CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-25
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default CLI for changing priority of gateways

Hi

We have a remote site with R60 Cluster. At times it happenes that the primarry firewall misbehaves and we lose connectivity to the network behind that firewall. as it is not totally down so secondary do not take over. As we could not access the Smart center server at this moment but the firewalls are still accessible (SSH). So pl tell me the command that I can run on any one of these to change its priority.
Reply With Quote
  #2 (permalink)  
Old 2008-03-25
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: CLI for changing priority of gateways

the cphaprob command can be used to set arbitrary fail/restore conditions - look n he ClusterXL documentation for details.

However I think your Cluster setup is the problem - any failure on the primary of connectivity should trigger a failover event - it sounds like your state sync or interface polling is not working correctly. I'd debug that first.
Reply With Quote
  #3 (permalink)  
Old 2008-03-26
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Thorpuse

It dont seem to be cluster issue.. please check my previous post

Connectivity Breaks with High Ping response

also when we reboot primary the failover takes place..
Reply With Quote
  #4 (permalink)  
Old 2008-03-26
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Is state preserved during failover?
Reply With Quote
  #5 (permalink)  
Old 2008-03-26
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: CLI for changing priority of gateways

I am not sure about that, as the connectivity is already down and we reboot the primary... so no idea.

I could not find the required command. Please tell me ..

Last edited by vijayant; 2008-03-27 at 04:07.
Reply With Quote
  #6 (permalink)  
Old 2008-03-27
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Do a controlled failover - cphastop on the primary would do it. Have a state-sensitive application running (e.g. FTP) at the time, and see if the connection is affected. If the FTP stops, then your state sync is broken. Fix that, and everything else should start going.

Also, are you using multicast or broadcast for cluster control protocol?
Reply With Quote
  #7 (permalink)  
Old 2008-03-27
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Thorpuse

Sorry I could not test that way. Its in production, need multiple levels of approval. So isnt there any command etc to check the state sync. CCP is default so Multicast
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:37.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0