Working on Checkpoint Cluster XL Load Sharing configuration, and found one blog post from Technopath LLC regarding Cisco switch configuration. It should be helpful for my next step.
The topology like this:
- Configure the following command on the internal router (usually it is layer 3 switch and 0100.5e16.0de2 is Internal Checkpoint VIP Multicast Mac Address):
- arp 192.168.20.2 0100.5e16.0de2 arpa
- mac address-table static 0100.5e16.0de2 vlan 10 interface gi1/0/2 gi1/0/3 gi1/0/4
- no ip igmp snooping vlan 10
- arp 192.168.15.2 0100.5e16.0de3 arpa
- mac address-table static 0100.5e16.0de3 vlan 20 interface gi1/0/5 gi1/0/6 gi1/0/7
- no ip igmp snooping vlan 20
本文详细介绍Checkpoint防火墙集群内部及外部虚拟IP的配置过程。通过在路由器与交换机上设置特定的ARP与MAC地址表项,确保了集群负载均衡功能的正常运作。文中还提供了获取集群多播MAC地址的方法,并指出了一种不推荐使用的获取MAC地址的方式。

521

被折叠的 条评论
为什么被折叠?



