Hi, Looking to test this and make the secondary the primary manager, so would like to know if what I proposed and questioned would work,thanks
On Sun, 17 Jul 2011 19:50 BST Peter Addy wrote: >not sure i follow you ? > >>As long as the licences can be attached by the primary to the nodes and >>secondary, they will work fine. >are you saying that the firewall nodes also have to have the secondary manager >IPs > >>you can also try by shutting down the checkpoint process on the primary >>smartcenter (otherwise it would mean the firewall couldn't process any trafic >>if >>the smartcenter is unreachable or if you stop the process for an upgrade). > >Surely the firewalls will still proces traffic regardless of the manager being >down, obviously if this is not for a long period then it could affect vpn >traffic i'm i correct? > >So in Smartcenter HA are we saying all firewalls have to have the secondary >and >primary licenses attached, we just have primary attached to the firewall >modules, using central licensing > > > > >________________________________ >From: pkc mls <[email protected]> >To: [email protected] >Sent: Sun, 17 July, 2011 19:06:38 >Subject: Re: [FW-1] Checkpoint management licensing question > >Le 17/07/2011 18:41, Peter Addy a écrit : >> Hi, >> If we have a primary smartcenter and secondary smartcenter running in HA >> The firewall licenses are tied to to the pirmary manager, now if the primary >> manager is unreachable, we make secondary the primary and make changes on the >> secondary and push out, will this still be fine, will the firewalls and vpns >> fucnction as normal even though the license is tied to the primary, i assume >we >> do not need to install another license on the firewalls for the secondary >> manager? >> >As long as the licences can be attached by the primary to the nodes and >secondary, they will work fine. > >you can also try by shutting down the checkpoint process on the primary >smartcenter (otherwise it would mean the firewall couldn't process any trafic >if >the smartcenter is unreachable or if you stop the process for an upgrade). >> will this function of a length of time, and if so how log, the primary will >> be >> back on line but only after a couple of days? >I can assure it works. >> Thanks > > >Scanned by Check Point Total Security Gateway. > >================================================= >To set vacation, Out-Of-Office, or away messages, >send an email to [email protected] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[email protected] >================================================= > >Scanned by Check Point Total Security Gateway. Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
