CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-19
Raedm Raedm is offline
Junior Member
 
Join Date: 2006-04-27
Posts: 25
Rep Power: 0
Raedm has an average reputation (10+)
Default VRRP fail over issue

Hi,

I am running a VRRP test, sending an continues ICMP packet (PING command) between an internal and external clients to the ISP. The process would fail over to the secondary FW when the primary goes down. However, opening an FTP sessions between both clients is not failing over when the master goes down.

Notes:
1- I am testing IPSO 4.0 build 40 with NGX R60 HFA_03.
2- the secondary becomes the master after the master gets disconnected.
3- Running an FTP sessions with out the fail over would work fine.
4- Starting another FTP sessions after the master become unviable and the secondary becomes a master would work fine.
5- Smart view tracker showing the following error message when the fail over occurs and the FTP sessions get disconnected " "TCP packet is out of state, first packet isn't SYN tcp_flags:FIN_ACK"


Any suggestions.
Reply With Quote
  #2 (permalink)  
Old 2006-09-19
dbedit dbedit is offline
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: VRRP fail over issue

Any routers running VRRP or just only Nokia's?? Could be a asymmetric routing issue. Is 'synchronize connections on clusters' enabled for FTP service, check properties on service FTP, it should be enabled by default.
Reply With Quote
  #3 (permalink)  
Old 2006-09-19
Raedm Raedm is offline
Junior Member
 
Join Date: 2006-04-27
Posts: 25
Rep Power: 0
Raedm has an average reputation (10+)
Default Re: VRRP fail over issue

Where can I find these options, I looked under voyager and I couldn't find them.

Is 'synchronize connections on clusters' enabled for FTP service, check properties on service FTP, it should be enabled by default.
Reply With Quote
  #4 (permalink)  
Old 2006-09-19
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: VRRP fail over issue

Synchronisation is not a Nokia thing, it's a Check Point thing. Check in Smart Dashboard, not Voyager.

On each node, is synchronisation configured and working correctly? If you run cphaprob state on each module, what output do you get? Does fw tab -t connections -s return similar values for both nodes?
Reply With Quote
  #5 (permalink)  
Old 2006-09-21
Raedm Raedm is offline
Junior Member
 
Join Date: 2006-04-27
Posts: 25
Rep Power: 0
Raedm has an average reputation (10+)
Default Re: VRRP fail over issue

I applied HFA_04 to the smart center and FWs, which corrected the issue.

Thank you for the help.
Reply With Quote
  #6 (permalink)  
Old 2006-10-23
Viggo Viggo is offline
Junior Member
 
Join Date: 2006-08-18
Posts: 4
Rep Power: 0
Viggo has an average reputation (10+)
Default Re: VRRP fail over issue

This is definitely interesting. Did anybody else had this kind of issue with NGX R60 before HFA_04 ?

*scratches head*
Reply With Quote
  #7 (permalink)  
Old 2006-10-23
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: VRRP fail over issue

My guess is that the HFA was irrelevant. It looks to me like synchronisation had never been working properly, and one of the nodes needed to be restarted, which happened during the upgrade.

Since no troubleshooting steps were done (or at least, no results were posted here), and the HFA was just applied, you can't say for certain.

I wouldn't worry about it if I was you Viggo.
Reply With Quote
  #8 (permalink)  
Old 2006-10-26
Viggo Viggo is offline
Junior Member
 
Join Date: 2006-08-18
Posts: 4
Rep Power: 0
Viggo has an average reputation (10+)
Default Re: VRRP fail over issue

Thanks. :)
I´m getting my fair share of trouble with a redundant solution with not one, but two switches (after all, they do want a redundant NETWORK as well, as many people seem to forget) and a pair of Nokias running VRRP (IP Clustering is not an option for now), and I´m using HFA_03. I do want to move to 04 and that seemed like a good reason.

But I agree with you; no way in hell that CP would allow a tough issue with VRRP going flaky for THREE hotfix releases.... right? ;-)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:03.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0