CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Crossbeam
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-17
Junior Member
 
Join Date: 2005-08-16
Posts: 18
Rep Power: 0
mac123 has an average reputation (10+)
Default Packet loss when proving VAP firewall resilience

Running VSX NGX R60 on Crossbeam X80 XOS 7.2.1-48.

Running with 2 x NPM, 2 x CPM, 3 X APM ( 1 in standby ), 2 APM in a VSX cluster

Running continuos https test to webserver behind the firewall when we pull a blade, standby kicks in but noticed from show active flow, NPM still sending traffic to blade which has been removed and we lose https sessions which do recover.

Not sure how to debug or fix this

Backup mode of vap group is set to group.

Any ideas ?

Thanks in advance

Mac
Reply With Quote
  #2 (permalink)  
Old 2008-03-25
Member
 
Join Date: 2007-02-26
Posts: 33
Rep Power: 0
lunatrick has an average reputation (10+)
Default Re: Packet loss when proving VAP firewall resilience

if you only have 3 apm's and one VSX cluster then why not just have all three live and have backup mode group...that way if one of the blade fails then the flow will be redirected....

what I don't understand is why the flow isn't just automatically redirected to blade 2 in this scenario...nevermind the third blade which would take time to boot and load the image which wil happen automatically as it joins the vap group. In terms of the checkpoint config I presume you have a sync network setup?

can you post up your vap config please?
Reply With Quote
  #3 (permalink)  
Old 2008-04-07
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Packet loss when proving VAP firewall resilience

Quote:
Originally Posted by mac123 View Post
Running VSX NGX R60 on Crossbeam X80 XOS 7.2.1-48.

Running with 2 x NPM, 2 x CPM, 3 X APM ( 1 in standby ), 2 APM in a VSX cluster

Running continuos https test to webserver behind the firewall when we pull a blade, standby kicks in but noticed from show active flow, NPM still sending traffic to blade which has been removed and we lose https sessions which do recover.

Not sure how to debug or fix this

Backup mode of vap group is set to group.

Any ideas ?

Thanks in advance

Mac
What is your checkpoint config on you cluster?? Did you set "3rd party ha"?? And a show techsupport will do us good, or can you post your config??
Reply With Quote
  #4 (permalink)  
Old 2008-04-17
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Packet loss when proving VAP firewall resilience

If you put 3 vaps as VSX cluster, Check Point Sync should take care of that.
Reply With Quote
  #5 (permalink)  
Old 2008-04-18
Junior Member
 
Join Date: 2007-05-04
Posts: 4
Rep Power: 0
wa1di has an average reputation (10+)
Default Re: Packet loss when proving VAP firewall resilience

For sync network you should have created internal circuit for managing state information between members if you have SBHA.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:43.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0