13.07.2015 Views

Firewall - Check Point

Firewall - Check Point

Firewall - Check Point

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ClusterXL45. When configuring a Nokia IP Cluster, do not set the primary or secondary interfacesto Network Objective Private. <strong>Check</strong> <strong>Point</strong> recommends setting a Nokia IP Cluster’sprimary interface to Network Objective Cluster, and its secondary interface toNetwork Objective Cluster or Sync.Platform Specific — Solaris46. When configuring virtual interfaces on Solaris GigaSwift interfaces, the ClusterXLproduct may not recognize the virtual interfaces in cases where no correspondingphysical interface is defined. If the virtual interface is not recognized, it will notrun a monitoring mechanism and eventually it will not perform failover. In order tomake ClusterXL work properly on such virtual interfaces, the corresponding physicalinterface must be defined. For example, when a CE device with an instance of 0 isdefined on the system, the /etc/hostname.ce0 file must be created and mustcontain some arbitrary IP address that will be assigned to the physical interface.47. ClusterXL does not support defining VLANs on Solaris bge interfaces.48. When configuring VLAN tags, set the IP address on the VLAN physical interface. Ifthe physical (untagged) interface is not used, the IP address can be any IP address.For example:If the physical interface is ce1, andthe VLAN interfaces are ce1001 and ce2001, thence1 must also have an IP address.49. ClusterXL in Unicast mode (Pivot) is not supported on Solaris when using VLANtagging.50. When using a Fujitsu GigEthernet NIC (fjgi and fjge interfaces) with <strong>Check</strong> <strong>Point</strong>Load Sharing (CPLS) multicast, packets can be received when the interface is setto promiscuous mode only.51. The local.arp file is not supported on ClusterXL gateways running Solaris. In orderto use manual NAT on Solaris, use the following workaround:On the command line, run the following command:arp -s pubFor this command to survive boot, add a file under /etc/rc3.d/ (the name does notmatter), and on each line enter an IP address to be NATed and its correspondingMAC address.arp -s pubarp -s pubetc...Enterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 42

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!