The information you are about to copy is INTERNAL!
DO NOT share it with anyone outside Check Point.
CloudGuard for Oracle Cloud Infrastructure (OCI)
Technical Level
Solution ID
sk168202
Technical Level
Product
CloudGuard Network for OCI
Version
R80.20 (EOL), R80.30 (EOL), R80.40, R81, R81.10
OS
Gaia
Platform / Model
Oracle Cloud Infrastructure
Date Created
05-Sep-2020
Last Modified
22-Jun-2022
Solution
This SK highlights Check Point's CloudGuard solutions for Oracle Cloud Infrastructure (OCI) as well as general guidance, best practices, and solutions to issues discovered in the field.
All-in-One (contact your SE for details) > not recommended for production use
Multi-Domain Management (contact your SE for details)
Licensing: BYOL (all versions), PAYG (R80.40, R81, and R81.10 only)
Definition of OCPU: Instance sizes: 1 OCPU is equivalent to 2 vCPUs. When you purchase a quantity, you must license according to the total amount of vCPUs.
Example: If you want to deploy a cluster with 2 OCPU instances you must purchase a quantity of 4 cores of CloudGuard.
Cluster Note: Cluster members' system time needs to be within 5 minutes of the actual time to communicate with the OCI API properly.
Interface MTU: All interfaces must have an MTU of 9000.
VFIO/SRIOV(***Recommended for best network performance***): VFIO/SRIOV is supported on all supported shapes except Standard2.
Identity Policies: Ensure that Identity Policies cover all compartments that contain resources relevant to your Check Point installation. (Ex. - VCN's associated with cluster IP moves due to failover events)
Making use of DRGs and OCI Service Gateways: OCI service gateways are needed to provide access to the Oracle API Service for cluster operations when internet access is unavailable. When used in conjunction with DRG's, the OCI Service Gateway route rule must be created in the DRG Route Table.
- Performance is limited by the amount of bandwidth allocated to each shape size - Test environment utilized CloudGuard Network Security R80.40 and E3 shapes with VFIO/SRIOV network interfaces
Current Oracle Cloud Marketplace Listings (as of 10 December 2021)
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Give us Feedback
Thanks for your feedback!
Are you sure you want to rate this stars?