Working with VSX Cluster Members
|
Important - This section does not apply to Scalable Platforms (Maestro and Chassis). |
This section presents procedures for adding and deleting VSX Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. Cluster
Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. Members.
Adding a New VSX Cluster Member
|
Important - Make sure that no other administrators are connected to the Management Server The " |
-
Install the new VSX Cluster Member
Security Gateway that is part of a cluster..
See the R81 Installation and Upgrade Guide.
-
Create a full backup of the environment (see sk100395).
-
Connect to the command line on the Management Server.
-
Log in the Expert mode.
-
Run this command and follow the on-screen instructions:
vsx_util add_member
-
Enter the IP address of the Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. or Main Domain Management Server.
-
Enter the Management Server administrator user name and password.
-
Follow the on-screen instructions.
-
-
Wait until the "add member operation finished successfully" message appears, indicating that the database has been successfully updated and saved.
Note - In a Multi-Domain Server
Dedicated Check Point server that runs Check Point software to host virtual Security Management Servers called Domain Management Servers. Synonym: Multi-Domain Security Management Server. Acronym: MDS. environment, this operation skips all Domain Management Servers locked by an administrator.
If this should occur, run the command again for the affected Domain Management Servers after they become available.
-
This prompt appears:
Do you wish to reconfigure the new VSX gateway/VSX cluster member
-
To reconfigure now (recommended), enter "
y
" and then:-
Wait until the "Reconfigure module operation completed successfully" summary notice appears.
-
Reboot the new VSX Cluster Member.
-
-
To reconfigure later, enter "
n
" and later follow these mandatory steps:-
Close all SmartConsole windows.
-
Connect to the command line on the Management Server.
-
Log in the Expert mode.
-
Run this command and follow the on-screen instruction:
vsx_util reconfigure
-
Wait until the Reconfigure module operation completed successfully summary notice appears.
Note - In a Multi-Domain Server environment, this operation skips all Domain Management Servers locked by an administrator.
If this should occur, run the command again for the affected Domain Management Servers after they become available.
-
Reboot the new VSX Cluster Member.
-
-
-
Connect to the command line on each VSX Cluster Member.
-
Examine the VSX Cluster configuration:
cphaprob state
-
If the VSX Cluster runs in the VSLS mode:
-
Connect to the command line on the Management Server.
-
Log in the Expert mode.
-
Redistribute Virtual Systems to the newly added VSX Cluster Member:
vsx_util vsls
-
Connect to the command line on each VSX Cluster Member.
-
Examine the VSX Cluster configuration:
cphaprob state
-
Deleting a VSX Cluster Member
|
Important - Make sure that no other administrators are connected to the Management Server before you perform this procedure. The |
-
Close all SmartConsole windows.
-
Create a full backup of the environment (see sk100395).
-
Detach the license from the VSX Cluster Member to be removed.
Otherwise, you cannot remove a VSX Cluster Member.
-
Close all SmartConsole windows.
-
Connect to the command line on the Management Server.
-
Log in the Expert mode.
-
Run this command and follow the on-screen instructions:
vsx_util remove_member
-
Enter the IP address of the Security Management Server or Main Domain Management Server.
-
Enter the Management Server administrator user name and password.
-
Enter "
y
" to confirm that you have detached the license from the VSX Cluster Member. -
Select the VSX Cluster.
-
Select the VSX Cluster Member.
-
Enter "
y
" to confirm that the VSX Cluster Member to be removed is disconnected.
-
-
Wait until the remove member operation finished successfully message appears.
Note - In a Multi-Domain Server environment, this operation skips all Domain Management Servers locked by an administrator.
If this should occur, run the command again for the affected Domain Management Servers after they become available.
The management database is now updated and saved.
-
Connect with SmartConsole to the Security Management Server or Main Domain Management Server that manages the VSX Cluster.
- From the left navigation panel, click Gateways & Servers.
-
Double-click the VSX Cluster object.
-
From the left tree, click Cluster Members.
-
Make sure you do not see an object representing the removed VSX Cluster Member.