User's Manual Part 1

Configuring High Availability
128 Check Point Safe@Office User Guide
Sample Implementation on Two Gateways
The following procedure illustrates how to configure HA for the following two
Safe@Office gateways, Gateway A and Gateway B:
Table 15: Gateway Details
Gateway A Gateway B
Internal Networks LAN, DMZ LAN, DMZ
Internet Connections Primary and secondary Primary only
LAN Network IP Address 192.169.100.1 192.169.100.2
LAN Network
Subnet Mask
255.255.255.0 255.255.255.0
DMZ Network IP Address 192.169.101.1 192.169.101.2
DMZ Network
Subnet Mask
255.255.255.0 255.255.255.0
The gateways have two internal networks in common, LAN and DMZ. This means
that you can configure HA for the LAN network, the DMZ network, or both. You
can use either of the networks as the synchronization interface.
The procedure below shows how to configure HA for both the LAN and DMZ
networks. The synchronization interface is the DMZ network, the LAN virtual IP
address is 192.168.100.3, and the DMZ virtual IP address is 192.168.101.3.
Gateway A is the Active Gateway.
To configure HA for Gateway A and Gateway B
1. Connect the LAN port of Gateways A and B to hub 1.