| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Have a situation: a pair of IBM 3650 dual quad-core processors 3.16 Ghz with 4GB RAM running in ClusterXL Active/Active Unicast mode. The Checkpoint software is NGx R65 2.6 kernel This firewall pair is being managed by Provider-1 NGx R65 2.4 kernel with HFA_02 running on a Dell 2850 dual processors 3.06 Ghz with 8GB RAM. Logs on the firewalls are being sent to a Provider-1 MLM and a standalone CLM. Provider-1 is NGx R65 with HFA_02 on 2.4 kernel. The stand-alone CLM is NGx R65 2.6 kernel on a Dell 2950-III box. Everything is running checkpoint 30 days eval license. I have about 300 rules in the security policy. I pushed policy to the pair of firewalls. Everything is working fine and I get no errors when pushing policy to the firewall I have a couple of QoS rule in the QoS policy. I see NO errors when pushing policy to the firewalls. At this point I start pushing about 900Mbps between the Iperf client/server through the firewall. Here are two issues I have: 1- In SmartView Monitor, it tells me that I hav NO QoS policy installed on gw1 and gw2, 2- After every two hours, I lose SIC either to the gw1 or gw2 firewall. I verified this by performing "test SIC" in the cluster members. When I pushed policy to the firewall, it tells me that policy push failed either to gw1 or gw2 member. The only way for me to fix is to re-SIC and reboot the firewall and re-establish SIC with the Provider-1 CMA. 3- I have NO issue with SIC when I go Active/Standby. Is this a bug in Checkpoint or something? My setup is a very simple one. Comment anyone? Thanks. Last edited by cciesec2006; 2008-05-15 at 20:46. Reason: attachment |
| |||
| Had this problem, too, on HP DL385 hardware with NGX (R65) on SPLAT 2.6 kernel in connection with a (R65) HFA_02 management. Lost SIC connection after a few minutes while everything was working before. Solution: get rid of the 2.6 kernel. When we installed R65 from the orig. CD without the 2.6 kernel there were no issues at all. |
| |||
| Quote:
Unfortunately this hardware isn't supported on the R65 2.4 kernel.... HTH __________________ Its all in the documentation. |
| |||
| Hi there, do you have that ticket number by chance? I also have ticket opened with ISS/checkpoint and they asked me if others run into the same issue. Please email me off-line for the ticket. Really appreciate it. |
![]() |
| Thread Tools | |
| Display Modes | |
| |