CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-11
Junior Member
 
Join Date: 2007-06-04
Posts: 12
Rep Power: 0
FDDIcent has an average reputation (10+)
Default Verifying a VRRP cluster

I have two Nokia boxes in a VRRP cluster, the cphad daemon on the primary mysteriously stopped and it failed over to the secondary. I performed a cpstop/start on the primary and then a cpstop on the second unit to fail it back to the correct device. This caused nothing but grief.

Now I'm in the position where what SHOULD be the primary (better hardware) is in secondary, and there's really nothing of note in /var/log/messages. Does anyone have any tips for trouble-shooting clustering? SmartCenter is completely green, cphaprob -i list looks good. Tcpdump of the int shows traffic flowing, I'm not sure what else I can do to verify.

Thanks,

-FDDI
Reply With Quote
  #2 (permalink)  
Old 2007-09-12
Member
 
Join Date: 2007-05-31
Posts: 52
Rep Power: 2
manrag has an average reputation (10+)
Default Re: Verifying a VRRP cluster

What kind of VRRP are you using? IPSO versions? What is the output of
cphaprob list on both members?
Reply With Quote
  #3 (permalink)  
Old 2007-09-13
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Verifying a VRRP cluster

There are some issues with cpha taking up large amounts of resource. I have had a particular problem with this. Apparently is fixed in the latest HFA's.
Reply With Quote
  #4 (permalink)  
Old 2007-09-13
Junior Member
 
Join Date: 2007-06-04
Posts: 12
Rep Power: 0
FDDIcent has an average reputation (10+)
Default Re: Verifying a VRRP cluster

IPSO 3.8 build 58 with HFA12

The primary came back up and thing seem to be running ok, I'm just not sure why stateful fail-over didnt work the first time. Multicast VRRP. Here's a cphaprob -i list:

Primary:


Built-in Devices:

Device Name: IPSO member status
Current state: OK

Registered Devices:

Device Name: Synchronization
Registration number: 0
Timeout: none
Current state: OK
Time since last report: 189608 sec

Device Name: Filter
Registration number: 1
Timeout: none
Current state: OK
Time since last report: 189608 sec

Device Name: cphad
Registration number: 2
Timeout: 5 sec
Current state: OK
Time since last report: 0.9 sec

Device Name: fwd
Registration number: 3
Timeout: 5 sec
Current state: OK
Time since last report: 0.2 sec

---
Secondary

Built-in Devices:

Device Name: IPSO member status
Current state: OK

Registered Devices:

Device Name: Synchronization
Registration number: 0
Timeout: none
Current state: OK
Time since last report: 247183 sec

Device Name: Filter
Registration number: 1
Timeout: none
Current state: OK
Time since last report: 247183 sec

Device Name: cphad
Registration number: 2
Timeout: 5 sec
Current state: OK
Time since last report: 1 sec

Device Name: fwd
Registration number: 3
Timeout: 5 sec
Current state: OK
Time since last report: 0.6 sec

Everything looks ok again at the moment, but it has me a bit concerned. The primary failed sync, secondary took over, primary was brought up with cpstop/start but then a cpstop on the secondary seemed to break fail-over. After a reboot of the primary everything recovered. CP has responded that we might want to increase our NAT cache which is usually full (10,000 entries) or reduce our connection limit which is far larger than our peak connections so as to not starve the kernel.
Reply With Quote
  #5 (permalink)  
Old 2007-09-18
Junior Member
 
Join Date: 2007-03-30
Location: DFW, TX
Posts: 25
Rep Power: 0
Bob_Zimmerman has an average reputation (10+)
Send a message via AIM to Bob_Zimmerman
Default Re: Verifying a VRRP cluster

Quote:
Originally Posted by FDDIcent View Post
IPSO 3.8 build 58 with HFA12
If you're running IPSO 3.8, I'm quite sure you can't be running HFA_12. "R55 for IPSO 3.8" (also called R55P) only goes up to HFA_09. When you run an 'fw ver', it should include the string "R55 for IPSO 3.8". If it doesn't, something is very wrong.
__________________
Robert Zimmerman
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:45.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0