CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-28
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default fw ctl zdebug - output

Hi People,

wonder is anyone has seen this before...

In short I'm having issues pinging/ssh to the cluster VIP (Simplfied VRRP).
All VPNs seems to be fine....

The output of fw ctl zdebug show the following drops:

fw_log_drop: Packet proto=1 193.##.##.##:2048 -> 85.##.##.##:18473 dropped by fwha_forw_run Reason: Failed to send to another cluster member

cheers

Dan
Reply With Quote
  #2 (permalink)  
Old 2008-04-08
Senior Member
 
Join Date: 2006-12-16
Posts: 161
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: fw ctl zdebug - output

Cluster-member Ping

VPN-1/Firewall-1 does not allow pinging a cluster virtual IP and a real IP addresses of one of the Cluster Members simultaneously. Several tools perform such simultaneous Pings.
There is a solution for this (available since HFA_315), which can be enabled by setting the kernel global parameter fw_allow_simultaneous_ping to "1".

Related solutions:
sk27105 - Verifications performed by VPN-1/FireWall-1 NG with 'Any Any Any Accept' rule.
sk26202 - Changing the kernel global parameters on all platforms.

And make sure you have a rule above the Stealth rule to allow SSH and icmp and http to the firewall from your machine only or a group of admin machines.
Reply With Quote
  #3 (permalink)  
Old 2008-04-08
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: fw ctl zdebug - output

Quote:
Originally Posted by Routerkid1 View Post
Cluster-member Ping

VPN-1/Firewall-1 does not allow pinging a cluster virtual IP and a real IP addresses of one of the Cluster Members simultaneously. Several tools perform such simultaneous Pings.
There is a solution for this (available since HFA_315), which can be enabled by setting the kernel global parameter fw_allow_simultaneous_ping to "1".
This only applies to Windows systems. If you ping from Linux/Unix systems,
Firewall-1 will let you ping both the cluster and member gateways at the same
time.
Reply With Quote
  #4 (permalink)  
Old 2008-04-08
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default Re: fw ctl zdebug - output

I did miss some vital information off this to be fair....

There are 2 external interfaces being used which are allocated Vlans.

It seems the issue might be the fact simplified mode is setup to supply the same Vmac to each interface and causing the switch to throw a benny.

I was going to try and set static Vmacs to see if this resolves it.

Cheers

Dan
Reply With Quote
  #5 (permalink)  
Old 2008-05-24
Junior Member
 
Join Date: 2007-05-29
Posts: 6
Rep Power: 0
rogermilla has an average reputation (10+)
Default Re: fw ctl zdebug - output

Quote:
Originally Posted by Danielpb View Post
Hi People,

wonder is anyone has seen this before...

In short I'm having issues pinging/ssh to the cluster VIP (Simplfied VRRP).
All VPNs seems to be fine....

The output of fw ctl zdebug show the following drops:

fw_log_drop: Packet proto=1 193.##.##.##:2048 -> 85.##.##.##:18473 dropped by fwha_forw_run Reason: Failed to send to another cluster member

cheers

Dan
I encountered the same problem as well when I issue fw ctl zdebug as well.

fw_log_drop: Packet proto=1 x.x.x.x:2048 -> x.x.x.x:27357 dropped by fwha_forw_run Reason: Failed to send to another cluster member
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:28.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0