Firewall-1

Re: [FW-1] State Sync does not supports VLAN ?

Subject: Re: [FW-1] State Sync does not supports VLAN ?
From: Fabrice BARUTEL <fabrice.barutel AT STERIA DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 19 Apr 2006 10:56:01 +0200
Hi,

I think you should deal only with level 2 on your Cisco 6500 with VLAN
tagging, because of your synchronization network shouldn't be tagged on the
Checkpoint side. Then Checkpoint servers will not see that your Cisco
switches used VLAN.
Try to create a new VLAN for the synchronization network, which will be
transfered/tagged accross your trunk between your two Cisco 6500.
Good luck.

--
Fabrice BARUTEL

------------------------------

Date:    Wed, 19 Apr 2006 13:04:42 +0800
From:    "Alex S." <alexals AT KKIPC DOT COM>
Subject: State Sync does not supports VLAN ?

Hi there,

I read about State Synchronization in ClusterXL document saying that

"There are two restrictions to the synchronization network:
First, VLANs cannot be used in the synchronization network in any
version. Second, in older versions, the interface used for the
synchronization network must be a real interface with a real IP address
(as opposed to a cluster IP or a virtual IP)." page 15.

I have two Cisco Catalyst 6500 series which is connected each other
fibre (trunk together) and our firewall are connected to it on both side
through dedicated VLAN two on location A and one in location B).

My question is does it really works? Anybody had done a state sync
across two routing switches before? If yes, can someone kindly give me a
guide about this?

Thanks very much.

Regards,

Al.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>