[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW-1] Stonebeat FullCluster an multiple external interfaces+VIP's
Michael, StoneBeat FullCluster supports multiple external or internal interfaces. >From FullCluster's point of view, the interfaces are simply either "operative" (meaning regular network traffic: DMZ, internal, external) or "protocol" (the heartbeat) or "control" (the one for the license, and to which the GUI should connect). The latter two can be combined on one interface as well. ---------------------------------------------------------------- Mark Boltz Stonesoft Corp. Product Manager, StoneGate Itälahdenkatu 22a [email protected] FIN-00210 Helsinki Tel: +358-9-4767 11 Finland Fax: +358-9-4767 1234 GSM: +358 40 763 5075 http://www.stonesoft.com "Enabling the secure, highly available enterprise." (SM) Michael Bryenton <[email protected]> To: [email protected] Sent by: Mailing list for discussion cc: of Firewall-1 Subject: [FW-1] Stonebeat FullCluster an multiple external <[email protected] interfaces + VIP's point.com> 02/03/2002 06:48 AM Please respond to Mailing list for discussion of Firewall-1 A question for all your guru's out there. Does Stonebeat support a Gateway Cluster object with more than one external IP? The setup I propose would see a pair of Checkpoint NG firewalls with 3 external and 7 internal interfaces. I want failover and load balancing for each of the interfaces - each interface has a different subnet. The 3 external all have a VIP's defined and six of the 7 internal interfaces have VIP's defined. Suppose A,B,C are the external interfaces and D,E,F,G,H,I,J are the internal interfaces. A would have VIP A_1 B would have VIP B_1 . . . I would have VIP I_1 and J would be the heartbeat network. How do I set this up with Stonebeat Fullcluster? All examples I see of Fullcluster show 1 external cluster IP joining to 1 external interface per firewall ... Is this all that it can do? Do I need 3 separate clusters to manage my 3 external subnets (so 6 firewalls in all)? Is there some routing that can get around this? And what about my internals subnets? Do I need 18 Clusters to handle this configuration of all subnets (36 firewalls)? Please advise. Thank you. Mike ================================================= To set vacation, Out Of Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
|