CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-08
lbraid lbraid is offline
Member
 
Join Date: 2007-06-12
Posts: 30
Rep Power: 0
lbraid has an average reputation (10+)
Default secondary FireWall-1 module

We have 2 ip560 nokia's, one primary and one seconary using VRRP active/standby - (NGX R61)
We tried a test failover to the secondary which was fine.

But everytime it gets to 2 hours it stops passing traffic. We have no errors reported on the system?

Has anyone experienced this before?

Regards

Lee
Reply With Quote
  #2 (permalink)  
Old 2007-11-08
donshoutarp donshoutarp is offline
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 4
donshoutarp has an average reputation (10+)
Default Re: secondary FireWall-1 module

I'd check to make sure the multicast packets from the active are getting thru to the secondary. I've seen cases where layer 3 switches sometimes stopped sending the packets. I know that there are commands, for example, in Cisco that keeps the packets flowing, but I always try to find a pure layer 2 switch.
Reply With Quote
  #3 (permalink)  
Old 2007-11-09
lbraid lbraid is offline
Member
 
Join Date: 2007-06-12
Posts: 30
Rep Power: 0
lbraid has an average reputation (10+)
Default Re: secondary FireWall-1 module

It's when on the secondary unit that the traffic stops passing after 2hours and the outbound connections are on layer 2 switches. We have to fail back over to the primary.

But now we want to sort this issue out just in case we do have real issue and the secondary device will only past traffic for 2 hours.

Regards

Lee
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:03.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0