CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-15
kraemer kraemer is offline
Junior Member
 
Join Date: 2005-10-26
Posts: 4
Rep Power: 0
kraemer has an average reputation (10+)
Send a message via ICQ to kraemer
Default Cluster XL - Old or too-new arriving updates

Hi CP-Gurus!
I have some questions to the output of cphaprob syncstat command
on an SPLAT R60 HFA3 Cluster XL:

The output on my platform looks like this:

cphaprob syncstat

Sync Statistics (IDs of F&A Peers - 1 ):

Other Member Updates:
Sent retransmission requests................... 256
Avg missing updates per request................ 1
Old or too-new arriving updates................ 78804199
Unsynced missing updates....................... 0
Lost sync connection (num of events)........... 29
Timed out sync connection ..................... 0

Local Updates:
Total generated updates ....................... 7832822
Recv Retransmission requests................... 124
Recv Duplicate Retrans request................. 138

Blocking Events................................ 0
Blocked packets................................ 0
Max length of sending queue.................... 0
Avg length of sending queue.................... 0
Hold Pkts events............................... 10703181
Unhold Pkt events.............................. 10703181
Not held due to no members..................... 13
Max held duration (sync ticks)................. 1
Avg held duration (sync ticks)................. 0

Timers:
Sync tick (ms)................................. 100
CPHA tick (ms)................................. 100

Queues:
Sending queue size............................. 512
Receiving queue size........................... 256

My general question is aboute the value of:
Old or too-new arriving updates................

In the Cluster XL guide is an hint about the value, that says:
"a large value implys connectivity problems"
But I can't find anything until now in our network.

The next tips are: enlarge the reciving queue or contact the Technical Support ...

Are there any experiences on your side with this problems. Can anyone give some reference values for the reciving queue, perhaps in dependency of the traffic going through an Cluster.
(Our cluster is running in pivot mode)

I am thankful for any suggestions or tips..

Regards
Karsten
Reply With Quote
  #2 (permalink)  
Old 2006-06-16
seanmac1904 seanmac1904 is offline
Member
 
Join Date: 2005-09-04
Location: Perth
Posts: 40
Rep Power: 0
seanmac1904 has an average reputation (10+)
Default Re: Cluster XL - Old or too-new arriving updates

(obvious one)

have you checked the date/time on both of the cluster members ?
ntp running ?

cheers

Sean
Reply With Quote
  #3 (permalink)  
Old 2006-06-16
kraemer kraemer is offline
Junior Member
 
Join Date: 2005-10-26
Posts: 4
Rep Power: 0
kraemer has an average reputation (10+)
Send a message via ICQ to kraemer
Default Re: Cluster XL - Old or too-new arriving updates

Hi seanmac1904,
thanks for your tip. But both cluster members have the identical date and time. Additionaly they are adjusted by NTP.

Regards,
Karsten
Reply With Quote
  #4 (permalink)  
Old 2006-06-16
mmoret mmoret is offline
Member
 
Join Date: 2006-01-04
Location: The Netherlands
Posts: 32
Rep Power: 0
mmoret has an average reputation (10+)
Default Re: Cluster XL - Old or too-new arriving updates

Are the two systems physically seperated?
I had to adjust the Timers by 10 (we run a ClusterXL cluster across a WAN)

regards
Martijn

lawrencium(root)# cphaprob syncstat

Sync Statistics (IDs of F&A Peers - 1 ):

Other Member Updates:
Sent retransmission requests................... 0
Avg missing updates per request................ 0
Old or too-new arriving updates................ 0
Unsynced missing updates....................... 0
Lost sync connection (num of events)........... 1
Timed out sync connection ..................... 2

Local Updates:
Total generated updates ....................... 2161345
Recv Retransmission requests................... 92
Recv Duplicate Retrans request................. 1

Blocking Events................................ 0
Blocked packets................................ 0
Max length of sending queue.................... 0
Avg length of sending queue.................... 0
Hold Pkts events............................... 1584
Unhold Pkt events.............................. 1584
Not held due to no members..................... 66
Max held duration (sync ticks)................. 11
Avg held duration (sync ticks)................. 0

Timers:
Sync tick (ms)................................. 100
CPHA tick (ms)................................. 1000

Queues:
Sending queue size............................. 512
Receiving queue size........................... 256
Reply With Quote
  #5 (permalink)  
Old 2006-06-16
kraemer kraemer is offline
Junior Member
 
Join Date: 2005-10-26
Posts: 4
Rep Power: 0
kraemer has an average reputation (10+)
Send a message via ICQ to kraemer
Default Re: Cluster XL - Old or too-new arriving updates

Hi Martijn,
if the meaning of "physically seperated" is, that the sync is seperated from the rest of the network, the the answer ist yes. We are using two sync-interfaces with crossover cables between the 2 machines.

Can you give me some more background information to your decision to increase the CPHA tick value?

Perhaps I can get some hints in cover of our network environment.

Thank you very much!

Karsten
Reply With Quote
  #6 (permalink)  
Old 2008-04-29
perw07 perw07 is offline
Junior Member
 
Join Date: 2007-03-16
Posts: 2
Rep Power: 0
perw07 has an average reputation (10+)
Default Re: Cluster XL - Old or too-new arriving updates

There is now a description of when this is a non-problem. If you have more than one sync interface, every hit in
Total generated updates
on one system will generate a hit in
Old or too-new arriving updates
on the other system. As long as they "balance", there is no problem.

See also sk34118 with the title Running the cphaprob syncstat command on a cluster member generates unfamiliar output.

/Per Westerlund
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:42.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0