CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-03
mannyz mannyz is offline
Junior Member
 
Join Date: 2005-08-17
Posts: 1
Rep Power: 0
mannyz has an average reputation (10+)
Default Trouble with ClusterXL loadsharing multicast mode

Dear list,
I am in trouble with a ClusterXL cluster of 2 nodes running in multicast mode.

OS: Sun Solaris 8
Fw-1: R55, HFA 17

Randomly Cluster seems to stop forwarding traffic.

The command "cphaprob state" shows no problem on the cluster:

Cluster Mode: Load Sharing (Multicast)

Number Unique Address Assigned Load State

1 (local) 172.16.29.1 50% active
2 172.16.29.2 50% active

I don't know if this is normal, but when the cluster is experiencing this problem, the "OLD-BROADCAST" traffic comes on all interfaces and not only on the sync interface.

The only way to overcome the issue is doing "cphastop" on a member and
lets the remaining node to switch all the traffic.

Checkpoint support is investingating (poorly) the issue while my boss call me every minute....

Any idea ?

Kind regards
Reply With Quote
  #2 (permalink)  
Old 2006-06-05
chelleshame chelleshame is offline
Junior Member
 
Join Date: 2005-10-10
Posts: 1
Rep Power: 0
chelleshame has an average reputation (10+)
Default Re: Trouble with ClusterXL loadsharing multicast mode

Hi,

Are you running smartdefense ?

I have a similar problem on ipso 3.9 NGX(R60) HFA_03 (load sharing) - For me seems to be related to smartdefense.

I encounter many issues (web pages not responding) as soon as I turn on any instant Messaging defenses and/or P2P defenses. Smart tracker does not show anything.

Last edited by chelleshame; 2006-06-06 at 00:03.
Reply With Quote
  #3 (permalink)  
Old 2006-06-12
seanmac1904 seanmac1904 is offline
Member
 
Join Date: 2005-09-04
Location: Perth
Posts: 40
Rep Power: 0
seanmac1904 has an average reputation (10+)
Default Re: Trouble with ClusterXL loadsharing multicast mode

Hi Our cluster has been much more stable since adding the following to the bottom of the /etc/system file

we run Solaris 9

set fw:fwsm_prevent_dangerous_send=2

also make sure that IGMP snooping is off on all interfaces

in cisco world

no ip igmp snooping

hope it helps

Sean
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:48.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0