CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-07
Junior Member
 
Join Date: 2007-02-06
Posts: 15
Rep Power: 0
Bongoboy has an average reputation (10+)
Default Clustering with Ipso 4.2 and R62

Im using R62 on nokias running Ipso 4.2.
Having set up vrrp on the nokias using 2 real and them sharing a vip I cant get the VRRP to settle down .

On one of the nokias I have loads of Tx Advertisments - incrementing, No Rx Advertisments (those I have seen are Rx Bad advertisments)

On the other nokia - I have loads of Rx Advertisments - incrementing, No Tx advertisments at all.

In essence VRRP isnt at all happy.
Has anyone has similar experiences and can point me in the right direction :

I have already removed the f/w policy to ensure nothing is being blocked.
Added rules so that each firewall can accept packets to the VRRP multicast address.
Tried both lagacy and simplified mode.
Eliminated the switch infrastructure in between by using a cross over cable between the two firewalls.

Any ideas would be well received.
Many thanks
Reply With Quote
  #2 (permalink)  
Old 2007-08-07
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Clustering with Ipso 4.2 and R62

Not trying to be insulting but just like to confirm that ClusterXL isn't ticked on the Check Point cluster object. I had a case very similar to yours that was caused by this. Just unticked the ClusterXL and set the 3rd Party to Nokia VRRP and pushed policy and away it went happily.

Other things I would check is the VRRP Monitor on the Nokia and what it says are the status of the interfaces. I have had a couple of cases where the Nokia refused to come out of initialising until I unconfigured the VRRP and readded the config.
Reply With Quote
  #3 (permalink)  
Old 2007-08-07
Junior Member
 
Join Date: 2007-02-06
Posts: 15
Rep Power: 0
Bongoboy has an average reputation (10+)
Default Re: Clustering with Ipso 4.2 and R62

Hi!
I had tried to disable the Cluster XL on the Cluster object to no joy....
however :-

I disabled it again,
Deleted VRRP config from both Voyager sessions, Saved all.
Pushed policy then reset both firewalls and its all good and is now working!

Many thanks for taking the time to reply your help has made my day!
all the best
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 04:39.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0