CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-23
cciesec2006 cciesec2006 is online now
Senior Member
 
Join Date: 2006-09-26
Posts: 757
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default ClusterXL unstable

I have a pair of SPLAT R55 w/ hfa20 running on Dell Servers
(P4 2.8 GHz and 1GB RAM) Active/Active ClusterXL. It is
being managed by a CMA inside a Provider-1 NG AI R55 with
HFA_20. The box is not pushing a lot of traffics, only
telnet and http traffics going through a box. There
is only ONE host behind the firewalls. Firewalls has
three interfaces (external, internal and sync interface).
External interface is connected to a hub #1. Internal
interface is connected to hub #2, and sync interface
is connected to hub #3.

Every morning, when I push policy to the cluster,
I am getting this message:

gw1: sys_message: installed ClusterXL
gw2: sys_message: installed ClusterXL
gw1: cluster_info: (ClusterXL) Stopping ClusterXL.
gw1: cluster_info: (ClusterXL) Starting ClusterXL.
gw2: cluster_info: (ClusterXL) Stopping ClusterXL.
gw2: cluster_info: (ClusterXL) Starting ClusterXL.

It means that my cluster is flapping. If I push
the policy again, I do not see these messages.
However, if I push the policy again an hour later,
I see these messages. It means that my cluster is
unstable.

I did the following to both SPLAT firewalls:

fw ctl set int fwha_freeze_state_machine_timeout 60

However, I still see those messages whenever I push
the policy every morning.

Anyone know what the problem is? Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-10-23
luisrocha luisrocha is offline
Junior Member
 
Join Date: 2006-04-19
Posts: 26
Rep Power: 0
luisrocha has an average reputation (10+)
Default Re: ClusterXL unstable

Are you using Multicast or Unicast Load sharing, by your descruption, it seems a problem with Multicast addresses and the switches you are using.

If you are using Multicast, does the switch have IGMP disable ?

Try to take a look at this articles:
Using ClusterXL with IGMP Snooping-enabled switches
Solution ID: #sk33221

Interface flapping in a Load Sharing ClusterXL R55 environment
Solution ID: #sk30822


Regards

Luis Rocha
Reply With Quote
  #3 (permalink)  
Old 2007-10-23
cciesec2006 cciesec2006 is online now
Senior Member
 
Join Date: 2006-09-26
Posts: 757
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL unstable

1) If you read my email carefully, I am using hubs, NOT switch.
Therefore, multicast or unicast will work on hubs because the hub
is a broadcast domain.

2) I am using ClusterXL Unicast load-sharing.

What you suggested does not apply in my situation.

Regards
Reply With Quote
  #4 (permalink)  
Old 2007-10-23
pat13b pat13b is offline
Senior Member
 
Join Date: 2007-05-25
Posts: 124
Rep Power: 2
pat13b has an average reputation (10+)
Default Re: ClusterXL unstable

Hello,

Not sure if this helps or even applies to your situation.........

Broadcom NICs causing system problems in a Multi-CPU, SecurePlatform, ClusterXL configuration Print this Solution

Solution ID: #sk31647

Product: ClusterXL, SecurePlatform
Version: NG AI, NG
Last Modified: 10-Apr-2006

Symptoms

Broadcom network interface cards (mostly on-board a HW Server) in some hardware models cause system problems, for example, freeze, crash etc. These problems are experienced when the following 4 product configuration criteria are in effect for the Security Gateway:
SecurePlatform operating system based machine deployed
Multi-CPU configuration machine deployed
ClusterXL solution established (cluster mode irrelevant)
The Performance Pack acceleration module is activated.


Cause

The Broadcom network interface card (NIC) caused problems are rooted in a clash between the NIC driver and the Linux kernel version that is used prior to version NGX.

Solution

Any one of the following 3 suggestions will eliminate this problem:

Disable the Broadcom NIC (e.g via BIOS setting) and replace it with a NIC of a different manufacturer (e.g. Intel).

Only use a Single-CPU configuration. Implement the
Single-CPU configuration either by removing/disabling the necessary number of CPUs or by deactivating the Performance Pack module.

Upgrade Security Gateway to version VPN-1 Pro/Express NGX. The Broadcom NIC caused problems are resolved in version NGX.


-pat13b
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:55.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0