In a Cluster, some features such as VPN only function properly when:

In a Cluster, some features such as VPN only function properly when:

In a Cluster, some features such as VPN only function properly when:

A.
all cluster members have the same number of interfaces configured.

B.
all cluster members’ clocks are synchronized.

C.
all cluster members have the same policy.

D.
all cluster members have the same Hot Fix Accumulator pack installed.



Leave a Reply 8

Your email address will not be published. Required fields are marked *


Brad

Brad

Can someone explain the answer please?

Love, Brad

CP-sniper

CP-sniper

See my comment below

CP-sniper

CP-sniper

Brad,

If clocks on cluster members are out of sync, then the SIC between members and the VPN will fail.

Brad

Brad

CP-sniper,
your explanation is much appreciated.

Love, Brad

FriedBacon

FriedBacon

Add to that, VPN between gateways by default users Certificates (that’s the beauty of having an SMS) w/c is time sensitive

Esteban

Esteban

B. all cluster members’ clocks are synchronized.

FriedBacon

FriedBacon

To add to CP-sniper’s input. By default, CheckPoint devices managed by an SMS negotiate VPN via SSL w/c uses certificates. Certificates as a whole regardless of the application is very time sensitive. Generally, it only allows +/- 10 min. difference