| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi, I found out a way on how to determine the multicast address on firewall cluster which is set automatically (by default). From command prompt on enforcement server, just key in this command # cphaconf debug_data Output : ================================================== ========= ========== ClusterXL Debug Information ============== ================================================== ========= ---------- Selection Table --------- Effective selection table size : 2 1:1 -------------------------------------- ---------- Multicast table ------------ eth0: Address: 192.168.10.6 Cluster/Default multicast IP : 192.168.10.250, MAC address : 01-00-5e-28-0a-fa eth1: Address: 192.168.1.6 Cluster/Default multicast IP : 192.168.1.250, MAC address : 01-00-5e-28-01-fa eth2: Address: 10.1.0.2 Cluster/Default multicast IP : 10.1.0.250, MAC address : 01-00-5e-28-00-fa ------------------------------------------------------------------------ ================================================== ========= ========== ClusterXL Debug End ============== ================================================== ========= I compared with another firewall peer and it has the same information with this firewall. All this while, I'm trying to find out the multicast address for the heartbeat as I had a problem to connect and synchronized three enforcement servers (firewall) which is connected to same VLAN on both Cisco 6500 which is trunked via a fiber. I found also that these multicast addresses are not change even after reboot. But there is one question, is this the multicast address mentioned in the "Troubleshoot interface flapping" section which is used to configure at Cisco 6500 series in order both or more enforcement synchronize on each other? In the other hand, I'm using State Sync for my firewall cluster which is running a 3rd Party load-balancing software (RainWall 3.1 SP5 R1) on top of it. I just wonder by using this multicast address, I could set it on Cisco 6509 switches to make both firewall on each location able to synchronize properly. Regards, Al Last edited by pop_alex; 2006-05-13 at 06:27. Reason: Clarifying |
![]() |
| Thread Tools | |
| Display Modes | |
| |