13.07.2015 Views

Firewall - Check Point

Firewall - Check Point

Firewall - Check Point

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ClusterXL2. Install policy.Unsupported Features57. Cluster deployments automatically hide the IP address of the cluster membersbehind a virtual IP address. If you manually add NAT rules that contradict thisconfiguration, the manually added NAT rules take precedence. For details, see the“ClusterXL Advanced Configuration” chapter of the ClusterXL Guide.58. TCP connections inspected by Web Intelligence or VoIP Application Intelligencefeatures will not survive failover. On the event of failover these connections will bereset.59. The compatibility matrix for third party clustering solutions (other than Nokia) isspecified in the following link:http://www.opsec.com/solutions/perf_ha_load_balancing.html. If a certain thirdparty solution is not specifically written as being supported for this release, youmust assume it is currently not supported. For Nokia clustering (VRRP or IPClustering), see the <strong>Check</strong> <strong>Point</strong> Software and Hardware Compatibility section of theClusterXL guide for information regarding which IPSO release is supported with thisVPN-1 release.60. Mounting an NFS drive on a cluster member is not supported, as hide NAT changesthe IP address of the cluster member, and the server cannot resolve the resultingmismatch.61. The following Web Intelligence features require connections to be sticky:• Header spoofing• Directory listing• Error concealment• ASCII only response• Send error pageA sticky connection is one where all of its packets, in either direction, are handledby a single cluster member. If you enable one of the features listed above, makesure that your clustering solution supports sticky connections. Sticky connectionscan be guaranteed for Web connections in the following configurations:• ClusterXL High Availability• ClusterXL Load Sharing with Sticky Decision Function enabled• ClusterXL Load Sharing with no VPN peers, no static NAT* rules and no SIP• Nokia VRRP Cluster• Nokia IP Clustering configuration with no VPN peers, static NAT* rules or SIPEnterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 44

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!