CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-02
Member
 
Join Date: 2006-02-05
Posts: 74
Rep Power: 3
jmcgrady has an average reputation (10+)
Default ClusterXL incorrectly says interface is disconnected

I'm running R60 hfa3 on Secureplatform. All is well except that Clusterxl is incorrectly reporting the status for two interfaces (6 total) on both cluster nodes. cphaprob -a if reports eth3 and 3th5 as disconnected, non sync (non secured). However i can ping devices on that interfaces subnet. The OS is happy that the interface is up, why would clusterxl report it as down?

Ive checked topology and netmasks in the cluster object. All looks correct.
Reply With Quote
  #2 (permalink)  
Old 2008-01-03
Member
 
Join Date: 2006-02-05
Posts: 74
Rep Power: 3
jmcgrady has an average reputation (10+)
Default Re: ClusterXL incorrectly says interface is disconnected

Found the issue. There was an old conf/discntd.if file listing the effected interfaces. Deleting that fixed the problem.
Reply With Quote
  #3 (permalink)  
Old 2008-02-05
Junior Member
 
Join Date: 2007-11-02
Location: Prague
Posts: 11
Rep Power: 0
Praetorio has an average reputation (10+)
Default Re: ClusterXL incorrectly says interface is disconnected

Hi.



Unix/Linux:
-------------
1) Run "cpstop".
2) Edit "$FWDIR/conf/discntd.if" with the names of the disconnected interfaces.

NOTE:
If "discntd.if" does not exist you will need to create it.

EXAMPLE:
eth4
eth5
eth6

3) Save changes.
4) Reboot firewall.
5) Repeat the same actions for the other Enforcement Module(s) in the cluster.
Reply With Quote
  #4 (permalink)  
Old 2008-02-05
Senior Member
 
Join Date: 2006-09-26
Posts: 855
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL incorrectly says interface is disconnected

You only need to do this IF you're running NG with AI R55 or lower.
Checkpoint NGx R60 suppose to fix this.

my advise is to open a TAC case with Checkpoint.
Reply With Quote
  #5 (permalink)  
Old 2008-02-06
Junior Member
 
Join Date: 2007-11-02
Location: Prague
Posts: 11
Rep Power: 0
Praetorio has an average reputation (10+)
Default Re: ClusterXL incorrectly says interface is disconnected

Yes, only R55 and lower version, but you can check this procedure for this products and components:VPN-1 Pro/Express NGX R60
VPN-1/FireWall-1 NG with AI R55 HFA_14 and higher ,VPN-1 VSX NGX R60,
ClusterXL Load Sharing mode ,ClusterXL High Availability

In Secure Knowledge can you search for sk31336 -Enabling / Disabling the MILS Feature
Reply With Quote
  #6 (permalink)  
Old 2008-02-06
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ClusterXL incorrectly says interface is disconnected

Quote:
Originally Posted by cciesec2006 View Post
You only need to do this IF you're running NG with AI R55 or lower.
Checkpoint NGx R60 suppose to fix this.
The file is no longer required in R60 and latter, but it is still supported.
e.g. if the interface is listed, it will not be monitored.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0