CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-26
vijayant vijayant is offline
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 116
Rep Power: 3
vijayant has an average reputation (10+)
Default Synchronisation Problem

Failover takes place successfully.

cphaprob state

1 10.0.0.1 100% active
2 (local) 10.0.0.2 0% down

[Expert@MOON]# cphaprob -ia list

Built-in Devices:

Device Name: Problem Notification
Current state: problem

Device Name: Interface Active Check
Current state: OK

Device Name: HA Initialization
Current state: OK

Device Name: Load Balancing Configuration
Current state: OK

Registered Devices:

Device Name: Synchronization
Registration number: 0
Timeout: none
Current state: problem
Time since last report: 174268 sec

Device Name: Filter
Registration number: 1
Timeout: none
Current state: OK
Time since last report: 41.2 sec

Device Name: cphad
Registration number: 2
Timeout: 2 sec
Current state: OK
Time since last report: 0.1 sec

Device Name: fwd
Registration number: 3
Timeout: 2 sec
Current state: OK
Time since last report: 0.4 sec


For primary all is fine

I can see traffic between Primary and Secondary Firewalls on Sinc interface.---> So its not down.

There are alot of traffic in error between primary and secondary


please check the attachment...

Now where should I dig in ..
Reply With Quote
  #2 (permalink)  
Old 2008-04-21
daz306td daz306td is offline
Junior Member
 
Join Date: 2007-03-06
Posts: 18
Rep Power: 0
daz306td has an average reputation (10+)
Default Re: Synchronisation Problem

I'd be very interested to see replies on this as I am experiencing the same issue and it does seem to be effecting a VPN tunnel we have confgiured on the cluster.

I am tempted to try THIS
__________________
Remember to add to someones reputation if they have helped you, by clicking on their scales icon

Last edited by daz306td; 2008-04-21 at 08:28.
Reply With Quote
  #3 (permalink)  
Old 2008-04-21
daz306td daz306td is offline
Junior Member
 
Join Date: 2007-03-06
Posts: 18
Rep Power: 0
daz306td has an average reputation (10+)
Default Re: Synchronisation Problem

Quote:
Originally Posted by daz306td View Post
I am tempted to try THIS
I'm unable to find a 'mgha' directory on my system (SPLAT)
__________________
Remember to add to someones reputation if they have helped you, by clicking on their scales icon
Reply With Quote
  #4 (permalink)  
Old 2008-04-29
vijayant vijayant is offline
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 116
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Synchronisation Problem

Hi daz306td

Please check for 'mgha' on Smart Center Server.

1 10.0.0.1 100% active
2 (local) 10.0.0.2 0% down

down may indicate a cable issue.

For my case I have registered some of the devices (cphaprob -register) that i supose gave me problem initially. Later I removed it and rebooted but still problem is there. But now I see it is resolved automatically. I dont know how. But now as I ping the peer sync ip from any cluster member, I get very high ing response 450 ms to 9000 ms. I also checked for traffic on sync interface at that time but found nothing. So I suspect it may be the interface issue or the cable may be faulty.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:54.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0