CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-11
jbailey01 jbailey01 is offline
Junior Member
 
Join Date: 2006-05-11
Posts: 11
Rep Power: 0
jbailey01 has an average reputation (10+)
Default Nokia VRRP Problem

Hello,

We have two Nokia IP330s running IPSO 3.8 and Check Point NG R55. The two firewalls are configured for HA and had been running fine for over a year. This past week we pushed a new policy and after the policy was pushed both firewalls reported their status as Master for all 7 interfaces we have clustered. I rebooted one of the firewalls and as it was booting the following was logged:

Information: cluster_info: (3rd Party Cluster) State change of member
2 (x.x.x.x) from active to down was canceled, since all other members
are down. Member remains active.

After this message was logged both firewalls again reported as Master for all clustered interfaces.

I have checked the topology and everything looks good, the only thing I noticed was that I can not ping the other side of the sync network I have setup. I am not sure if this is normal, but its just something I noticed while troubleshooting.

I have not been able to do much troubleshooting due to the connectivity problems that are caused when both firewalls are up.

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 2006-05-13
karlk karlk is offline
Junior Member
 
Join Date: 2006-04-22
Posts: 4
Rep Power: 0
karlk has an average reputation (10+)
Default Re: Nokia VRRP Problem

I have the same problem ever since I changed the inside ip addresses on my Nokia VRRP pair of IP530's. I also haven't been able to troubleshoot well since it takes down the network to have both firewalls plugged in.

The policy is blocking the VRRP advertisements. If I cpstop on the machine that's supposed to be backup, the interfaces go to backup. So, the policy on that machine is blocking the advertisements from the "true" master. When I cpstart, the backup goes master, while the other stays master.

I also can't find anything wrong with the policy or topology.
Reply With Quote
  #3 (permalink)  
Old 2006-07-06
maxpower maxpower is offline
Junior Member
 
Join Date: 2005-08-26
Posts: 2
Rep Power: 0
maxpower has an average reputation (10+)
Default Re: Nokia VRRP Problem

Can you try to take a look from the log.

See whether the traffic between 2 interfaces (cluster) are able to communicate with MCAST packet?

check the anti-spoofing and the firewall policy should help.
Reply With Quote
  #4 (permalink)  
Old 2006-07-06
donshoutarp donshoutarp is offline
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 4
donshoutarp has an average reputation (10+)
Default Re: Nokia VRRP Problem

If "Monitor Firewall State:" is enabled, you may wish to try to disable this until the VRRP gets a bit stable.
Reply With Quote
  #5 (permalink)  
Old 2006-07-06
fwman fwman is offline
Junior Member
 
Join Date: 2006-06-19
Posts: 8
Rep Power: 0
fwman has an average reputation (10+)
Default Re: Nokia VRRP Problem

Nokia says in an info to IPSO 3.6 (R55 already has a "vrrp" service):

Double Check to make sure the Firewall is allowing VRRP packets out of its interfaces:

Create a workstation object with the name VRRP-MCAST-NET for address 224.0.0.18

Create the VRRP service in FW-1 as follows:
Open the Services Manager

Select New -> Other

Type vrrp in the Name field

Enter ip_p = 0x70 in the Match field
Reply With Quote
  #6 (permalink)  
Old 2006-07-06
dbedit dbedit is offline
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: Nokia VRRP Problem

Changing IP addresses on your VRRP interfaces will cause trouble. You have to remove the interface from your VRRP config first before changing addresses. In some cases you have to remove the VRID and setup VRRP config again for all interfaces to get it work. If only changes to rulebase is made just make sure before applying you can use database revision control to revert to your working policy.
Reply With Quote
  #7 (permalink)  
Old 2006-07-06
braintek braintek is offline
Junior Member
 
Join Date: 2006-07-06
Posts: 7
Rep Power: 0
braintek has an average reputation (10+)
Default Re: Nokia VRRP Problem

I had this problem a couple of times the only quick solution was to recreate the VRRP table (Simplified mode). In my case I had been changing the VIP and was getting unstable FW state.

Hope that helps
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:23.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0