CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-04
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default DHCP Relay on a Solaris 10 Cluster XL Setup?

We have a Cluster XL (R65) setup with 2 nodes running Solaris 10 (working perfectly). We want to setup a DHCP server on one of our windows boxes and use the firewall cluster as a DHCP relay agent to forward the broadcasts on the various VLAN's to the DHCP server. We have a similar setup at a different site working perfectly with a single firewall node.

When we attempt to setup the same config on the cluster we get dropped packets in tracker with the message: "Connection contains real IP of NATed address"

Can anyone give us some pointers as to how to go about correctly setting up a DHCP relay agent on a cluster? We currently have the relay agent setup on both nodes, is this the correct config? Is this even a config that checkpoint supports? As I said, it works perfectly with one node but in a cluster it fails.

Any help would be appreciated.
Reply With Quote
  #2 (permalink)  
Old 2007-09-06
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: DHCP Relay on a Solaris 10 Cluster XL Setup?

No thoughts folks? Would this work better if the DHCP relay agent was only on the active node?

I assume that the issue is to do with the internal NAT'ing between the actual node IP and the cluster IP?
Reply With Quote
  #3 (permalink)  
Old 2007-09-17
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: DHCP Relay on a Solaris 10 Cluster XL Setup?

For reference to anyone having the same problem:
I believe I have fixed this by adding a NAT rule that disables NAT from any object to my DHCP server. so:

ANY, DHCP SERVER, ANY, ORIGINAL, ORIGINAL, ORIGINAL, ANY
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:01.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0