CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-08
Junior Member
 
Join Date: 2006-08-14
Posts: 13
Rep Power: 0
highpoint_1 has an average reputation (10+)
Default Master not passing traffic in Vrrp

Hi All

In a Vrrp setup, master seems to lock up and stops passing traffic, during this time the slave doesn't take over until the master is rebooted. Once the master comes back up, its able to assume responsibility, what are the troubleshooting steps to take in this situation.

thanks
Reply With Quote
  #2 (permalink)  
Old 2006-09-08
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: Master not passing traffic in Vrrp

Check if can reach all interfaces from both firewalls with icmp where VRRP is configured. When master locks up, are all interfaces on backup in backup state or are some in master????
Reply With Quote
  #3 (permalink)  
Old 2006-09-08
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 4
donshoutarp has an average reputation (10+)
Default Re: Master not passing traffic in Vrrp

You could look in messages to see it there are any errors. I would also make sure that your ISPO (assuming you are using Nokia) is at the latest rev for your release and that you are on the latest HFA for Checkpoint.

Can you provide some details of your configuration?
Reply With Quote
  #4 (permalink)  
Old 2006-09-12
Junior Member
 
Join Date: 2006-08-17
Posts: 5
Rep Power: 0
mmuessig has an average reputation (10+)
Default Re: Master not passing traffic in Vrrp

In VRRP-HA constellation there are IMHO two reasons for backup-instance to take over:
- no vrrp-advertisements are seen from any vrrp-configured interfaces
- vrrp-advertisements are seen with lower prio than the own

If so, backup should start to send vrrp-advertisements with its prio. As they are higher, "old master" should stop sending vrrp-advertisements, become backup and "old backup" should become master.

Check your vrrp traffic on external and internal clusterinterfaces on both machines (four interfaces in summary) and pay special attention to prios in vrrp-packets.

To do so run from a console:

tcpdump -i <clusterinterface> ip proto 112

If master/backup state is clear, only master should send advertisements. You will see them only from physical interfaces source address, not from virtual cluster ip.

kind regards
Reply With Quote
  #5 (permalink)  
Old 2006-09-14
Junior Member
 
Join Date: 2006-08-14
Posts: 13
Rep Power: 0
highpoint_1 has an average reputation (10+)
Default Re: Master not passing traffic in Vrrp

thanks for all your input, apparently there was a rogue machine with the same ip address causing the master to lock up, once this was turned off the master is functioning normally

thanks
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:39.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0