CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-01
Junior Member
 
Join Date: 2006-11-13
Posts: 3
Rep Power: 0
Kurgen727 has an average reputation (10+)
Default NGX R61 Adding New interface drops Cluster

NGX 61 2 server (FW3 active , FW4 standby) in an active/standby setup with 8 interfaces Eth0-7.

I previously had eth0-4 configured. Network Interface for eth5 is not yet connected to the switch.

I went into sysconfig on FW4 (standby) to add a connection, config the adapter, to eth5 and poof the whole cluster went offiline. I tried stopping and restarting the member but no luck. I deleted the connection, restarted both gateways and the cluster was restored.

Later that same evening I repeated the procedure, and everything went flawlessly.

-The next day I connected the eth5 interface (only after I ran the command "ifconfig eth5 down") to the switch, and the cluster again crashed.

I finished the cluster config in dashboard, for the new adapters and everything was fine again.

Should adding an adapter (on the standby no less) take down the whole cluster? Is there a way to avoid this? I've never had this happen before.

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-02-02
Senior Member
 
Join Date: 2006-12-16
Posts: 161
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: NGX R61 Adding New interface drops Cluster

Well here are my rules to go by.

1. Do not configure an interface without plugging it in to the switch as Cluster XL will send ccp packets toward this interface and this can cause a interface clapping issue. You can check the control connections in tracker and see if you see any that show recieve up transmit down.

2. If you must configure the interface and do not have the switch in place mark the interface as monitored private and reinstall the policy.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0