CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-10
lserge lserge is offline
Junior Member
 
Join Date: 2006-07-10
Posts: 1
Rep Power: 0
lserge has an average reputation (10+)
Default Routing to the standby cluster member

Hi guys!
Could you please help me with such situation:
NGX R60, HFA 03, Cluster HA
FW1 has 4 interfaces, FW2 has 5. Unused interface described in the discntd.if. Cluster is ok.
FW1 is active, FW2 - standby. I need to use non-cluster network behind FW2, but unsucessful...
Example configuration:
FW1 is 192.168.1.1
FW2 is 192.168.1.2 and 192.168.2.2
Cluster is 192.168.1.3
WS1 is 192.168.1.4 and has static routing to 192.168.2.0 through 192.168.1.2. WS2 is 192.168.2.2
I can snoop packets from the WS1 to WS2 on the FW2 interface 1. That's all. No packets on the SmartTracker. No packets on the FW2 interface2....
Any suggestions?
Reply With Quote
  #2 (permalink)  
Old 2006-07-11
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 849
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Routing to the standby cluster member

You could try turning off this setting:

Cluster Object Properties -> Topology -> Enable Extended Cluster Anti-Spoofing

This extended anti-spoofing will drop packets without logging them (much to my delight).

HTH
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:00.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0