CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-15
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default ClusterXL trouble.. Help!!!!

Have a situation:

a pair of IBM 3650 dual quad-core processors 3.16 Ghz with 4GB RAM
running in ClusterXL Active/Active Unicast mode. The Checkpoint
software is NGx R65 2.6 kernel

This firewall pair is being managed by Provider-1 NGx R65 2.4 kernel
with HFA_02 running on a Dell 2850 dual processors 3.06 Ghz with 8GB RAM.

Logs on the firewalls are being sent to a Provider-1 MLM and a standalone CLM.
Provider-1 is NGx R65 with HFA_02 on 2.4 kernel. The stand-alone CLM
is NGx R65 2.6 kernel on a Dell 2950-III box.

Everything is running checkpoint 30 days eval license.

I have about 300 rules in the security policy. I pushed policy to the
pair of firewalls. Everything is working fine and I get no errors when
pushing policy to the firewall

I have a couple of QoS rule in the QoS policy. I see NO errors when
pushing policy to the firewalls.

At this point I start pushing about 900Mbps between the Iperf client/server
through the firewall.

Here are two issues I have:

1- In SmartView Monitor, it tells me that I hav NO QoS policy installed
on gw1 and gw2,

2- After every two hours, I lose SIC either to the gw1 or gw2 firewall.
I verified this by performing "test SIC" in the cluster members. When
I pushed policy to the firewall, it tells me that policy push failed
either to gw1 or gw2 member. The only way for me to fix is to re-SIC
and reboot the firewall and re-establish SIC with the Provider-1 CMA.

3- I have NO issue with SIC when I go Active/Standby.


Is this a bug in Checkpoint or something? My setup is a very simple one.

Comment anyone? Thanks.

Last edited by cciesec2006; 2008-05-15 at 20:46. Reason: attachment
Reply With Quote
  #2 (permalink)  
Old 2008-05-15
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL trouble.. Help!!!!

here is a diagrame of my test
Attached Thumbnails
clusterxl-trouble-help-ibm_3650.jpg  
Reply With Quote
  #3 (permalink)  
Old 2008-05-15
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: ClusterXL trouble.. Help!!!!

Had this problem, too, on HP DL385 hardware with NGX (R65) on SPLAT 2.6 kernel in connection with a (R65) HFA_02 management. Lost SIC connection after a few minutes while everything was working before.

Solution: get rid of the 2.6 kernel. When we installed R65 from the orig. CD without the 2.6 kernel there were no issues at all.
Reply With Quote
  #4 (permalink)  
Old 2008-05-16
Senior Member
 
Join Date: 2006-01-25
Posts: 1,005
Rep Power: 4
melipla has an average reputation (10+)
Default Re: ClusterXL trouble.. Help!!!!

Quote:
Originally Posted by cciesec2006 View Post
2- After every two hours, I lose SIC either to the gw1 or gw2 firewall.
I verified this by performing "test SIC" in the cluster members. When
I pushed policy to the firewall, it tells me that policy push failed
either to gw1 or gw2 member. The only way for me to fix is to re-SIC
and reboot the firewall and re-establish SIC with the Provider-1 CMA.

3- I have NO issue with SIC when I go Active/Standby.


Is this a bug in Checkpoint or something? My setup is a very simple one.

Comment anyone? Thanks.
I have an open, not going anywhere, SR with Check Point about an R65 2.6 kernel cluster which loses SIC on either the active or the standby member (its random). The loss of SIC is caused by CPD utilizing 100% on one of the CPUs. I've narrowed the problem down to RTM / Smartview monitor being enabled for the Gateway object and have seen varying times for when the problem occurs--when I had attempted to time it, it was an hour between occurrences.

Unfortunately this hardware isn't supported on the R65 2.4 kernel....

HTH
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2008-05-16
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL trouble.. Help!!!!

Hi there,

do you have that ticket number by chance? I also have ticket opened with
ISS/checkpoint and they asked me if others run into the same issue.

Please email me off-line for the ticket. Really appreciate it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:38.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0