CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-07
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 190
Rep Power: 2
hotice_ has an average reputation (10+)
Default Weird HA Issue: pinging VIP and both Members responding

Running IPSO 4.1 on both firewalls in Cluster configuration...

and we're having two distinct problems right now:

1) On the INTERNAL SIDE: We have two PCs on the same LAN segment pinging the VIP of the cluster....One of the PC is getting an echo reply while the other gets nothing.

TCPDumps shows that exact behavior:

16:00:25.030123 I PC_A > VIP: icmp: echo request
16:00:30.037799 I PC_A > VIP: icmp: echo request
16:00:35.044795 I PC_A > VIP: icmp: echo request
16:00:40.051886 I PC_A > VIP: icmp: echo request
16:00:45.059192 I PC_A > VIP: icmp: echo request
16:00:50.066415 I PC_A > VIP: icmp: echo request
16:00:55.073650 I PC_A > VIP: icmp: echo request
16:01:00.080898 I PC_A > VIP: icmp: echo request
16:01:05.088232 I PC_A > VIP: icmp: echo request
16:01:10.095419 I PC_A > VIP: icmp: echo request
16:01:15.102684 I PC_A > VIP: icmp: echo request
16:01:18.412269 I PC_B > VIP: icmp: echo request
16:01:18.412722 O VIP > 172.26.7.9: icmp: echo reply


2) On the EXTERNAL SIDE, we get a different behavior.

Same PC pinging the external interface (VIP) of the firewall (allowed by rule) and this time BOTH firewalls are responding to the ping request. This is confirmed by the tracker.

The customer has set up a proxy ARP thru Nokia Voyager and set the Virtual MAC address 0:0:5e:0:1:[VRID] converted to HEX.

Has anyone ever encountered this weird problem before?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 03:59.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0