| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I've got a question about ClusterXL HA & how the standby server actually takes over. Those of you who are more experienced w/ Checkpoint FW's (1st timer here) can likely push me in the right direction. Platform: NGXR65 on SPLAT. - Brand-new config...building from ground up. - 2 identical hosts with 5 NICs per server, 1 on each dedicated to synchronization network via X-over between hosts. My question/problem: I run steady pings to the VIP of the internal interface and they respond. I then do a "stop member" on the active member via SmartView Monitor. I can no longer ping the VIP until I "start member" on what was the primary member. (SmartView Monitor & cphaprob state on secondary server both verify that the secondary is now the primary, fyi). - Gratuitous ARP turned off on switch (Extreme Networks X450-a) - IGMP Snooping turned off on same switch I did a packet capture when I do the "stop member" and I see gratuitous ARP's coming from the "new" primary server for the VIP....but it never seems to actually grab the VIP address & start responding. I'm figuring I'm just missing something obvious here, which is why I'm posting this. Any ideas? Do I have to do anything w/ static ARP entries on the Gateways? I don't think I do (haven't found anything that says so), but I'm unsure. I've scoured the ClusterXL Admin Guide & these very CP forums, and haven't run across anything like my particular situation. Thanks way in advance, Jay |
| |||
| Well, I think I figured out my own problem. It appears to have been a flaw in my ruleset. I was only allowing SSH & ICMP from the smartcenter server to the internal interfaces of the FW's. (these are the ones i've been testing fail over with). I had a rule below that denying all other traffic to these interfaces. Once I created a rule for the 2 interfaces in question to allow ANY between them, fail over now works just fine. I didn't think I had to specify that in my rules. I'm assuming I'm going to have to do this for all the interfaces on the Clustered FW's. |
![]() |
| Thread Tools | |
| Display Modes | |
| |