CPUG  

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1.  Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
2.  CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
     Courses Starting 5/12, 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3.  We have new forums in Portuguese and German (see below).
4.  Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5.  Join Us On LinkedIn - We now have a CPUG group


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-25
vijayant vijayant is offline
Member
 
Join Date: 2006-05-24
Posts: 90
vijayant has an average reputation (10+)
Default CLI for changing priority of gateways

Hi

We have a remote site with R60 Cluster. At times it happenes that the primarry firewall misbehaves and we lose connectivity to the network behind that firewall. as it is not totally down so secondary do not take over. As we could not access the Smart center server at this moment but the firewalls are still accessible (SSH). So pl tell me the command that I can run on any one of these to change its priority.
Reply With Quote
  #2 (permalink)  
Old 2008-03-25
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 268
Thorpuse has an average reputation (10+)
Default Re: CLI for changing priority of gateways

the cphaprob command can be used to set arbitrary fail/restore conditions - look n he ClusterXL documentation for details.

However I think your Cluster setup is the problem - any failure on the primary of connectivity should trigger a failover event - it sounds like your state sync or interface polling is not working correctly. I'd debug that first.
Reply With Quote
  #3 (permalink)  
Old 2008-03-26
vijayant vijayant is offline
Member
 
Join Date: 2006-05-24
Posts: 90
vijayant has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Thorpuse

It dont seem to be cluster issue.. please check my previous post

Connectivity Breaks with High Ping response

also when we reboot primary the failover takes place..
Reply With Quote
  #4 (permalink)  
Old 2008-03-26
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 268
Thorpuse has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Is state preserved during failover?
Reply With Quote
  #5 (permalink)  
Old 2008-03-26
vijayant vijayant is offline
Member
 
Join Date: 2006-05-24
Posts: 90
vijayant has an average reputation (10+)
Default Re: CLI for changing priority of gateways

I am not sure about that, as the connectivity is already down and we reboot the primary... so no idea.

I could not find the required command. Please tell me ..

Last edited by vijayant : 2008-03-27 at 03:07.
Reply With Quote
  #6 (permalink)  
Old 2008-03-27
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 268
Thorpuse has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Do a controlled failover - cphastop on the primary would do it. Have a state-sensitive application running (e.g. FTP) at the time, and see if the connection is affected. If the FTP stops, then your state sync is broken. Fix that, and everything else should start going.

Also, are you using multicast or broadcast for cluster control protocol?
Reply With Quote
  #7 (permalink)  
Old 2008-03-27
vijayant vijayant is offline
Member
 
Join Date: 2006-05-24
Posts: 90
vijayant has an average reputation (10+)
Default Re: CLI for changing priority of gateways

Thorpuse

Sorry I could not test that way. Its in production, need multiple levels of approval. So isnt there any command etc to check the state sync. CCP is default so Multicast
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:35.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0