CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-10
CuseHokie CuseHokie is offline
Junior Member
 
Join Date: 2007-02-09
Posts: 3
Rep Power: 0
CuseHokie has an average reputation (10+)
Default Cluster IP instead of Host IP (Radius)

Setup: NG AI R55

Trying to get clustered firewalls to authenticate with radius servers.

We have some of the clusters (all SecurePlatform) sourcing from their host IP address (which is what we want), but we have others sourcing from their shared-IP address.

When adding the "no-nat" rule, the Microsoft IAS server reported that the "NAS-IP address" was then the host, but the "Client IP address" was still the shared...

Anyone have any tidbits or experiences?

It's just bizarre why some clusters are working fine, and some aren't. There must be some setting within the cluster that is causing it to not use the host IP address of the cluster members.
Reply With Quote
  #2 (permalink)  
Old 2007-02-11
CuseHokie CuseHokie is offline
Junior Member
 
Join Date: 2007-02-09
Posts: 3
Rep Power: 0
CuseHokie has an average reputation (10+)
Default Re: Cluster IP instead of Host IP (Radius)

Update to my issue...

On a post somewhere buried on this site, there was mention of disabling a setting under "3rd party configuration".

Apparently, we had to first disable ClusterXL on the cluster object to even see that tab on the left...

Then we were able to go into 3rd party config and not have the firewall modules hide behind the shared IP.

Then we went back to set ClusterXL again...

Anyways, it seems to have resolved our issue...

Seems like a bug though, if enabling ClusterXL hides the 3rd party option, yet the settings within 3rd party still take effect?

Oh well, all is good!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:59.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0