| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| We have a Cluster XL (R65) setup with 2 nodes running Solaris 10 (working perfectly). We want to setup a DHCP server on one of our windows boxes and use the firewall cluster as a DHCP relay agent to forward the broadcasts on the various VLAN's to the DHCP server. We have a similar setup at a different site working perfectly with a single firewall node. When we attempt to setup the same config on the cluster we get dropped packets in tracker with the message: "Connection contains real IP of NATed address" Can anyone give us some pointers as to how to go about correctly setting up a DHCP relay agent on a cluster? We currently have the relay agent setup on both nodes, is this the correct config? Is this even a config that checkpoint supports? As I said, it works perfectly with one node but in a cluster it fails. Any help would be appreciated. |
| |||
| No thoughts folks? Would this work better if the DHCP relay agent was only on the active node? I assume that the issue is to do with the internal NAT'ing between the actual node IP and the cluster IP? |
| |||
| For reference to anyone having the same problem: I believe I have fixed this by adding a NAT rule that disables NAT from any object to my DHCP server. so: ANY, DHCP SERVER, ANY, ORIGINAL, ORIGINAL, ORIGINAL, ANY |
![]() |
| Thread Tools | |
| Display Modes | |
| |