CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-24
pvaneynd pvaneynd is offline
Junior Member
 
Join Date: 2006-10-16
Posts: 5
Rep Power: 0
pvaneynd has an average reputation (10+)
Default ClusterXL: probing on more then one VLAN

Hello,

Recently we noticed the hard way that on a trunked interface ClusterXL (R60 HFA4 on SPLAT) only monitors the lowest numbered vlan. This would be fine if the topology of all vlans would be the same, but they are not: the 2 switched connected to the firewalls do not trunk the vlan between them, but forward them out to two different pairs of switches, one per vlan, and it are these 2nd level switches with have a trunk between them.
The problem is that only one vlan is probed, so if one of the 2nd level switches (or their connections) fail for the second vlan the firewall will not failover and that vlan is down.
On a PIX one can add vlan interfaces to the list of monitored interfaces using "monitor-interface foo". Does a similar tool exist for ClusterXL?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:09.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0