CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-25
Sharky Sharky is offline
Junior Member
 
Join Date: 2007-05-16
Posts: 12
Rep Power: 0
Sharky has an average reputation (10+)
Default problem LOAD SHARING Multicast

Dear Sirs:

I request assistance with the following item:

I am installing a cluster in LOAD SHARING Unicast and it works OK, and I tried to make the switch to LOAD SHARING Multicast, but at the moment to implement it crashes, I may not send or receive mail.

The configuration at the different devices:

1. Parameters used in SW.

A. Disabling IGMP Snooping

To disable IGMP snooping run:

No IP IGMP snooping



B. Disabling Multicast Limits

To disable multicast limits run:

no storm-control multicast level (On all the interface the SW)

1. Parameter used on the Router

a. Configuring a Static ARP Entry on the Router

arp _._._._ (ip cluster) 01:00:5E:__:__:__ (mac multicast) arpa

Between the cluster check point and the mail server there is a pix, but in this PIX y not set no parameter.

Please, I request your help for find if there is some other parameter, that I need to set up on the Switch, router and/or PIX, thanks for your help.
Reply With Quote
  #2 (permalink)  
Old 2008-04-25
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: problem LOAD SHARING Multicast

Just use Unicast mode, it will save you a lot of problems. Multicast mode is very switch dependent and many will not work with it no matter what you do.
Reply With Quote
  #3 (permalink)  
Old 2008-04-25
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 125
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: problem LOAD SHARING Multicast

I agree new mode ha or unicast load share aka pivot mode will work well.
Reply With Quote
  #4 (permalink)  
Old 2008-04-26
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 540
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: problem LOAD SHARING Multicast

Quote:
Originally Posted by Sharky View Post
Dear Sirs:

I request assistance with the following item:

I am installing a cluster in LOAD SHARING Unicast and it works OK, and I tried to make the switch to LOAD SHARING Multicast, but at the moment to implement it crashes, I may not send or receive mail.

The configuration at the different devices:

1. Parameters used in SW.

A. Disabling IGMP Snooping

To disable IGMP snooping run:

No IP IGMP snooping



B. Disabling Multicast Limits

To disable multicast limits run:

no storm-control multicast level (On all the interface the SW)

1. Parameter used on the Router

a. Configuring a Static ARP Entry on the Router

arp _._._._ (ip cluster) 01:00:5E:__:__:__ (mac multicast) arpa

Between the cluster check point and the mail server there is a pix, but in this PIX y not set no parameter.

Please, I request your help for find if there is some other parameter, that I need to set up on the Switch, router and/or PIX, thanks for your help.
What I keep hearing is that the more expensive your switch is, the less likely it's able to support Multicast mode. Buy a cheap switch or use Unicast mode.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #5 (permalink)  
Old 2008-05-14
Sharky Sharky is offline
Junior Member
 
Join Date: 2007-05-16
Posts: 12
Rep Power: 0
Sharky has an average reputation (10+)
Default Re: problem LOAD SHARING Multicast

Thanks for help. But now I need your help for What is the difference between unicast and multicast conections and pros and cons between both.
Very grateful for your collaboration
Reply With Quote
  #6 (permalink)  
Old 2008-05-14
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 272
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: problem LOAD SHARING Multicast

hi sharky in multicast load sharing mode. in clusterXL deployments the internal devices will have their default gateway pointing to the cluster virtual ip address and similarly on the external interface.

so lets say ur internal users are trying to get to the internet. in this case when the internal router or host does a arp request for the mac address of the virtual ip address any of the active cluster members will respond with a multicast mac to the host. so when the host sends the traffic to the multicast address all the cluster members will receive the frame at layer 2. then each cluster will make a decision whether to process or drop the packet. making sure that no firewalls are processing the same packet and atleast one firewall is processing the packet.

in load sharing unicast mode. in this mode only a single cluster member also called pivot mac address is associated with the cluster virtual ip address.

so here when the host request the mac address of the virtual ip address the pivot responds with his interface mac address. once the pivot receives the frame then only the pivot makes the decision function as to whether forward the packet by himself or forward it to other cluster members. the other members when they receive the packet by the pivot they simply just forward it they don;t make any decision.

the difference in the mode is only how the cluster members receive the packet for load sharing. rest the working on clusterXL remains the same.

hope this help u out.

regards

sebastan
Reply With Quote
  #7 (permalink)  
Old 2008-05-19
Sharky Sharky is offline
Junior Member
 
Join Date: 2007-05-16
Posts: 12
Rep Power: 0
Sharky has an average reputation (10+)
Default Re: problem LOAD SHARING Multicast

Thanks for your collaboration

regards
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:10.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0