| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| hi group, i'm using clusterxl in ha-mode (splat, ngx,r60,hfa02), and trying to be a good admin i use ntp (on an a server in the dmz) to sync the time on both. but i've run into a problem: since the last reboot of both cluster-machines time-syncing does not work anymore on the standby-machine :-( i took a look into the logs and see a strange thing: the mashine's ip is hidden behind the virtual cluster-ip. why does this happen? any ideas? thx, stefan Last edited by veste; 2006-07-10 at 03:58. Reason: forgot something |
| |||
| I just checked my ngx cluster (hfa03) and my standby member's ntp requests are not being natted. You should check the logviewer to see which NAT rule it's matching. Maybe it's a bad rule? |
| |||
| Quote:
Service: ntp-udp (123)btw: if i stop the cp-daemons, everything works. weird thing :-( question: how can i see the implied rules in the dashboard? i can't find how. thx!!! |
| |||
| Quote:
View->Implied Rules |
| |||
| Check your 3rd party configuration in your gateway cluster properties and uncheck 'hide cluster members' outgoing traffic behind the cluster's IP address' |
| |||
| Quote:
i've looked into the rulebase: *) there are no implied nat-rules *) there are no nat-rules at all, where something is hidden behind the cluster-ips *) i allow outgoing from local-mashine as "before last" |
| |||
| Quote:
|
| |||
| Quote:
|
| |||
| Seems like you need to add a nat rule to me. rule #1 original packet: src = fw dst = ntp server svc = ntp tranlsated packet: src = original dst = original svc = original rule #2 original packet: src = ntp server dst = fw svc = ntp tranlsated packet: src = original dst = original svc = original |
| |||
| Quote:
that's it! disabled clusterXL, unchecked the hide-thing in 3rd party, checked clusterXL, installed and now ist _W O R K S_ !!! so i don't need the NAT-workaround. thx to all for your help! cheers,s. |
| |||
| Quote:
|
![]() |
| Thread Tools | |
| Display Modes | |
| |