CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-13
doccocaubai doccocaubai is offline
Junior Member
 
Join Date: 2008-04-12
Posts: 13
Rep Power: 0
doccocaubai has an average reputation (10+)
Default Big problem with Clustering!!!

I have a diagram:


I have a big problem with that diagram. At the same time, I just can ping 1 or 2 IP address on nokia. Ex:
I can ping 192.168.2.252, 192.168.2.253 but can not ping 192.168.2.254.
But a moment later, I can ping 192.168.2.254 but can not ping 192.168.2.252 or 192.168.2.253.
And that problem also appear with other interfaces.
I check that cluster working functionally. But that problem still appear. What can I do?
Please, help me!!
Reply With Quote
  #2 (permalink)  
Old 2008-04-13
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 50
Rep Power: 1
eduardw has an average reputation (10+)
Default Re: Big problem with Clustering!!!

Hi,

When your not able to ping one of the nodes, did you see the echo request arriving on the interface of the node (fw mon , or tcp dump). Also check the tracker. When you do not see the incoming echo request you could have an arp problem some where in your network.

I presume that some where in the network is a router which routes the traffic from the smart center to the nodes. If so check the arp time out on this router.
When the problems occurs the try deleting the arp cache on this router, and then check again.


Eduard
Reply With Quote
  #3 (permalink)  
Old 2008-04-13
pat13b pat13b is offline
Senior Member
 
Join Date: 2007-05-25
Posts: 108
Rep Power: 2
pat13b has an average reputation (10+)
Default Re: Big problem with Clustering!!!

I ran into this same problem and it ended up being a multicast problem.

I was doing IPSO clustering and getting different results using diffrent cisco switches. I know it is probably not recommended to go to forwarding mode, but that's how I ended up fixing the problem, and it's been fine ever since.

-pat13b
Reply With Quote
  #4 (permalink)  
Old 2008-04-13
doccocaubai doccocaubai is offline
Junior Member
 
Join Date: 2008-04-12
Posts: 13
Rep Power: 0
doccocaubai has an average reputation (10+)
Default Re: Big problem with Clustering!!!

My cluster is running in forwarding mode. I checked the tracker but nothing concert with arp. And in smartcenter I configured the policy permit any any. But that problem still happen.
Reply With Quote
  #5 (permalink)  
Old 2008-04-13
pat13b pat13b is offline
Senior Member
 
Join Date: 2007-05-25
Posts: 108
Rep Power: 2
pat13b has an average reputation (10+)
Default Re: Big problem with Clustering!!!

Hmmm, Not sure.

- How about topology in check point. Does this look correct?
- Global policy have accept ICMP ?
- looking at voyager "cadmin" does this show anything?

-pat13b
Reply With Quote
  #6 (permalink)  
Old 2008-04-13
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 119
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Big problem with Clustering!!!

put the cluster in broadcast mode with cphaconf set_ccp broadcast command The default is multicast and the cluster mode can be restored to the default by typing cphaconf set_ccp multicast
Reply With Quote
  #7 (permalink)  
Old 2008-04-28
taichan taichan is offline
Junior Member
 
Join Date: 2007-07-04
Posts: 4
Rep Power: 0
taichan has an average reputation (10+)
Default Re: Big problem with Clustering!!!

It's normal (default) that you can't ping both member IPs.

Take a look at the sk33285, there is an option fw_allow_simultaneous_ping

And how you can change kernel parameter on all platforms: sk26202


best regards

Tim
Reply With Quote
  #8 (permalink)  
Old 2008-04-29
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 434
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Big problem with Clustering!!!

Quote:
Originally Posted by taichan View Post
It's normal (default) that you can't ping both member IPs.

Take a look at the sk33285, there is an option fw_allow_simultaneous_ping

And how you can change kernel parameter on all platforms: sk26202


best regards

Tim
As an addition to above explained, be "careful" if you enable this since _every_ icmp request will be logged. So if you send 10 pings to the firewall, all 10 will be logged as individual entry in the log which can make logs grow fast ;-)
Reply With Quote
  #9 (permalink)  
Old 2008-04-29
taichan taichan is offline
Junior Member
 
Join Date: 2007-07-04
Posts: 4
Rep Power: 0
taichan has an average reputation (10+)
Default Re: Big problem with Clustering!!!

Quote:
Originally Posted by abusharif View Post
As an addition to above explained, be "careful" if you enable this since _every_ icmp request will be logged. So if you send 10 pings to the firewall, all 10 will be logged as individual entry in the log which can make logs grow fast ;-)
Hehe and for that, to handle all your log stuff, you can buy Check Points log correlation software (Eventia) ;-)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:22.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0