CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-17
Member
 
Join Date: 2008-04-12
Posts: 53
Rep Power: 1
doccocaubai has an average reputation (10+)
Default Problem with address spoofing on Nokia cluster!!!!

This is my network topology

So I have a problem with adrress spoofing. I used the smartcenter to ping the cluster. Everything is OK except when I ping the outside interface of IP390_2(10.2.0.242), it's said that request time out. And I saw that the checkpoint drop that packet because of address spoofing (I check that in smartview tracker). What can I do? How to fix this problem?
Reply With Quote
  #2 (permalink)  
Old 2008-04-18
Member
 
Join Date: 2006-08-30
Location: Cheshire UK
Posts: 32
Rep Power: 0
coldark has an average reputation (10+)
Default Re: Problem with address spoofing on Nokia cluster!!!!

First and most obvious to me is where is your Smart Centre's Default Gateway Configured? I suspect it is set to IP390_1 Internal NIC. If that is so, then when you ping the EXT NIC of IP390_2 it will route there via IP390_1, and the traffic from your ManagementServer will appear to be arriving at the External Address - but claiming to be sourced from an Internal Address - a classic AntiSpoof situation. If this IS the case, what you should do is set the SmartCenter's Default Gateway to the Internal Cluster IP, and put 2 routes on your SmartCenter:

1) Traffic to IP390_1 External via IP390_1 Internal <======== Allows Management to communicate direct with IP390_1
2) Traffic to IP390_2 External via IP390_2 Internal <======== Allows Management to communicate direct with IP390_2

IF THE ABOVE IS NOT THE CASE - then...

Any chance you could screenshot the Topology Tab of your Cluster Object.

In particular, I mean SmartDashboard go to your Cluster Object > Topology > Edit Topology - take screenshot.

As an aside, and nothing to do with your original question - the two sync nets you have shouldn't normally be specified as Cluster interfaces - I think it is more normal to specify these only as sync interfaces (1st Sync and 2nd Sync).

What type of clustering are you using? VRRP?

Last edited by coldark; 2008-04-18 at 05:24.
Reply With Quote
  #3 (permalink)  
Old 2008-04-18
Member
 
Join Date: 2008-04-12
Posts: 53
Rep Power: 1
doccocaubai has an average reputation (10+)
Default Re: Problem with address spoofing on Nokia cluster!!!!

default gateway of my smartcenter is the cluster ip : 192.168.2.254.
My cluster is running in nokia clustering mode (active-active)
So, how can I fix the ploblem AntiSpoofing?
Reply With Quote
  #4 (permalink)  
Old 2008-04-19
Member
 
Join Date: 2006-08-30
Location: Cheshire UK
Posts: 32
Rep Power: 0
coldark has an average reputation (10+)
Default Re: Problem with address spoofing on Nokia cluster!!!!

Antispoofing is configured on the Cluster Object > Topology Tab - The Antispoof settings are shown when you select "Edit Topology" here is an example:

EXAMPLE ONLY FROM DEMO MODE OF SMARTDASHBOARD



The Antispoof settings are indicated in the Topology Column on the Right Side.

It is a lot easier to offer advice if you put in a screen shot of your current Topology that will show us what your antispoof settings currently are.

As I asked in my previous post this can be done by...

Any chance you could screenshot the Topology Tab of your Cluster Object.

In particular, I mean SmartDashboard go to your Cluster Object > Topology > Edit Topology - take screenshot (ALT>Print Screen).

As an aside, and nothing to do with your original question - the two sync nets you have shouldn't normally be specified as Cluster interfaces - I think it is more normal to specify these only as sync interfaces (1st Sync and 2nd Sync).

What type of clustering are you using? VRRP?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:43.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0