Checkpoint FW1 failover requirements?

Checkpoint FW1 failover requirements?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Checkpoint FW1 failover requirements? SJ 02-23-2005
Posted by SJ on February 23, 2005, 12:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,
We currently are running a Checkpoint NG firewall on a Solaris box with
an Enterprise license for unlimited users.

I am looking to set up another identical Solaris box running Checkpoint to
be a failover/standby when the first one would fail.
I am not looking for load balancing.

My question: Is this functionality built in to the NG firewall software
itself?
And would we have to pay for another ($20K) Enterprise licence to make this
happen?

If this scenario requires another Enterprise license to be purchased, it
would probably just make more sense to buy two Cisco PIXes in a
standby/failover configuration and save a bunch of money.

Any help or advice would be greatly appreciated. Thank you!




Posted by Thomas Marko on February 24, 2005, 8:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
SJ wrote:
> Hello,
> We currently are running a Checkpoint NG firewall on a Solaris box with
> an Enterprise license for unlimited users.
>
> I am looking to set up another identical Solaris box running Checkpoint to
> be a failover/standby when the first one would fail.
> I am not looking for load balancing.
>
> My question: Is this functionality built in to the NG firewall software
> itself?

Yes, there is a functionality in FW-1/VPN-1 which is called CPHA which
can do standby HA but can also do Load Balancing (depends on how many
coins you'll through into the slot ;-)

You can also realize HA using the protocol VRRP (builtin in Nokia and
Nortel Alteon Appliances, and ?).

> And would we have to pay for another ($20K) Enterprise licence to make this
> happen?

AFAIK you will need a license for the second module, but not for a
second management server. If you use CPHA you will have to purchase a
ClusterXL license.

> If this scenario requires another Enterprise license to be purchased, it
> would probably just make more sense to buy two Cisco PIXes in a
> standby/failover configuration and save a bunch of money.

Please do not compare a Check Point FW-1/VPN-1 with a Cisco PIX. Just
looking for the price when buying a firewall is IMHO the wrong way.

Cheers,
Thomas


Similar ThreadsPosted
Netscreen Failover question May 11, 2005, 11:37 pm
Cisco ASA 5500 WAN failover September 20, 2005, 7:49 am
Cisco VPN Failover setup May 1, 2006, 5:11 pm
Cisco Failover License problem August 4, 2004, 1:48 am
Failover mode on Arkoon Firewall March 8, 2005, 4:07 pm
Changing pix configs when failover is configured June 29, 2006, 10:28 am
Reccs for firewall upgrade- small business, 1 remote site, WAN failover- Fortigate vs. Netscreen vs. others? January 25, 2007, 3:46 pm
Checkpoint - Deny traceroute through checkpoint firewall August 10, 2004, 3:27 pm
Checkpoint - NAT Help February 7, 2005, 8:00 am
checkpoint March 17, 2005, 5:12 pm

The site map in XML format XML site map

Contact Us | Privacy Policy