CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-08
implain implain is offline
Junior Member
 
Join Date: 2007-05-29
Posts: 3
Rep Power: 0
implain has an average reputation (10+)
Default fw_sync_block_new_conns

I have error in /var/log/message that show below
FW-1: State synchronization is in risk. Please examine your synchronization network to avoid further problems !
FW-1: It is recommended to set the global parameter fw_sync_block_new_conns to 0
FW-1: Please refer to documentation for details on this issue. Any change must be applied to ALL cluster members
FW-1: fwldbcast_recv: delta sync connection with member 1 was lost and regained.58615 updates were lost.
FW-1: fwldbcast_recv: received sequence 0xe99253 (fragm 0, index 1), last processed seq 0xe8ad5b

fw_sync_block_new_conns parameter ,i can not find to edit .Anyone know where the parameter? i try to use guiDBedit to find this parameter but i can't see
Reply With Quote
  #2 (permalink)  
Old 2008-04-08
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 142
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: fw_sync_block_new_conns

This is a kernel parameter and can be set with fw ctl int set sync_block_new_conns 0
Reply With Quote
  #3 (permalink)  
Old 2008-07-31
Testing-123 Testing-123 is offline
Senior Member
 
Join Date: 2007-07-27
Posts: 106
Rep Power: 2
Testing-123 has an average reputation (10+)
Default Re: fw_sync_block_new_conns

Hi,

If you were receiving this message, would it imply your primary firewall is receiving a high throughput and therefore cannot state sync to the secondary? What other log messages can help determine if a firewall is experiencing load issues (except for system utilization reports on box etc)

By default fw_sync_block_new_conns is set to -1 (load detection disabled) so why permanently enable it by setting it to 0?

Am i correct in saying that, setting this variable to 0, you are saying if a firewall is under heavy load, state sync is more important then passing new connections?

Regards
Testing-123
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:36.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0