CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-24
Junior Member
 
Join Date: 2007-05-08
Posts: 23
Rep Power: 0
auroranl has an average reputation (10+)
Default Strange problem with trunk interfaces after reboot

Hello,

On a newly installed SPLAT/R60A firewall. I am using trunks (first time). With sysconfig I created 4 VLAN interfaces in a particular NIC and I configured the switch in trunk mode with the 4 VLANS allowed.

When I boot, or reboot, the system the 'normal' interfaces work fine, however I don't see any 2-way traffic on the trunk interface. I don't receive any ARP response when I try to ping from the firewall.

In a last resort, I removed al VLANS from the FW interface and recreated the whole lot. Much to my surprise, everything worked fine afterwards. After a reboot however, same problem as before.

Does anybody have any clue on how to solve this problem? The hardware used is a HP DL380 with dual Gig cards (e1000 driver).

Last edited by auroranl; 2007-07-25 at 04:16.
Reply With Quote
  #2 (permalink)  
Old 2007-07-25
Senior Member
 
Join Date: 2006-01-25
Posts: 1,004
Rep Power: 4
melipla has an average reputation (10+)
Default Re: Strange problem with trunk interfaces after reboot

Quote:
Originally Posted by auroranl View Post
When I boot, or reboot, the system the 'normal' interfaces work fine, however I don't see any 2-way traffic on the trunk interface. I don't receive any ARP response when I try to ping from the firewall.
AFAIK you can't use the "normal" interface and have active vlans on the same interface. For example, if you wanted to trunk up eth0, you cannot define an IP address on eth0 AND have the vlans work on eth0.100, eth0.200, eth0.300 etc. You either define eth0 OR you define vlans--not both. If this is what you're doing then I'd convert the "normal" interface to a vlan, should be relatively easy.

HTH
Reply With Quote
  #3 (permalink)  
Old 2007-07-26
Junior Member
 
Join Date: 2007-05-08
Posts: 23
Rep Power: 0
auroranl has an average reputation (10+)
Default Re: Strange problem with trunk interfaces after reboot

I use the two onboard interfaces without VLAN tags for MGMT and BackBone traffic. I also have 3 dual GIG NIC cards from which I use 1 port of each card. Those interfaces have the VLAN interfaces.

Today I am setting up the same firewall in a lab environment and start snooping. I think something goes wrong with initialising the interfaces at boot time, maybe the traffic is not being tagged with VLAN tags or something.
The switch is not learning any MAC address from the VLAN interfaces of my firewall, until I use sysconfig to remove and re-create the VLAN interfaces.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0