS servers. |
||
4 |
Enable Virtual Routers:
|
||
5 |
Configure your Virtual Routers in either Gaia Portal, or Gaia Clish See: |
Configuring Global Settings for VRRP
This section shows you how to configure the global settings that apply to all Virtual Routers.
![Closed](transparent.gif)
Step |
Instructions |
||
---|---|---|---|
1 |
In the navigation tree, click one of these:
|
||
2 |
In the VRRP Global Settings section:
|
||
3 |
Click Apply Global Settings. |
![Closed](transparent.gif)
Gaia starts to monitor the Firewall after the cold start delay completes.
This can cause some problems:
-
If all the interfaces in a Virtual Router fail, all VRRP Cluster Members become VRRP Backups.
None of the VRRP Cluster Members can become the VRRP Master and no traffic is allowed.
-
If you change the time on any of the VRRP Cluster Members, a VRRP failover occurs automatically.
-
In certain situations, installing a policy causes a failover.
This can happen if it takes a long time to install the policy.