CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-25
s_baugh23 s_baugh23 is offline
Junior Member
 
Join Date: 2006-02-16
Posts: 3
Rep Power: 0
s_baugh23 has an average reputation (10+)
Default HA Nokia Cluster topology

Hi

I have an existing HA nokia pair running VRRP over multiple interfaces which is working. I fail to see any VRRP advertisements when I configure additional interfaces and add them into the cluster topology.
The original interfaces are working but the newly created interfaces are not, Any helpe would be greatly appreciated.

Cheers
Reply With Quote
  #2 (permalink)  
Old 2006-10-25
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 776
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: HA Nokia Cluster topology

Just to clarify, what steps have you followed?

You should have created the new interfaces using IPSO, then added the necessary VRRP config.

You should also have updated the cluster definition in Smart Dashboard, and updated each of the objects, and pushed policy.

Run fw monitor if you think that IPSO is generating the traffic, but Check Point is blocking it.

What does Voyager show under Monitor -> VRRP -> Interfaces?
Reply With Quote
  #3 (permalink)  
Old 2006-10-25
s_baugh23 s_baugh23 is offline
Junior Member
 
Join Date: 2006-02-16
Posts: 3
Rep Power: 0
s_baugh23 has an average reputation (10+)
Default Re: HA Nokia Cluster topology

Hi

Yes, that's exactly what i have done.

ran fw monitor and no VRRP advertisements are seen for the new interfaces

Interfaces dont don't show up in VRRP monitor, even though they have been configured
Reply With Quote
  #4 (permalink)  
Old 2006-10-25
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 776
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: HA Nokia Cluster topology

Are those interfaces actually up?

If the interface is down, it won't show up on the VRRP monitor page.

Otherwise it will show up on VRRP monitor.

Can you post the ifconfig output for that interface, along with fw ctl iflist, and show vrrp interface from iclid?
Reply With Quote
  #5 (permalink)  
Old 2006-10-26
s_baugh23 s_baugh23 is offline
Junior Member
 
Join Date: 2006-02-16
Posts: 3
Rep Power: 0
s_baugh23 has an average reputation (10+)
Default Re: HA Nokia Cluster topology

Just noticed from the logs that IPSRD daemon is complaining as I initially cofigured the new VRRP instances on different interfaces

[admin]# Oct 26 15:01:09 [LOG_ERR] mcvr_xlate[939]: Cannot apply ipsrd configuration: duplicate address 10.132.243.1 on interface eth-s3p2c0 VRID 51 and interface eth-s3p3c0 VRID 51

Oct 26 15:01:31 [LOG_ERR] mcvr_xlate[943]: Cannot apply ipsrd configuration: duplicate address 10.132.244.1 on interface eth-s3p1c0 VRID 51 and interface eth-s3p4c0 VRID 51


Cheers
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:46.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0