CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-23
Hitman Hitman is offline
Member
 
Join Date: 2006-05-11
Location: Montreal QC Canada
Posts: 36
Rep Power: 0
Hitman has an average reputation (10+)
Default Cluster member up and down (FIB) problem

Hi,

I have 2 SPLAT configure in a HA cluster.

Problem:

At interval of 5 minutes one of the member decide to drop the FIBMGR connection between the cluster members.
After that the cluster member 2 become down.

I get theses messages in the log tracker :

Cluster member IP is being spoofed
Cluster XL member 2 is down Problem notification on member 2 detected a problem (FIB)

A couple of seconds later this member 2 is up with the following log message:

Cluster XL member 2 is up Problem notification on member 2 status OK (FIB)

Five minutes later same thing happen.

The IP spoof is impossible by anoter server because this cluster is in a test environnement and with no other server in the cluster networks.

Thanks in advance for your help
Reply With Quote
  #2 (permalink)  
Old 2006-06-16
bryancromwell bryancromwell is offline
Junior Member
 
Join Date: 2005-10-14
Posts: 3
Rep Power: 0
bryancromwell has an average reputation (10+)
Default Re: Cluster member up and down (FIB) problem

If you are not using Advanced Routing, Disable it in cpconfig (Dynamic Routing option) This is what the FIB device is for.
We still configure Rip via the old zebra method so we just disabled it in our enviroment for now.
Reply With Quote
  #3 (permalink)  
Old 2007-04-19
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 159
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: Cluster member up and down (FIB) problem

Just for future problems with the error message 'Cluster member IP is being spoofed'

I was seeing this when a VPN was trying to be establish on an internal interface. The resolution was to untick the following 'Enable Extended Cluster Anti-Spoofing' under the topology tab of the cluster object.

hope this helps.

cheers

Dan

Last edited by Danielpb; 2007-04-19 at 02:32.
Reply With Quote
  #4 (permalink)  
Old 2007-11-26
cormic cormic is offline
Junior Member
 
Join Date: 2007-09-24
Posts: 5
Rep Power: 0
cormic has an average reputation (10+)
Default Re: Cluster member up and down (FIB) problem

All,

I just had this problem when I brought up my first NGX cluster on SPLAT Pro. When I did a chpaprob list I got the following.

Device Name: FIB
Registration number: 4
Timeout: none
Current state: problem
Time since last report: 42.8 sec

I was also seeing a drop in the logs for FIBMGR on port TCP 2010.

I found checkpoint article sk31243. This basically told me to create the following rule

SOURCE: gateway_cluster
DESTINATION: gateway_cluster
SERVICE: FIBMGR
ACTION: accept
INSTALL ON: gateway_cluster

Hope this helps for future users.

Regards,
Graham
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:12.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0