CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point UTM-1 Appliances
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2010-04-09
Junior Member
 
Join Date: 2010-02-02
Posts: 8
Rep Power: 0
johann.spies has an average reputation (10+)
Default No DNS after policy is loaded

I am building a load sharing cluster of two UTM-1's with R70.
.
When the policy is not installed, dns lookups work normally. When I load a policy, no lookups can be done.

Even when I try it with one rule

Src Dest service
any any any accept

No DNS lookups succeed.

At one stage a few days while trying to determine what the problem was, it suddenly worked with a full set of 88 rules. Today again there was no DNS and nothing changed in the rules since then.

The log shows that udp-domain packets to the dns-servers were accepted.

Any idea what is going on?

Regards
Johann
Reply With Quote
  #2 (permalink)  
Old 2010-04-09
Junior Member
 
Join Date: 2010-02-02
Posts: 8
Rep Power: 0
johann.spies has an average reputation (10+)
Default Re: No DNS after policy is loaded (more information)

It is not primarily a dns-problem. It is a networking problem. When the dns was not working I could not ping the backbone or the external segments of our network from the UTM, but I could ping the DMZ and the other member of the cluster through the private network. And I could ssh to the UTM from the backbone segment.

Somehow after some fiddling here and there and reloading an older policy (the same one that was active when the problem occurred this morning) everthing is working again.

I have tried to activate the Sticky option in the advanced Load Sharing Configuration but it was rejected because some accleration option is not available.

Can this be an indication that the communication witin the cluster is not working as it should?

Regards
Johann
Reply With Quote
  #3 (permalink)  
Old 2010-04-16
Senior Member
 
Join Date: 2006-10-03
Location: Offenbach/ Germany
Posts: 147
Rep Power: 4
Yasushi Kono has an average reputation (10+)
Default Re: No DNS after policy is loaded

Hi Johann,

did you install HFA20 just on the Security Management Server? If not, try that one. After this, you should try to do DNS. Without HFA (at least 20), you could run into trouble, since truncated DNS packets could be dropped.

Regards,
Yasushi
Reply With Quote
Reply

Tags
dns failure, r70, utm-1

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:37.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1