Re: Checkpoint FW1 failover requirements?

From: Thomas Marko (news-kabsiREMOVEME_at_tomsoft.at)
Date: 02/24/05


Date: Thu, 24 Feb 2005 08:26:31 +0100

SJ wrote:
> Hello,
> We currently are running a Checkpoint NG firewall on a Solaris box with
> an Enterprise license for unlimited users.
>
> I am looking to set up another identical Solaris box running Checkpoint to
> be a failover/standby when the first one would fail.
> I am not looking for load balancing.
>
> My question: Is this functionality built in to the NG firewall software
> itself?

Yes, there is a functionality in FW-1/VPN-1 which is called CPHA which
can do standby HA but can also do Load Balancing (depends on how many
coins you'll through into the slot ;-)

You can also realize HA using the protocol VRRP (builtin in Nokia and
Nortel Alteon Appliances, and ?).

> And would we have to pay for another ($20K) Enterprise licence to make this
> happen?

AFAIK you will need a license for the second module, but not for a
second management server. If you use CPHA you will have to purchase a
ClusterXL license.

> If this scenario requires another Enterprise license to be purchased, it
> would probably just make more sense to buy two Cisco PIXes in a
> standby/failover configuration and save a bunch of money.

Please do not compare a Check Point FW-1/VPN-1 with a Cisco PIX. Just
looking for the price when buying a firewall is IMHO the wrong way.

Cheers,
Thomas



Relevant Pages

  • Re: Somewhat OT - Firewall Licencing
    ... I have used Checkpoint too, it is a PITA to have to actually manually update the count, but that is how they encourage truth from their subscribers. ... As mentioned, if you are unwilling to abide by the license agreement, it may be time to find a lesser firewall solution provider. ...
    (microsoft.public.windows.server.networking)
  • Checkpoint FW1 failover requirements?
    ... I am looking to set up another identical Solaris box running Checkpoint to ... Is this functionality built in to the NG firewall software ... If this scenario requires another Enterprise license to be purchased, ...
    (comp.security.firewalls)
  • Problems with checkpoint and solaris 8 in.ftpd
    ... I am having a problem with Checkpoint 4.1 and Solaris 8 with regards to ... ftp'ing through the firewall to a solaris 8 FTP server. ... This packet whetever it is causes the firewall to terminate the tcp connection ...
    (comp.security.firewalls)
  • RE: Firewall Server
    ... Ipfilter on Solaris also, ... Sun also has a firewall product. ... > Checkpoint on Solaris ... > You can use GNU/Linux as firewall server. ...
    (Security-Basics)
  • RE: suggestions on a good firewall
    ... Cisco does not do ... BTW I never said I disliked Checkpoint, ... suggestions on a good firewall ... standards (Open Platform for Security) Is brought to you by Checkpoint ...
    (Security-Basics)