CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-12
rossbird rossbird is offline
Junior Member
 
Join Date: 2006-07-12
Posts: 4
Rep Power: 0
rossbird has an average reputation (10+)
Default Multicast Storm

Hi all,

I am currently having an issue with our firewalls creating mutlicast storms on our switches. We have clustering enabled using a muticast address and have statically entered arp entries into all of our switches so that they accept the multicast address, but when I sniff on any port on the switch I see all traffic being sent to the fw as if I'm on a hub. I've read that enabling multicast mac with IGMP in voyager and IGMP snooping on the switch might resolve the issue. I've also read that muticast mac with IGMP snooping on voyager is a bad idea. My question is how do I resolve the issue of muticast storms on the swtich while still maintaining a clustered environment?

IPSO fwserver1 3.9-BUILD041
This is Check Point VPN-1(TM) & FireWall-1(R) NG with Application Intelligence (R55) HFA_17, Hotfix 670 - Build 005

Any help would be appricated.
Reply With Quote
  #2 (permalink)  
Old 2006-07-12
dbedit dbedit is offline
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: Multicast Storm

It's also possible to run in broadcast mode if you are still having issues. Don't know the exact command anymore, check CLI guide!If you cannot find it let me know.
Reply With Quote
  #3 (permalink)  
Old 2006-07-13
david david is offline
Senior Member
 
Join Date: 2006-06-28
Posts: 140
Rep Power: 3
david has an average reputation (10+)
Default Re: Multicast Storm

cphaconf set_ccp broadcast

need to do a cprestart afterwards for the change to take effect

can then run the command below to verify

cphaprob -a if
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:33.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0