CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-07
Junior Member
 
Join Date: 2007-02-12
Posts: 12
Rep Power: 0
mnutriaji has an average reputation (10+)
Default High Availability Slowing Down Network

Hi everyone

need help on High Availability...
I installed Secureplatform R62 in 2 firewall modules(HA-1 and HA-2). I glued them together as New Mode High AVailabilty.
I enabled the State Synchronization and priority to HA-1.

currently iam using single module (no HA configuration), everything works fine. Using bandwidth meter, measurement for inter LAN segmen in firewall can reach up to 90 Mbps.

But, when i applied the HA modules as the replacement of single mode, network performance dropped 50%. The measurement using the bandwidth meter reach up to 40 Mbps only. It is felt by user as well.

I checked in Tracker, everything is fine. Suing command cpstat ha and cphaprob state, everything is OK.
Each firewall port and switch port i set to manual : Full duplex, and speed 10/100.

Is anyone ever experience this? is it possible HA cause this? are there any way i can troubleshoot tis case?

thanks a lot in advance

marendra
Reply With Quote
  #2 (permalink)  
Old 2007-06-07
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: High Availability Slowing Down Network

Are you using new hardware for the HA cluster? I'm assuming the CP version is staying the same, given that no new features (like SD or any SSs) are enabled the cluster shouldn't perform slower then the single gw. I find it out that you manually set the speed / duplex on every interface. Do any of the firewall ports or switch ports list any errors? Does the performance remain bad if you stop HA and test through the active gw?
Reply With Quote
  #3 (permalink)  
Old 2007-06-07
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: High Availability Slowing Down Network

Try to use pivot/unicast/whatever its called mode (The one that's not new mode). Some switches have a hard time with the multi-cast
Reply With Quote
  #4 (permalink)  
Old 2007-06-07
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: High Availability Slowing Down Network

Quote:
Originally Posted by chillyjim View Post
Try to use pivot/unicast/whatever its called mode (The one that's not new mode). Some switches have a hard time with the multi-cast
I think Chillyjim is referring to this CP command:
cphaprob set_ccp broadcast
(to change back, use multicast instead of broadcast)
Reply With Quote
  #5 (permalink)  
Old 2007-06-07
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: High Availability Slowing Down Network

Actually I was thinking of clicking the radio button in the cluster object->clusterxl screen.
Reply With Quote
  #6 (permalink)  
Old 2007-06-08
Junior Member
 
Join Date: 2007-02-12
Posts: 12
Rep Power: 0
mnutriaji has an average reputation (10+)
Default Re: High Availability Slowing Down Network

Quote:
Originally Posted by melipla View Post
I think Chillyjim is referring to this CP command:
cphaprob set_ccp broadcast
(to change back, use multicast instead of broadcast)
do you mean cphaconf set_ccp broadcast/multicast ?
chillyjim, which radio button you're referring to? legacy mode?

thanks

marendra
Reply With Quote
  #7 (permalink)  
Old 2007-06-10
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: High Availability Slowing Down Network

Quote:
Originally Posted by mnutriaji View Post
chillyjim, which radio button you're referring to? legacy mode?
That sound right
Reply With Quote
  #8 (permalink)  
Old 2007-06-26
Junior Member
 
Join Date: 2007-02-12
Posts: 12
Rep Power: 0
mnutriaji has an average reputation (10+)
Default Re: High Availability Slowing Down Network

Phew, Finally
All my HAs are working. But in still i dont know why if the traffic going through trunking, all the network performance that goes thourh firewall cut down to 50%.

My solution are not using trunking at all. and it works

Anyone ever experience any6thing like this before ?

thanks you all for your help

thanks

marendra
Reply With Quote
  #9 (permalink)  
Old 2007-06-27
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: High Availability Slowing Down Network

Quote:
Originally Posted by mnutriaji View Post
if the traffic going through trunking, all the network performance that goes thourh firewall cut down to 50%.
Can you explain a little more on how you came to this conclusion?

Would it affect all traffic passing through the firewall or only packets passing through the trunk port(s)?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:07.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0