CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-19
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default ARP Issue with cluster as default gateway for client?

Hi Folks,
I have an issue with a checkpoint ClusterXL cluster acting as a gateway for a number of clients. This is a new setup so we've not had it working before. We are using Sunfire V210 boxes with Solaris 10 as the OS and Checkpoint R65. The Cluster is HA/New braodcast mode. No 3rd party utils are installed.

We have created an interface on the two cluster nodes with a VLAN and configured the clients correctly. However the clients can't route using the cluster IP as the gateway. If I change the gateway to one of the cluster node IP's everything works fine!

I cannot ping the cluster IP from a client on that subnet (but can ping the nodes), I can ping the cluster IP from a client on another subnet. It's very confusing. The topology is all correct as far as i can see.

Running a few snoops on the interfaces, the cluster nodes see ARP whois requests being broadcast from the client, but dont respond to them. They do respond to their individual IP's though. As I mentioned the cluster interface is up and working as I can ping it from another subnet fine.

I'm not sure what i've done wrong but if anyone could offer some pointers it would be appreciated.

Last edited by GordonCopestake; 2007-09-20 at 00:52.
Reply With Quote
  #2 (permalink)  
Old 2007-09-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

What platform is this on?
Reply With Quote
  #3 (permalink)  
Old 2007-09-19
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

Sorry, knew I would miss something! It's Solaris 10 and Checkpoint R65
Reply With Quote
  #4 (permalink)  
Old 2007-09-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

Sorry I haven't really worked with Solaris, however are using ClusterXL for the cluster or do you have a third party ha solution.

I can't recall if ClusterXL runs on Solaris, maybe another of the Solaris users can clarify

I have seen similar issues on Nokia if the Dashboard configured with ClusterXL rather then set to third party and then Nokia VRRP, which is why I ask the question about ClusterXL
Reply With Quote
  #5 (permalink)  
Old 2007-09-19
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

Sorry, yes we are using Cluster XL

I'll amend my original post to contain more detail
Reply With Quote
  #6 (permalink)  
Old 2007-09-19
Junior Member
 
Join Date: 2006-06-02
Posts: 24
Rep Power: 0
rugby1725 has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

What cluster mode are you using. Are the gateways plugged into the same switch or 2 with a VLAN between them. If you are using Load Sharing with multicast mode it sounds like you don't have the settings right on the switch.
Reply With Quote
  #7 (permalink)  
Old 2007-09-20
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

We are using HA/New and the 2 nodes are plugged into different switches with a VLAN for redundancy. We didn't want the switch to be a single point of failure. As far as I know the switch setup is fine. We have changed from Multicast to Broadcast in an effort to get this to work with no success.
Reply With Quote
  #8 (permalink)  
Old 2007-09-20
Junior Member
 
Join Date: 2006-06-02
Posts: 24
Rep Power: 0
rugby1725 has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

Are you sure you have your netmasks correct on all of the clients and gateways. Also, when you were setup for multicast did you put the multicast arp entry in.
Reply With Quote
  #9 (permalink)  
Old 2007-09-21
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: ARP Issue with cluster as default gateway for client?

I have resolved this issue by stripping all the interfaces off one node, rebooting, then re-building the interface list. Fail over and repeat for the other node. I must have done something wrong as it works now, but for the life of me I can't see what. All subnet masks were correct and all broadcasts etc were correct. Confusing, but at least it works!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 04:08.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0