1. yes
2. depends on the version of ipso, in ipso 3.8 you have an option to monitor 
the fwd process under the vrrp settings, careful with 3.8 it has its own r-55 
build.
3. with ha only you do not need the clusterxl license, however you will need an 
additional FW lic for the failover box.

-GS

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] Behalf Of
Stachowicz,Mark
Sent: Wednesday, December 08, 2004 10:37 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] FW: [FW-1] High Availability and Nokia IPSO
Clustering


Thanks for the info.

So you are saying if I enable clustering on Nokia IPSO,  that will give
me state sync if the hardware fails and the VRRP fails over to the other
Nokia device?

That is fine if the HW fails, however if something happens to the CP
software,  that doesn't help me, right?

If I just want to do high availability with CP,  can I just purchase the
VPN-1 Pro HA license or do I need to get ClusterXL as well?   I don't
need load sharing.

Sorry for all the questions,  I just really want to get an understanding
of this.

Thanks again. -ms



-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Will
Zegeer
Sent: Wednesday, December 08, 2004 9:37 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] FW: [FW-1] High Availability and Nokia IPSO Clustering

Yes, You need an additional license for either load sharing or HA for
Cluster XL. Cluster XL is enabled for Nokia as well but you don't need a
license for it. With Nokia, Cluster XL is enabled for State Sync only.

-Will

        -----Original Message-----
        From: Stachowicz,Mark [mailto:[EMAIL PROTECTED]
        Sent: Tue 12/7/2004 10:15 AM
        To: [EMAIL PROTECTED]
        Cc:
        Subject: Re: [FW-1] High Availability and Nokia IPSO Clustering



        If I didn't want to do load sharing,  only automatic failover,
would I
        still need ClusterXL?  I currently have VPN-1 Pro gateway
licenses on my
        Nokias,  I assume that for auto failover capabilities I would
need to
        replace those licenses with the "Additional VPN-1 Pro Gateways
for Load
        Sharing and High Availability" licenses?  Or are these licenses
an
        add-on to the VPN-1 Pro license I have now?

        I've tried turning on HA with my current licenses and it does
activate,
        however if I attempt to check status,  it returns an error
saying the HA
        module is not installed.   This is why I think I need the
license for
        HA.

        Thanks!

        -ms

        -----Original Message-----
        From: Mailing list for discussion of Firewall-1
        [mailto:[EMAIL PROTECTED] On Behalf Of
Will
        Zegeer
        Sent: Tuesday, December 07, 2004 8:05 AM
        To: [EMAIL PROTECTED]
        Subject: Re: [FW-1] High Availability and Nokia IPSO Clustering

        CP Cluster XL licenses - either HA or Loadsharing. When NG first
came
        out (and in the 4.1/4.0 days), it was very cumbersome and didn't
work
        well. But now, Post R54 releases work very well and it's very
easy to
        set up. I suggest Secureplatform with cluster xl and read the
cluster xl
        pdf.

        -Will

                -----Original Message-----
                From: Stachowicz,Mark
[mailto:[EMAIL PROTECTED]
                Sent: Mon 12/6/2004 11:25 PM
                To: [EMAIL PROTECTED]
                Cc:
                Subject: [FW-1] High Availability and Nokia IPSO
Clustering



                I have two Nokia 710 gateways running IPSO 3.7 and
Checkpoint
        NG-AI R54
                (FW-1/VPN-1 Pro).   I also have a Solaris 2.8 management
station
        that
                manages both firewalls.

                I only have Nokia VRRP running now to failover the
firewalls in
        the
                event of a failure,  however this will only work in the
event of
        a
                hardware failure.  This does not help if the master
firewall
        software
                stops working or the policy fails.

                What are my options for high availability with my
Checkpoint
        firewalls
                to ensure that I always have a failover?

                Can you also provide licenses that I would need to
purchase?

                Thanks very much in advance..

                -mark stachowicz


                =================================================
                To set vacation, Out-Of-Office, or away messages,
                send an email to [EMAIL PROTECTED]
                in the BODY of the email add:
                set fw-1-mailinglist nomail
                =================================================
                To unsubscribe from this mailing list,
                please see the instructions at
                http://www.checkpoint.com/services/mailing.html
<https://65.242.83.79/http/0/www.checkpoint.com/services/mailing.html>

<https://65.242.83.79/http/0/www.checkpoint.com/services/mailing.html>
                =================================================
                If you have any questions on how to change your
                subscription options, email
                [EMAIL PROTECTED]
                =================================================


        =================================================
        To set vacation, Out-Of-Office, or away messages,
        send an email to [EMAIL PROTECTED]
        in the BODY of the email add:
        set fw-1-mailinglist nomail
        =================================================
        To unsubscribe from this mailing list,
        please see the instructions at
        http://www.checkpoint.com/services/mailing.html
<https://65.242.83.79/http/0/www.checkpoint.com/services/mailing.html>
        =================================================
        If you have any questions on how to change your
        subscription options, email
        [EMAIL PROTECTED]
        =================================================


=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options,
email [EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to