CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-06
Junior Member
 
Join Date: 2008-02-05
Posts: 5
Rep Power: 0
ipbuckstopshere has an average reputation (10+)
Default VRRP duplicate VIP sourced from standby physical MAC

I am a Checkpoint noob (very familiar with PIX/ASA) just thrown into this thing with no vendor support, so I'm trying to grind my way through this but haven't been successful yet.

I'm running R62 with IPSO 4.2. I have four VRRP interfaces. 3 work fine. However, my internet facing one has problems. Whenever I push the policy, traffic fails through the firewall and I see an log stating there is a duplicate IP. This IP is my VIP for the internet. It sees the VIP sourced from the physical MAC of the secondary firewall. When I push policy a second time, it works fine (but still see the duplicate IP log message).

Isn't VRRP supposed to source the Virtual IP from the virtual MAC?

I also have problems with a redirect rule. port 80 is supposed to be denied and redirected to port 443. This works "intermittently." When it works I see the packet hit the firewall and immediate response and redirect. when it fails, i see the packet hit the firewall and "disappear," no response at all, just like the firewall dropped it, except I can't find any log detailing it ever hit the firewall.
When this is not working, you can manually specify 443 and it works fine... so port 443 works all the time... redirect on port 80 works off and on..

Any suggestions/help is much appreciated.

Thanks!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:06.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0