CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-26
wiz4rd wiz4rd is offline
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Cluster-XL Information Legacy Mode

Hello guys,

I Need to know if under Legacy mode when an fault occour the mac-address is the same on the other memeber.

If I have two nodes ( pivot and standby member) and the pivot goes down, the other memeber will have the same Mac address ?

Is important for me understand well because if I change the pivot member the mac is different and the arp cache needs 10 minute to refresh.

Thank for any reply :)
Reply With Quote
  #2 (permalink)  
Old 2007-02-27
birmingham birmingham is offline
Junior Member
 
Join Date: 2007-02-20
Posts: 7
Rep Power: 0
birmingham has an average reputation (10+)
Default Re: Cluster-XL Information Legacy Mode

I dont know but I if I recall the Cluster XL whitepaper downloadable from checkpoint goes into some detail on things like that.
Reply With Quote
  #3 (permalink)  
Old 2007-02-27
wiz4rd wiz4rd is offline
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: Cluster-XL Information Legacy Mode

Quote:
Originally Posted by birmingham View Post
I dont know but I if I recall the Cluster XL whitepaper downloadable from checkpoint goes into some detail on things like that.
Is not clear on paper :)
Reply With Quote
  #4 (permalink)  
Old 2007-02-27
birmingham birmingham is offline
Junior Member
 
Join Date: 2007-02-20
Posts: 7
Rep Power: 0
birmingham has an average reputation (10+)
Default Re: Cluster-XL Information Legacy Mode

Im not a great MAC address etc expert so maybe misunderstanding you but on page 186 of the cluster xl guide for NGX R62 it says

"In Legacy Mode the cluster members share identical IP and MAC addresses, so that
the active cluster member receives from a hub or switch all the packets that were
sent to the cluster IP address."

Thanks
Birmingham
Reply With Quote
  #5 (permalink)  
Old 2007-02-27
wiz4rd wiz4rd is offline
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: Cluster-XL Information Legacy Mode

Quote:
Originally Posted by birmingham View Post
Im not a great MAC address etc expert so maybe misunderstanding you but on page 186 of the cluster xl guide for NGX R62 it says

"In Legacy Mode the cluster members share identical IP and MAC addresses, so that
the active cluster member receives from a hub or switch all the packets that were
sent to the cluster IP address."

Thanks
Birmingham

Hi Birmingham,

I have NGX R60 but I think that is the same for documentation, the problem is when the pivot node goes down the mac address is of the other node (non pivot) and is a big problem for all session that needs to know the new mac-address. I will try to reboot the node.

Stay tuned

Thank you :)
Reply With Quote
  #6 (permalink)  
Old 2007-02-28
birmingham birmingham is offline
Junior Member
 
Join Date: 2007-02-20
Posts: 7
Rep Power: 0
birmingham has an average reputation (10+)
Default Re: Cluster-XL Information Legacy Mode

Based on the quote from the white paper the mac address should be the same for both members. Are you sure you are not looking at the mac address for the local box ip and mac not the cluster ip & mac it is broadcasting for the cluster which according to the white paper should be the same on both boxes.

I always test failover by putting lots of stuff in a massive zip file and ftping it across the cluster, rebooting the members as it passes through.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:09.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0