CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-26
Junior Member
 
Join Date: 2006-05-15
Posts: 8
Rep Power: 0
djmachin has an average reputation (10+)
Default ClusterXL not working when failed over

This is releated to the previous post about ClusterXL in HA mode not working.

We have R60 (HFA03) on two Sun Fire V210's running Sparc Solaris 9.

If I have both nodes (A and B) powered off and power A up and then B, I can get on the internet. If I fail over to node B (using "Stop Member" on SmartView Monitor) I cannot get on the internet from the single laptop connected to the internal interface. If It then cpstart node A and fail it back to A, the laptop can get on the internet fine.

Now if I power both off and start this time with node B, the same pattern follows with the internet always available on node B.

I am using a 10Mb hub for the external interfaces and a Dell PowerConnect 3324 for the internal facing interface. I did initially try a 3COM 3300 switch on the external facing interfaces. I changed to the hub after thinking that it was the switch caching the ARP entry. That does not seem to be the cause of the problem as it is still the same after the swap out.

I have a manual ARP entry (automatic proxy ARP disabled) on each node with the MAC address of the external interface. I also have a single hiding translated rule for the internal network to go out on the internet.

Can anyone suggest anything that seems wrong or is there anything I can try to try and fix this problem?

Thanks to all for your time.
Dave
Reply With Quote
  #2 (permalink)  
Old 2006-06-26
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ClsuterXL not working when failed over

Quote:
Originally Posted by djmachin
I have a manual ARP entry (automatic proxy ARP disabled) on each node with the MAC address of the external interface. I also have a single hiding translated rule for the internal network to go out on the internet.
Why are you not using automatic proxy arp? I suspect that's part of the issue as ClusterXL depends on being able to control the proxy arp.
Reply With Quote
  #3 (permalink)  
Old 2006-06-26
Junior Member
 
Join Date: 2006-05-15
Posts: 8
Rep Power: 0
djmachin has an average reputation (10+)
Default Re: ClsuterXL not working when failed over

Thanks for your reply.

As I understand it, Automatic Proxy ARP is only activated if you used Automatic NAT. As we will be using manual NAT with a corresponding routing table on each node, I thought I may as well disable the Automatic Proxy ARP. If this is wrong then please feel free to correct me.

Thanks
Dave
Reply With Quote
  #4 (permalink)  
Old 2006-06-27
Junior Member
 
Join Date: 2006-06-27
Posts: 4
Rep Power: 0
Error404 has an average reputation (10+)
Default Re: ClsuterXL not working when failed over

You have to DISABLE the automatic proxy arp feature if you use manual arping.

global Properties -> NAT -> Automatic ARP configuration (uncheck this option)

If you do not so, you will have to merge the "automatic arp table" with the manual even if you are not using any automatic arp entries.

See also SK#30197 for the problem
Reply With Quote
  #5 (permalink)  
Old 2006-07-26
Junior Member
 
Join Date: 2006-04-26
Location: US
Posts: 17
Rep Power: 0
scottlsattler has an average reputation (10+)
Send a message via Yahoo to scottlsattler
Default Re: ClsuterXL not working when failed over

also I remember seeing something about if your devices do not support gratitous arps fail over will not work.
Reply With Quote
  #6 (permalink)  
Old 2006-08-22
Junior Member
 
Join Date: 2006-08-22
Posts: 1
Rep Power: 0
Version1 has an average reputation (10+)
Default Re: ClsuterXL not working when failed over

Were you able to find out what the issue was? I have seen the same problem after an upgrade to R60 on Secure Platform.
Reply With Quote
  #7 (permalink)  
Old 2006-10-24
Junior Member
 
Join Date: 2006-10-24
Posts: 4
Rep Power: 0
tolu60 has an average reputation (10+)
Default Re: ClsuterXL not working when failed over

I had a similar problem initially, but turned out that I had the wrong cabled connected to to the wrong interface... also you may want to check the routing table on the cluster members if the cluster addresses are on different subnets to the member interface.
The problem I'm having now (if anyone else has experienced it) is that I'm not able to establish VPN tunnel using SecureClient.
My configuration is this: 6 interfaces on both cluster members, 2 DMZ, 1 synch, 2 external (internet for redundancy), and 1 for internal lan... all cluster member interfaces are on different subnest to the cluster (virtual) addresses with the exception of the internal interface. Internal is on 192.168.50.x which is also same subnet as the cluster IP for that interface...
The strangest thing is I can establish VPN tunnel when I'm on the 192.168.50.x subnet, but not from the internet. I'm guessing this is to do with the internet cluster IP and the member interfaces being on different subnets, but can't quite figure it out. Hope this makes sense?
Reply With Quote
  #8 (permalink)  
Old 2007-03-02
Junior Member
 
Join Date: 2006-05-15
Posts: 8
Rep Power: 0
djmachin has an average reputation (10+)
Default Re: ClsuterXL not working when failed over

We managed to get it working in the end. Using manual NAT in Smart Dashboard was a no go. I needed to do the NAT within each object so that it could use the automatic proxy ARP. After I did that the fail-over started to work fine every time. The main problem was getting my head round the different way of doing the address translation. In our old single FP3 box we did a security policy, address translation and an ARP/Routing table within the OS itself. Using the ClusterXL way just meant that we had to change the way we did things.
Reply With Quote
  #9 (permalink)  
Old 2007-03-23
Junior Member
 
Join Date: 2006-09-29
Posts: 17
Rep Power: 0
hono222 has an average reputation (10+)
Default Re: ClusterXL not working when failed over

Hi,
Sorry to post this here I didn't know where else to post it. Perhaps someone can tell how to post a new message. Anyway the real problem is this:

On Friday of last week we had a power outage since then ALL of the internal virtual ips periodically time out. Like a hiccup. Has anyone had this problem?

Your help would greatly be appreciated.

Thanks
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0