CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-13
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default sync: Inconsistencies

Hi,

Not sure if anyone can help on this but both cluster modules are reporting the following in the Tracker:

sync: Inconsistencies exists between policies installed on the cluster members. Please reinstall the policy on the cluster.

I can re-install the policy fine on occasions on the backup member I receive the following error:

Reason: SmartCenter aborted connection with peer, due to timeout = 600000(mil-sec)(port = 18191) (Ip = ##.##.##.##) (message from 'firewall host name' which is the backup module)

I have double checked voyager and can see the heart beat, plus I have check the Sync interface to make sure i can vrrp packets to 224.0.0.18.
All seems fine and I'm at a loss.

cheers
Reply With Quote
  #2 (permalink)  
Old 2007-07-30
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default Re: sync: Inconsistencies

Hi still seeing these issues...can anyone shed a ray of light?

cheers
Reply With Quote
  #3 (permalink)  
Old 2007-07-31
Junior Member
 
Join Date: 2006-04-27
Posts: 14
Rep Power: 0
nandushankar has an average reputation (10+)
Default Re: sync: Inconsistencies

This occurs when one of the cluster members has already received the new Policy, and the other has not. The first member sends packets on the sync network with new Policy ID. The second member receives them both, and because of Policy inconsistencies, sends the message to SmartView Tracker. When installing the Policy on all cluster members, make sure the option "For Gateway Clusters install on all the members, if it fails do not install at all" is enabled in the "Install Policy" dialog box, before proceeding with the Policy installation. Please try to install the policy on the enforcement module which has not recieved the policy, also check the same using fw stat command to check which is the last policy installed. Please revert back if there is some issues. You can also try using fw unloadlocal on the enforcement module which has old policy and try pushing the policy again.

__________________
Nandu Shankar
CCSA,CCSE,CCSE+,CCMSE,RHCE,CCNA,MCP
Reply With Quote
  #4 (permalink)  
Old 2007-08-01
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default Re: sync: Inconsistencies

Hi thanks for the reply.......

I have done the fw stat command and it shows the same policy was installed, but there is a time difference of about 1 1/2 min..........would this cause the log errors?

cheers

Dan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:41.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0