Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
128
Redundant Firewalls
213455-L, October 2005
Installing the redundant Switched Firewall
1.
Make sure that the first Switched Firewall is on and operational.
N
OTE
–
Make sure that
/cfg/net/vrrp/ha
and
/cfg/net/vrrp/aa
are disabled at
this point in the procedure.
2.
Rack mount the redundant Switched Firewall hardware.
See the
Nortel Switched Firewall 5100 Series Hardware Installation Guide
(216382-C).
3.
Connect the power cable for the redundant Switched Firewall, but do not turn it on yet.
Attach power as described in the
Nortel Switched Firewall 5100 Series Hardware Installation
Guide
(216382-C).
4.
Connect the redundant network feeds to the Switched Firewalls.
N
OTE
–
Be sure to connect each network to the same port/interface on both Switched
Firewalls.
Configuration check list
1.
Check Point sync network should be on a separate interface. It can also be in the SSI
subnet.
2.
If the sync interface is not the SSI interface, then make sure
/cfg/net/if
<#>/vrrp/ip1
and
/cfg/net/if<#>/vrrp/ip2
settings for the sync interface is
0.0.0.0.
3.
VLAN is not supported on the sync interface.
4.
Make sure the routers are pointing to the
ip1
and
ip2
addresses in the
/cfg/net/if
<#>/vrrp
menu and not to
addr1
and
addr2
addresses in the
/cfg/net/if<#>
menu.
5.
Do not use the SSI MIP as the default gateway.
6.
Make sure you have unchecked ClusterXL in the Cluster general properties tab in Check
Point SmartDashboard
™
tool.
7.
Do not enable
Automatic proxy arp
configuration in the SmartDashboard global
properties tab.