CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default interface monitoring for failover in clusterXL

hi all i am trying to find out that whether cluster XL sends keep alive ccp packets along the data interfaces i mean the internal and external interface like in cisco failover

cause when i was labbing it up i disconnected a internal interface on the switch of the active firewall still no failover happenend.

is interface monitoring disabled by default in clusterXL. i read a document which states we need to enable interface monitoring for the interface. i mean it;s bad the basic purpose of failover should be to track the state of the data interfaces and it should be tracked by default.

can someone pls tell me what is the address to which the ccp packets are send.

any kind of help on the same would be great.

regards

sebastan
Reply With Quote
  #2 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: interface monitoring for failover in clusterXL

CCP packets are sent on all cluster interfaces (If a trunk interface they are sent only on the lowest numbered vlan by default).
Reply With Quote
  #3 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: interface monitoring for failover in clusterXL

hi jim i am using vlans for my internal and external network on eth0 and sync on a dedicated interface eth1.

does clusterXL track the state of the vlan interface by default or do i have to enable it.

cause i tried removing the internal vlan on the trunk port of the switch but no failover happenend.

my failover only works when i create a critical device and report as problem.

i want when a vlan interface or a physical interface is down the failover should happen just like in other firewalls is this possible.

can u pls help me out.

thanks once again.

regards

sebastan

Last edited by sebastan_bach; 2008-05-14 at 07:47.
Reply With Quote
  #4 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: interface monitoring for failover in clusterXL

Only the lowest numbered VLAN is checked. I think there is a way to monitor additional VLANs but I don't know how off hand.
Reply With Quote
  #5 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: interface monitoring for failover in clusterXL

hi jim thanks a lot mate i will get the command from the documentation.

mate just one more query so if i am using physical internal and external interfaces then if a interface goes down failover should normally occur right without any additional configuration.

here since i am using vlans i will need to add additonal commands to get it working.

i feel these configuration options of the failover should been given via the gui . the splat cli is not user friendly and nor the switches of the commands are mentioned properly in the documentation.

waiting for ur reply mate.

thanks once again.

regards

sebastan
Reply With Quote
  #6 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: interface monitoring for failover in clusterXL

Quote:
Originally Posted by sebastan_bach View Post
mate just one more query so if i am using physical internal and external interfaces then if a interface goes down failover should normally occur right without any additional configuration.
Yes that is correct

Quote:
here since i am using vlans i will need to add additonal commands to get it working.
Yes that is also correct

Quote:
i feel these configuration options of the failover should been given via the gui . the splat cli is not user friendly and nor the switches of the commands are mentioned properly in the documentation.
It is not a SPLAT configuration it is a kernel config. The parameter is "fwha_monitor_all_vlan"

As for adding this to the GUI, there isn't much call for it that I've seen.

How do other vendors handle it? I know PIX (<7) only monitored link state by default.

If monitoring all VLANs on a trunk port is on by default, how do you disable it with the other vendors?

Remember turning this on generates more traffic and in most cases will buy you very little.
Reply With Quote
  #7 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: interface monitoring for failover in clusterXL

hi jim thanks a lot for ur reply mate. mate i am running here into a problem i am not able to find the command for enabling monitoring of all the vlans here.

i could just find this command

fw ctl set int fwha_monitor_if_link_state 1. but this command is monitoring the state of the links.but since i am here using vlans i need the other command for enabling monitoring of vlans.

here i am running tcpdump on the firewall and i can see the ccp packets only on the sync and the vlan10 which is the lowest vlan . i am not able to see ccp packets on vlan 20 which is my external interface.

pls can u tell me where to find the command for doing the same.

thanks a lot for ur help.

waiting for ur reply.

regards

sebastan
Reply With Quote
  #8 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: interface monitoring for failover in clusterXL

hi jim i tried the command u mentioned in the post. it gives a error either the command or the argument is invalid. i guess i am missing more arguments to it. can u pls tell the complete command or the documentation to which i can refer too.

thanks waiting for ur reply.

regards

sebastan
Reply With Quote
  #9 (permalink)  
Old 2008-05-15
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: interface monitoring for failover in clusterXL

It's a kernel option, not a CLI command. Look up how you modify $FWDIR/con/fwkern.conf (I think that's the file but I'm not sure).
Reply With Quote
  #10 (permalink)  
Old 2008-05-15
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: interface monitoring for failover in clusterXL

hi jim u mean to say i need to modify the file and enter the syntax u wrote above to get it working.

pls help me out.

i been trying to get it working since many days.

waiting for ur reply.

regards

sebastan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:13.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0