CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-07
diago diago is offline
Junior Member
 
Join Date: 2006-11-05
Posts: 24
Rep Power: 0
diago has an average reputation (10+)
Default Problem adding additional clustered interface

We are running CheckPoint NGXR60 (splat on enforcement points / Windows on SmartCenter Server) and have had difficulties adding an additional clustered interface (to be used as a DMZ) to our cluster which has been running flawlessly until now.

The problem: after connecting a Cisco 2900XL series switch to each enforcement point NICs (and locking both switch and enforcement point interfaces to 100/Full I check the enforcement points and both show the interface as up. I then go into the cluster topology in the smartdashboard and add the following as a new interface:

Enforcement Point 1: 192.168.25.1/24 (internal)
Enforcement Point 2: 192.168.25.2/24 (internal)
Virtual IP: 192.168.25.3/24 (internal)

After installing the policy I lose connectivity to another DMZ we have connected to another interface (but not all other DMZs - we have several), which is a similar range - to the above address we're using (eg. 192.168.23.0/24). If I check the enforcement points the route for 192.168.25.0/24 has been automatically added and appears ok. I then have to backout the topology changes for the other DMZ to come back online.

Has anyone got any suggestions as to what the problem could be?

Thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 2006-11-08
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 811
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Problem adding additional clustered interface

You say that you are losing connectivity to another DMZ - could you be more specific in what you mean here? Are those interfaces still up? Are they still passing traffic - look at tcpdump/fw monitor. What do your logs say?

I think you've got some topology issues. Do the names of the interfaces in SmartDashboard correspond EXACTLY with the names at an OS level?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:04.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0