CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-05
n3al10 n3al10 is offline
Junior Member
 
Join Date: 2006-07-28
Posts: 10
Rep Power: 0
n3al10 has an average reputation (10+)
Default multicast vs broadcast is there a performance difference what is better?

I am having issues running R65 Cluster XL UTM 2050 Cluster on multicast.

When I set it to broadcast things work fine. Biggest issue I have seen is alerts that the HA Cluster Sync interface is flapping.

I disabled igmp snooping on the Cisco 2950 switch that the two devices cluster sync interface plugs into but that did not seem to help.

Does igmp snooping need to be turned off on all cisco switches that the firewalls plug into?

Lastly is there a major performance difference of running the cluster in broadcast instead of multicast? Any reason why multicast is better?

It hard to find an answer...
Reply With Quote
  #2 (permalink)  
Old 2008-03-06
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 791
Rep Power: 3
melipla has an average reputation (10+)
Default Re: multicast vs broadcast is there a performance difference what is better?

Quote:
Originally Posted by n3al10 View Post
Does igmp snooping need to be turned off on all cisco switches that the firewalls plug into?
While trying to troubleshoot the cause of one of my interfaces going up and down with support, they told me that every cisco device (even ones not directly connected) should have igmp snooping disabled. They had me set it to broadcast (which it already was) in order to avoid any igmp snooping issues. Whether or not that means its true should probably be answered by someone more familiar with Cisco devices than I.

Quote:
Originally Posted by n3al10 View Post
Lastly is there a major performance difference of running the cluster in broadcast instead of multicast? Any reason why multicast is better?
I think the reason is because its multicasting packets. That means less packets have to be sent in order to communicate status to other gateways in the cluster. In large clusters I could see this as being a benefit.
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 12:52.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0