CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-02
lodown lodown is offline
Member
 
Join Date: 2006-05-05
Posts: 54
Rep Power: 3
lodown has an average reputation (10+)
Default ClusterXL/HA R65 SSH to passive member

All,

I have found that after a new install of R65 on a HA cluster I am now unable to SSH to the passive member. The traffic is accepted, but a session never starts. This has happened on 3 different sets of clusters built by 2 different engineers, so it is unlikely an operator error. Has anyone else experienced this?

lodown
Reply With Quote
  #2 (permalink)  
Old 2007-10-02
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 119
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

No please make sure you have a rule above your stealth rule to allow ssh from certain machines or networks.
Reply With Quote
  #3 (permalink)  
Old 2007-10-02
lodown lodown is offline
Member
 
Join Date: 2006-05-05
Posts: 54
Rep Power: 3
lodown has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

All of the necessary rules are in place, and ssh was working properly before the move to R65. Ticket has been opened with CP.

lodown
Reply With Quote
  #4 (permalink)  
Old 2007-10-02
bglass bglass is offline
Junior Member
 
Join Date: 2007-10-01
Posts: 6
Rep Power: 0
bglass has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

Do a tcpdump on the interface that the SSH connection is going through on the secondary node. It may be hiding its' reply traffic behind the cluster IP causing it to fail. Let me know if that's the case..
Reply With Quote
  #5 (permalink)  
Old 2008-04-09
smps200 smps200 is offline
Junior Member
 
Join Date: 2008-04-07
Posts: 1
Rep Power: 0
smps200 has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

Quote:
Originally Posted by lodown View Post
All,

I have found that after a new install of R65 on a HA cluster I am now unable to SSH to the passive member. The traffic is accepted, but a session never starts. This has happened on 3 different sets of clusters built by 2 different engineers, so it is unlikely an operator error. Has anyone else experienced this?

lodown
i have experienced this . i cant login over ssh into standby node (NGX R61 cluster). I am able to ping it from time to time , like 2 pings are going thru and all others are blocked.
anyone could let me know what this is ? id like to be able to connect onto passive node for backups etc....
Reply With Quote
  #6 (permalink)  
Old 2008-04-09
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 119
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

delete the cluster object and then create a new policy package.


File copy policy to package.

open the new policy and recreate the cluster object.
Reply With Quote
  #7 (permalink)  
Old 2008-04-18
Noidea Noidea is offline
Junior Member
 
Join Date: 2008-04-10
Posts: 8
Rep Power: 0
Noidea has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

Hello,

We have the same problem. When analysing traffic we saw that the passive member is answering with his VIP adress, which causes the next packet to be routed to the Active member, and therefore the connection fails.

This also makes it impossible to do for example NTP updates from the passive member, as he is going to send out his NTP requests using his VIP as source, and the reply will come to the active member.

sk31607 discribes this issue. This seems to be the case from:

VPN-1 Pro (VPN-1/FW-1) NGX R65
VPN-1 Pro (VPN-1/FW-1) NGX R60 (since HFA_05).
VPN-1 Pro (VPN-1/FW-1) NG with AI R55 HFA_19.

To enable/disable this feature, you have to change the global parameter
fwsm_dlpi_notification from '0' (default value) to 1.

Now... In our case, the parameter IS set to 0 ( default ) but the passive module is still sending out requests from it's VIP.

Anyone an idea?
Reply With Quote
  #8 (permalink)  
Old 2008-04-23
crucial crucial is offline
Member
 
Join Date: 2006-03-24
Posts: 49
Rep Power: 0
crucial has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

I often have this same issue. I seem to remember being able to fix it by adding a route, but I don't recall the details. I'd like to figure this out as well.
Reply With Quote
  #9 (permalink)  
Old 2008-04-30
Noidea Noidea is offline
Junior Member
 
Join Date: 2008-04-10
Posts: 8
Rep Power: 0
Noidea has an average reputation (10+)
Default Re: ClusterXL/HA R65 SSH to passive member

The only way we where able to solve it is by creating a nat rule on both modules.

SRC: MODULE DST: ANY PROT ANY / original - original - original

Hope this helps!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:07.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0