CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-10
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Dell Server 2950-III and mirror RAID-1 and SPLAT NGx R65

need advice on folks with experience with Dell 2950-III
Servers dual quad-core processors with 4GB RAM as a
Checkpoint NGx R65 enforcement modules. this question
has to do with mirror RAID-1 of the hard drive.


The server comes with two 80GB hard drive. I configure
it for mirror RAID-1. After that I configure Checkpoint
NGx R65 with HFA_02 on it. The enforcement module is
managed by a CMA inside a Provider-1. Everything is
working fine.

Now to stimulate a hard drive failure, I remove one of
the hard drive, called hard drive #1 from the Dell server.
At this point, the firewall continues to work fine.

I then insert a brand new hard drive, called hard
drive X, into the slot of hard drive #1. At this point,
I would expect hard drive X to be mirror by hard drive
#2. It's 4pm in the afternoon so I went home. I would
expect the mirror to be done by 8am the following morning.

Next day, when I came in, I would expect the mirror is
done by now. To simulate a failure, I remove hard drive
#2 from the Dell server, expecting that the dell server
should still be working. However, the minute I remove
the hard drive #2, the firewall stopped working.

Anyone working with Dell Server 2950-III know how
the RAID-1 mirror works. Apparently, it did not work
the way I expected it to work.

Thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 2008-05-10
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 586
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Dell Server 2950-III and mirror RAID-1 and SPLAT NGx R65

Quote:
Originally Posted by cciesec2006 View Post
need advice on folks with experience with Dell 2950-III
Servers dual quad-core processors with 4GB RAM as a
Checkpoint NGx R65 enforcement modules. this question
has to do with mirror RAID-1 of the hard drive.


The server comes with two 80GB hard drive. I configure
it for mirror RAID-1. After that I configure Checkpoint
NGx R65 with HFA_02 on it. The enforcement module is
managed by a CMA inside a Provider-1. Everything is
working fine.

Now to stimulate a hard drive failure, I remove one of
the hard drive, called hard drive #1 from the Dell server.
At this point, the firewall continues to work fine.

I then insert a brand new hard drive, called hard
drive X, into the slot of hard drive #1. At this point,
I would expect hard drive X to be mirror by hard drive
#2. It's 4pm in the afternoon so I went home. I would
expect the mirror to be done by 8am the following morning.

Next day, when I came in, I would expect the mirror is
done by now. To simulate a failure, I remove hard drive
#2 from the Dell server, expecting that the dell server
should still be working. However, the minute I remove
the hard drive #2, the firewall stopped working.

Anyone working with Dell Server 2950-III know how
the RAID-1 mirror works. Apparently, it did not work
the way I expected it to work.

Thanks in advance.
In the hardware RAID arrays I've worked with, you need to open the software user interface and actually tell it to start rebuilding; it's not enough to just insert a new drive. The reasoning, I think, is that rebuilding on a new drive is essentially a destructive reformatting of that drive, and they want to be ensure this is what you really want done.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #3 (permalink)  
Old 2008-05-10
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Dell Server 2950-III and mirror RAID-1 and SPLAT NGx R65

Quote:
Originally Posted by BarryStiefel View Post
In the hardware RAID arrays I've worked with, you need to open the software user interface and actually tell it to start rebuilding; it's not enough to just insert a new drive. The reasoning, I think, is that rebuilding on a new drive is essentially a destructive reformatting of that drive, and they want to be ensure this is what you really want done.
If that is the case, it would require a firewall reboot which is something I
do not want. After all, the whole idea is to minimize the firewall downtime.
If the box is rebooted for reconfigure RAID-1, it surely defeated the purpose
of RAID-1 redundancy.
Reply With Quote
  #4 (permalink)  
Old 2008-05-11
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 586
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Dell Server 2950-III and mirror RAID-1 and SPLAT NGx R65

Quote:
Originally Posted by cciesec2006 View Post
If that is the case, it would require a firewall reboot which is something I
do not want. After all, the whole idea is to minimize the firewall downtime.
If the box is rebooted for reconfigure RAID-1, it surely defeated the purpose
of RAID-1 redundancy.
I think the claim to redundancy is that even if one drive fails, the machine keeps working and allows you to replace the failed drive at your leisure. If you can wait a week and make it to a maintenance window, I agree it's not perfect but it's still pretty good.

I believe some more advanced RAID arrays may allow you to maintain a hot spare live all the time and it will then build it automatically when needed.

Otherwise, I'd sort of expect a reboot at some point in order to swap out a hard drive and repair the array, unless the RAID has some software that can run on your OS and configure the array without booting.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #5 (permalink)  
Old 2008-05-13
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Dell Server 2950-III and mirror RAID-1 and SPLAT NGx R65

This varies a lot between controllers. Its one of my few issues with SPLAT, if I need special software to kick a raid controller, I have to hope I can find a build that will work.

Seeing as Dell kind of supports RH, maybe there is a build out there that will work from the command line. Look for a statically linked version, it will be your best shot.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:42.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0