CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-06
Junior Member
 
Join Date: 2007-10-18
Location: Melbourne, Australia
Posts: 26
Rep Power: 0
fizzkakz has an average reputation (10+)
Default Line protocol down on SPLAT box

Hi all,


Twice in the past two days I have had the same SPLAT gateway go unreachable. The first time I had someone on site reboot the server which did not fix the problem. He then noticed that the interface LEDs were not lit up. After reseating the cables the interfaces came up and we had restored connectivity. Looking at the logs on the switch connected to one of these interfaces that would not come up all I can see if line protocol going down and then being restored when the cable was reseated. This firewall is going to be decommissioned shortly as I was hoping I could put it down to a once off.

This same firewall has gone down again this morning. This is obviously a reoccurring problem which I am going to need to investigate. Can anyone offer any suggestions on what may be causing this fault? Where within the SPLAT can I find the appropriate logs that may indicate what is causing this problem?

Any help would be appreciated. Thanks!
Reply With Quote
  #2 (permalink)  
Old 2008-08-06
Junior Member
 
Join Date: 2007-10-18
Location: Melbourne, Australia
Posts: 26
Rep Power: 0
fizzkakz has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

This appears to be a different problem. The SPLAT box had randomly dropped the route that allows us to manage it. I have seen this happen before with other static routes. Is this is a known issue?
Reply With Quote
  #3 (permalink)  
Old 2008-08-07
Senior Member
 
Join Date: 2007-07-16
Posts: 693
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

How are you managing your routes? Are you using sysconfig or have you created a rc.local file to add routes? If it's the latter, that's where your problem is - bad idea to do this....
Reply With Quote
  #4 (permalink)  
Old 2008-08-07
Junior Member
 
Join Date: 2007-10-18
Location: Melbourne, Australia
Posts: 26
Rep Power: 0
fizzkakz has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

I always using sysconfig.

Is it possible I have unknowingly manipulated routes via the Dashboard or are they completed unrelated?
Reply With Quote
  #5 (permalink)  
Old 2008-08-07
Senior Member
 
Join Date: 2007-07-16
Posts: 693
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

Sounds like a different issue. I'd suspect a hardware/driver issue. What SPLAT and NGX version is it?
Reply With Quote
  #6 (permalink)  
Old 2008-08-07
Junior Member
 
Join Date: 2007-10-18
Location: Melbourne, Australia
Posts: 26
Rep Power: 0
fizzkakz has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

Running SPLAT NGX R60 Build 244.

I have also suspected a hardware issue. I have noticed that when you login via ssh it displays the login prompt in a normal amount of time but sometimes takes up to ten seconds to display the password prompt. There is also a lengthy delay after typing in route and the route table being displayed. Could this point to a hardware issue? If so how can I diagnose it?
Reply With Quote
  #7 (permalink)  
Old 2008-08-07
Junior Member
 
Join Date: 2007-10-18
Location: Melbourne, Australia
Posts: 26
Rep Power: 0
fizzkakz has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

I am also getting lengthy delays when typing netstat and other diagnostic commands on this device.
Reply With Quote
  #8 (permalink)  
Old 2008-08-07
Junior Member
 
Join Date: 2008-05-11
Posts: 28
Rep Power: 0
jaskaran224 has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

You need to ensure, if the hardware on which you are running SPLAT is compatible.. Probably you can check the hardware and NIC compatibilty of various vendors on below link.

Check Point Software: SecurePlatform
Reply With Quote
  #9 (permalink)  
Old 2008-08-08
Senior Member
 
Join Date: 2006-01-25
Posts: 1,005
Rep Power: 4
melipla has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

Even if they are compatible, make sure that there are no interface errors in splat and on the switch, make sure the switch and splat report the same speed & duplex.

You can lose routes associated with a specific interface if you do something like "ifdown eth1". However I've never seen an interface disappear while the system is running.
__________________
Its all in the documentation.
Reply With Quote
  #10 (permalink)  
Old 2008-08-08
Junior Member
 
Join Date: 2008-03-24
Posts: 21
Rep Power: 0
moaahk has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

I think your case is exactly the same as my SPlats UTM 1050 appliance, one of the interface will go down at uncertain time, it totally random. When the interface gose down, all the route associate with the interface will disappear too.

I have contacted with check point, and they provided me a solution to reinstall the image on the appliance. But, this problem still can not be fixed.
We have to do RMA at last.

I think this could be a network card driver or hardware problem, because it alway happen on the same interface and when it happen, the SPlat box will also hang and we need to shutdown the appliance. But when the appliance come up, the interface will even disappear from "ifconfig -a" command.
Reply With Quote
  #11 (permalink)  
Old 2008-08-10
Junior Member
 
Join Date: 2007-10-18
Location: Melbourne, Australia
Posts: 26
Rep Power: 0
fizzkakz has an average reputation (10+)
Default Re: Line protocol down on SPLAT box

The thing that makes me suspect it is not a software incompatibility issue is that fact that I run four gateways with the exact same hardware, part for part. Every gateway is running the same version of SPLAT. But this issue only occurs on one of the gateways.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:05.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0