CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-08
Junior Member
 
Join Date: 2006-03-08
Posts: 5
Rep Power: 0
dstern@bn.com has an average reputation (10+)
Default Troubleshoot Interface Flapping

Platform:
Linux, NG, 4 interfaces.

If you look at the following, you see that the secondary keeps going up and down. A reboot didnt fix it. Any ideas on troubleshooting?


# cphaprob state

Cluster Mode: New High Availability (Active Up)

Number Unique Address Assigned Load State

1 192.168.75.1 100% active
2 (local) 192.168.75.2 0% standby

# cphaprob state

Cluster Mode: New High Availability (Active Up)

Number Unique Address Assigned Load State

1 192.168.75.1 100% active
2 (local) 192.168.75.2 0% down

# cphaprob state

Cluster Mode: New High Availability (Active Up)

Number Unique Address Assigned Load State

1 192.168.75.1 100% active
2 (local) 192.168.75.2 0% standby
Reply With Quote
  #2 (permalink)  
Old 2006-03-08
Junior Member
 
Join Date: 2005-08-19
Posts: 14
Rep Power: 0
Claer has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Try to find why the second member keep going down.

From my experience, I had a similar case with an unused interface configured in DHCP mode. As there was no link on this interface, this particular cluster member was going up and down as yours. My solution was to remove IP configuration from that interface.

Hope this help :)
Reply With Quote
  #3 (permalink)  
Old 2006-03-08
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Check Smartview Tracker and Status and use "cphaprob list". Last command shows you cluster devices and there status.
Reply With Quote
  #4 (permalink)  
Old 2006-03-08
Junior Member
 
Join Date: 2006-03-08
Posts: 5
Rep Power: 0
dstern@bn.com has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Right - I know how to find it, Im more curious as to what creates the condition of regular up/down activity.
Reply With Quote
  #5 (permalink)  
Old 2006-03-08
Senior Member
 
Join Date: 2006-03-08
Posts: 122
Rep Power: 3
varera has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

1. Please check your cluster is working in multicast mode. It most probably is.
2. To avoid the problem you have two options:

2.1 switch to broadcast mode (not really a good solution)
2.2 switch off igmp snooping on your switch. it will fix is once and for all. this solution is recommended by clusterxl user guide.
Reply With Quote
  #6 (permalink)  
Old 2006-03-09
Junior Member
 
Join Date: 2006-03-08
Posts: 5
Rep Power: 0
dstern@bn.com has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

IGMP Snooping is not running on the switch. There are a number of Cisco CSS Load Balancers on that segment that some of my people feel are causing a bad interaction. When I know more Ill post it.

Thanks for all the help.
Reply With Quote
  #7 (permalink)  
Old 2006-03-10
Junior Member
 
Join Date: 2006-03-08
Posts: 5
Rep Power: 0
dstern@bn.com has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

it looks like a funky clusterXL issue. Usually, if CCP isnt being transmitted, then its on all of the interfaces. In my case, its only happening on 1 interface, which means the cluster needs to be slapped.
Reply With Quote
  #8 (permalink)  
Old 2006-03-30
Junior Member
 
Join Date: 2006-03-30
Location: Rio de Janeiro, RJ, Brasil
Posts: 8
Rep Power: 0
FERappel has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

This occurs here due to the trunk not forwarding multicast traffic between the virtual trunk ports in the 6500 w/ the Native IOS, the ones connecting inside, though no problems w/ the (real) ones connecting the firewalls, inside or outside - the multicast macs appears in the ports -, neither w/ trunk in the 6500 w/ the CatOS + IOS, the ones connecting outside. The solution was to configure the multicast addresses in the ports, both the virtual and the ones connecting firewalls, but not the real ones of the trunk, besides disabling IGMP snooping. There are links in the CP and the Cisco sites. Note: the parameters are slight different for the Native IOS between SUP2 and SUP1A.

Last edited by FERappel; 2006-04-25 at 07:10. Reason: Clarifying.
Reply With Quote
  #9 (permalink)  
Old 2006-04-14
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Hi,

Can you provide me the link for the solution? :)

Regards,

Al
Reply With Quote
  #10 (permalink)  
Old 2006-04-14
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

In CP knowledge base there is next link
http://www.cisco.com/en/US/products/...5.html#1035778
Reply With Quote
  #11 (permalink)  
Old 2006-04-20
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 4
maurox has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Did you solve the problem ( I'm having the same problem ) with the Cisco solution ?
thanks,
Maurox
Reply With Quote
  #12 (permalink)  
Old 2006-04-21
Junior Member
 
Join Date: 2006-04-21
Posts: 1
Rep Power: 0
Blueknight has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Guys I have come across a similar problem many moons ago. The issue then was to do with the Ethernet interface being in auto and continually hunting between 10 and 100 Mb settings. Was ok once we hard configed the interface on the firewall and the switch to operate at a specific speed.

Hope this helps

Blueknight
Reply With Quote
  #13 (permalink)  
Old 2006-04-25
Junior Member
 
Join Date: 2006-03-30
Location: Rio de Janeiro, RJ, Brasil
Posts: 8
Rep Power: 0
FERappel has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Quote:
Originally Posted by maurox
Did you solve the problem ( I'm having the same problem ) with the Cisco solution ?
thanks,
Maurox
Yes, I did!
Reply With Quote
  #14 (permalink)  
Old 2006-04-25
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Quote:
Originally Posted by FERappel
This occurs here due to the trunk not forwarding multicast traffic between the virtual trunk ports in the 6500 w/ the Native IOS, the ones connecting inside, though no problems w/ the (real) ones connecting the firewalls, inside or outside - the multicast macs appears in the ports -, neither w/ trunk in the 6500 w/ the CatOS + IOS, the ones connecting outside. The solution was to configure the multicast addresses in the ports, both the virtual and the ones connecting firewalls, but not the real ones of the trunk, besides disabling IGMP snooping. There are links in the CP and the Cisco sites. Note: the parameters are slight different for the Native IOS between SUP2 and SUP1A.
Hi,

Am still confuse about multicast IPs. How do I determine the multicast IP?

Thanks.

Regards,

Al
Reply With Quote
  #15 (permalink)  
Old 2006-04-28
Junior Member
 
Join Date: 2006-03-30
Location: Rio de Janeiro, RJ, Brasil
Posts: 8
Rep Power: 0
FERappel has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Quote:
Originally Posted by pop_alex
Hi,

Am still confuse about multicast IPs. How do I determine the multicast IP?

Thanks.

Regards,

Al
Not you, FW-1! sk 25977 30197 11551 31325, which I've sent 2 e-mails w/ comments to CP, 1 implemented, 1 pending.

Last edited by FERappel; 2006-04-28 at 08:43. Reason: Missing.
Reply With Quote
  #16 (permalink)  
Old 2006-05-11
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: Troubleshoot Interface Flapping

Hi, JFYI...

I had done a synchronization between two test machine (installed with the latest version of Check Point NG AI R55) across two Cisco 6509 Switch Series recently and it works perfectly. These machines are installed using Red Hat 7.3. By enabling the "no igmp snooping" on VLAN, it works fine. Below are two test result conducted recently:

a) By connecting both test machine (firewall) on each Cisco 6509 Switch series, which will be on same VLAN across trunked fiber, also configured both switches using a command called "no igmp snooping". It works perfectly.

b) We put IPs on VLAN on both side (Cisco 6509 switches) and test the state sync. Result, it working fine.

It seems it works fine using a test machine with Red Hat Linux 7.3 (installed with Check Point NG AI R55) but I couldn't make it sync using three SUN V280R (O.S. Solaris 9) with 1GBic Quadcard on each, across two Cisco 6509 switches.

I wonder why,

a) when using two test machine (firewall) on Linux are able to synchronize over two Cisco 6509 switches without any problem instead using two or more firewall on Solaris?

b) do I need to configure "mac-address-table static" for multicast address on Cisco 6509 switches just to make firewall talk to each other?

One last question, I noticed when I reboot all three firewall server (SUN) after activate the state synchronization, these messages appeared on primary and third firewall (but none in secondary firewall) during startup;

Apr 14 15:57:33 xxx.xxxx.xx ip: [ID 856290 kern.notice] ip: joining multicasts failed (3) on ce1 - will use link layer broadcasts for multicast

What does this mean?

Thanks very much

Regards,

Al

Last edited by pop_alex; 2006-05-13 at 07:21. Reason: Clarifying
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:28.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0