CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-21
longname longname is offline
Junior Member
 
Join Date: 2006-08-11
Posts: 14
Rep Power: 0
longname has an average reputation (10+)
Default Nokia IPSO cluster only support Checkpoint Load Sharing?

2x Nokia IP530 work as cluster, IPSO3.6-FCS14
Checkpoint: FP3
In Nokia part, use muticast mode cluster configuration
In Checkpoint, use High Availability mode

Now we have problem with this configuration. VPN and OWA are very slowly. And If we shutdown one firewall, VPN and OWA are very fast.
One Nokia reseller give us a suggestion that he think for muticast mode IPSO cluster should choose checkpoint with Loading sharing not High Availability.
But with this configuration, we work fine for about 12 months. Anyone suggestion?

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2006-08-21
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Nokia IPSO cluster only support Checkpoint Load Sharing?

It might be working, but your Nokia reseller is correct - if you are running IP clustering on your Nokia boxes, your setting in SmartDashboard should be Load Sharing. Not sure exactly what it looks like on your version, but in R60, the cluster object should have ClusterXL unchecked in the General Pane, then under 3rd party configuration, it should be Load Sharing, Nokia IP Clustering.

High Availability is for VRRP.

I wonder if your slowness is due to problems synchronising connections between the nodes? If VPN and OWA are very slow, then things are not working fine, are they?
Reply With Quote
  #3 (permalink)  
Old 2006-08-21
longname longname is offline
Junior Member
 
Join Date: 2006-08-11
Posts: 14
Rep Power: 0
longname has an average reputation (10+)
Default Re: Nokia IPSO cluster only support Checkpoint Load Sharing?

Thanks for your reply.
Base on this configuration, we work fine for nearly one year. But don't know what reason, it has problem only with VPN and OWA. All inside connection (Our firewall like a big router ) are ok.

For Nokia configuration:
1. heartbeat line configure as primary cluster line. Heatbeat line connect through a small hub which only connect two nokia IP530.
2. We have a small network which connect two nokia and managment server. But for this network, not configure with cluster IP.
Reply With Quote
  #4 (permalink)  
Old 2006-08-21
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Nokia IPSO cluster only support Checkpoint Load Sharing?

Just to clarify, do you have both your Check Point synchronisation network, and your primary Nokia synchronisation network using the same interfaces on your cluster, through a hub?

Having a separate network with just your management station on it, and no cluster IP, is not a problem (well, assuming your management server doesn't need to route beyond the firewalls).

If I was in your situation, here's some things I would do:

1/ Have a look at the output of cphaprob syncstat and fw ctl pstat. Look for retransmissions, missing updates, dropped by network, etc. If those numbers are looking high, then that won't be helping.

2/ Related to the above, replace that hub with a pair of switches. Configure two separate VLANs on the switch. Configure a secondary Nokia synchronisation network. Then configure Check Point to use the secondary Nokia sync network as its primary sync network, and the primary Nokia sync as its secondary - make sense? So each one has its own primary sync network, but will fail over to use the others network if required. That should deal with any network-related issues.

3/ Change your cluster config in SmartDashboard to be Load Sharing. Regardless of if things have worked OK, you've got a problem with OWA and VPNS, and this is a definite misconfiguration.

4/ While looking over the cluster, check all interfaces for errors - check the Ierrs and Oerrs columns in the output of netstat -in. If you've got any, resolve them.

4/ All of the above can be done in a day or so. No guarantees that it will resolve your specific issue, but you should get better performance out of it. You then need to start thinking about your future path though - I'm guessing you're running FP3, which is the last one supported by Check Point - i.e. soon it will be out of support. I would look to upgrade to a newer version of IPSO and Check Point. Primarily to get IPSO upgraded to take advantage of the improved clustering code. This will take a bit more effort though, and more testing (and maybe more $ too).

Out of interest, how busy is your firewall? i.e. typical CPU/memory/throughput/concurrent connections?
Reply With Quote
  #5 (permalink)  
Old 2006-08-22
longname longname is offline
Junior Member
 
Join Date: 2006-08-11
Posts: 14
Rep Power: 0
longname has an average reputation (10+)
Default Re: Nokia IPSO cluster only support Checkpoint Load Sharing?

Thank you for your reply.
For your question, my firewall 's work load is not so high. CPU usage normally below 25%, and Memory Usage normally about 92%

Last edited by longname; 2006-08-22 at 02:59.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:42.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0