CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-21
GastonBougie GastonBougie is offline
Junior Member
 
Join Date: 2008-01-11
Posts: 3
Rep Power: 0
GastonBougie has an average reputation (10+)
Default Strange behaviour pushing policy to cluster

Hi,
I've set up a vmware network with 2 managements and 2 firewalls.
The managements work ok as active/standby.
The firewalls work ok when they are separate ones.

Now, when I make the 2 separate firewalls as one cluster and want to push the policy to it, it gives me an error messange:
--------------------------------------------------------------


fw-cluster NGX R65 Advanced Security

The Topology information must be configured for object fw01, interface eth0, in order to use the Anti-Spoofing feature.

Warning: Anti-Spoofing is not configured for some interfaces and gateways.
This will allow address spoofing through these gateways.
Anti-Spoofing should be configured on the following objects: Gateway: fw01, Interface: eth0

Operation ended with errors.
--------------------------------------------------------------

I know how to configure anti-spoofing.
Strange thing is. When I edit the topology, and modify fw01, the error message complains about fw02. So when I modify fw02, it complains back to fw01. With modify I mean, change the subnet and IP adres to something different, and change it back diretly, just to provoce him to setup the interface again.

The firewalls are splat installations, nothing special, just a clean install.
It did work before several times, but just now it doesn't and I was curious about why it complains.

In the web-interface I've check every interface and routing settings.
I hope somebody has been there before ;) as I can use any help.

Some edits along the way:
[fw01]# cphaprob -a if
HA module not started.

cpconfig: Enable cluster membership for this gateway

detached firewalls from cluster.
delete cluster
configure topology again on eth0 on both fw's as this dissapears when removing from cluster.
push policy to both firewalls (this goes always ok)
rebuild the cluster,
push policy to cluster, and again the above error.

-------------------------------------------------------------

Problem solved:
In the web-interface, I've entered an extra routing, which I needed for my internal ntp and dns servers to reach.
The route has been tested, and worked ok.
Smartdashboard uses these extra routes also for creating an anti-spoofing group,
so the routed network and the interface network are both included in this anti-spoofing group.. great stuff..all fine.
But for some reason, it doesn't work when I create a cluster with an extra route entered in the webinterface.
So, deletion of the extra route, re-create SIC, recreate fw object and the cluster.... Now everything is fine.

Hope it can help someone... someday.

Last edited by GastonBougie; 2008-04-21 at 08:09.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:07.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0