CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-04
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Need help with ClusterXL problem

I need urgent help really fast.

I have a pair of Firewall running NG with AI R55 with HFA_20 on dell
optiplex PCs. FW1 has 1GB of RAM and P4 1.8GHz processor. FW2 has
512MB of RAM and P4. 1.8Ghz processor. Everything is running fine.
in Active/Active load-sharing ClusterXL unicast mode, as seen below:

[Expert@GW1]# cphaprob state

Cluster Mode: Load Sharing (Unicast)

Number Unique Address Assigned Load State

1 (local) 10.1.1.1 30% active (pivot)
2 10.1.1.2 70% active

[Expert@GW1]#
[Expert@GW2]# cphaprob state

Cluster Mode: Load Sharing (Unicast)

Number Unique Address Assigned Load State

1 10.1.1.1 30% active (pivot)
2 (local) 10.1.1.2 70% active

[Expert@GW2]#


Today, I performed "shutdown" on FW2 and upgraded it from 512MB
to 1GB of RAM to match with FW1. After FW2 comes back online,
cpha on FW2 showed as "down" as seen below:

[Expert@GW1]# cphaprob state

Cluster Mode: Load Sharing (Unicast)

Number Unique Address Assigned Load State

1 (local) 10.1.1.1 100% active (pivot)
2 10.1.1.2 0% down

[Expert@GW1]#
[Expert@GW2]# cphaprob state

Cluster Mode: Load Sharing (Unicast)

Number Unique Address Assigned Load State

1 10.1.1.1 100% active (pivot)
2 (local) 10.1.1.2 0% down

[Expert@GW2]#

I repeatedly performed "cpstop;cpstart" on FW2 but no luck.
I even rebooted FW2 several times but cpha on FW2 always
showed as "down". If I removed 512MB of RAM from FW2 and
reboot the firewall, cphaprob on FW2 will work again, as
seen below:

[Expert@GW2]# cphaprob state

Cluster Mode: Load Sharing (Unicast)

Number Unique Address Assigned Load State

1 10.1.1.1 30% active (pivot)
2 (local) 10.1.1.2 70% active

[Expert@GW2]#


Both PCs are identical with the exception that FW1 has
1GB RAM and FW2 has 512MB RAM. Any attempts to upgrade
FW2 to 1GB RAM killed cpha on FW2. Rebooting or cprestart
on FW2 does not resolve the issue.


Anyone has run into this before? Please help.
Reply With Quote
  #2 (permalink)  
Old 2007-12-05
Junior Member
 
Join Date: 2007-02-08
Posts: 2
Rep Power: 0
jaga4india has an average reputation (10+)
Default Re: Need help with ClusterXL problem

Try to replace with single 1GB RAM . I believe it should resove this issue.
Reply With Quote
  #3 (permalink)  
Old 2007-12-05
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Need help with ClusterXL problem

FW1 has 2-512MB RAM = 1GB RAM total
FW2 has 1-512MB RAM = 512MB RAM total.

When I add another 1-512MB to the FW2, I run into
issues. If I remove 1-512MB from FW2, the problem
goes away.

Both boxes use the same identical memory from Dell.
It is not like the box is not booting up, only ClusterXL
issue.

I am trying to understand how replacing with 1-1GB
memory will solve anything.
Reply With Quote
  #4 (permalink)  
Old 2007-12-12
Senior Member
 
Join Date: 2006-12-16
Posts: 161
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Need help with ClusterXL problem

put a gig of ram in the box and change Cluster XL to HA and then reinstall the box. It should take about 30 minutes.
Reply With Quote
  #5 (permalink)  
Old 2007-12-12
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Need help with ClusterXL problem

I don't want to run HA. I want to run Active/Active.
Reply With Quote
  #6 (permalink)  
Old 2007-12-12
Junior Member
 
Join Date: 2006-05-20
Posts: 28
Rep Power: 0
fdamstra has an average reputation (10+)
Default Re: Need help with ClusterXL problem

Quote:
Originally Posted by cciesec2006 View Post
When I add another 1-512MB to the FW2, I run into issues. If I remove 1-512MB from FW2, the problem goes away.
What if you leave only the new 512MB stick of RAM in? Could it be as simple as a bad memory upgrade?

Your symptoms are strange. You could open a ticket with CheckPoint, but we know how that goes.

Have you pushed policy after the memory upgrade? I'd try that first.

If that doesn't work, I expect that something in the initial hardware detection is sticking around and having trouble with the memory upgrade. I'd get a backup, do the memory upgrade, and reinstall.
Reply With Quote
  #7 (permalink)  
Old 2007-12-12
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Need help with ClusterXL problem

"What if you leave only the new 512MB stick of RAM in? Could it be as simple as a bad memory upgrade?"

Then I have no issue.

"Have you pushed policy after the memory upgrade? I'd try that first."

re-push the policy many times. issue remained.

When I upgraded the box to 1GB RAM (2x512MB), I can see the box
has 1GB from the "dmesg" and from "/proc/meminfo" so the splat box
does see 1GB RAM. Why it is not working, I am at a lost.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:13.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0