Introduction to ClusterXL

R82 ClusterXL Administration Guide

Introduction to ClusterXL

The Need for Clusters

Security Gateways and VPN connections are business critical devices. The failure of a Security Gateway or VPN connection can result in the loss of active connections and access to critical data. The Security Gateway between the organization and the world must remain open under all circumstances.

ClusterXL Solution

ClusterXL is a Check Point software-based cluster solution for Security Gateway redundancy and Load Sharing. A ClusterXL Security Cluster contains identical Check Point Security Gateways.

Item Description
1 Internal network
2 Switch for internal network
3 Security Gateways with ClusterXL
4 Switch for external networks
5 Internet

How ClusterXL Works

ClusterXL uses State Synchronization to keep active connections alive and prevent data loss when a Cluster Member fails. With State Synchronization, each Cluster Member "knows" about connections that go through other Cluster Members.

ClusterXL uses virtual IP addresses for the cluster itself and unique physical IP and MAC addresses for the Cluster Members. Virtual IP addresses do not belong to physical interfaces.

Note - This guide contains information only for Security Gateway clusters. For additional information about the use of ClusterXL with VSX, see the R82 VSX Administration Guide.

The Cluster Control Protocol

The Cluster Control Protocol (CCP) packets are the glue that links together the members in the Security Cluster. CCP runs on UDP port 8116 between the Cluster Members, and has the following roles:

The Check Point CCP is used by all ClusterXL modes.

Important - There is no need to add an explicit rule to the Security Policy that accepts CCP packets.

For more information, see Configuring the Cluster Control Protocol (CCP) Settings.