CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Dynamic Routing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-01
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 4
maurox has an average reputation (10+)
Default Splat Pro Ospf

Does anyone have any OSPF configuration experience with SPLAT NGX?
I tried to implement that, but , in cluster load sharing enviroment , I don't understand if it is normal that only one member has the routing table with the OSPF route learned via OSPF...
The routing configuration is the same on both modules and if I stop one member the other learn the routes.
Is this normal ?
I think no because in Load sharing all the memeber must have the route....but maybe there are some news feauters that adjust this...

Any Idea ?

Thanks ,
Maurox
Reply With Quote
  #2 (permalink)  
Old 2006-03-02
Junior Member
 
Join Date: 2005-12-09
Posts: 1
Rep Power: 0
mpagliuzzi has an average reputation (10+)
Default Re: Splat Pro Ospf

No it's not normal. Have you enable OSPF on both cluster's gateways ?
bye
MicheleP
Reply With Quote
  #3 (permalink)  
Old 2006-03-06
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 4
maurox has an average reputation (10+)
Default Re: Splat Pro Ospf

As you can see from my previous message , the routing configuration is the same ; the issue was solved adjusting the multicast mac address configuration on the switch.

the problem now ( and for this we disabled the ospf configuration) is that when one module ( module2) goes down ( rebooting a node or stopping the daemons ) there are routing problems on the other ( module1) both when it ( module2) goes down both when it( module2) becomes up.

Is the same for you (if you have an OSPF config..)
Regards
Maurox
Reply With Quote
  #4 (permalink)  
Old 2006-03-06
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Splat Pro Ospf

Stupid queston first, you do have the license for ClusterXL?

Next question, are you using SecureXL?

But you are correct, in a ClusterXL all gateways should learn the routes. Are you in "new mode" or "Pivot"/unicast Mode?
Reply With Quote
  #5 (permalink)  
Old 2006-03-06
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 4
maurox has an average reputation (10+)
Default Re: Splat Pro Ospf

We have the licenses and yhe SecureXL enabled.
The configuration is with load sharing in multicast mode.
Please note that the problem wasn't on the dynamic routes :
after some test we see that they works ; only one member has the entire dynamic routes table , but the second module learn them by the first and all works fine ( in the lab without all the Dynamic routes but with some routes to test the OSPF) .

The problems , in production, and with a lot of routes learned via OSPF, were generated when we tried to reboot( or stop the fw/cpha daemon ) one of the modules:
nothing works for approximately 20 seconds when one of the members goes down and when it becomes active there were problems for other 20 seconds....
Reply With Quote
  #6 (permalink)  
Old 2006-04-24
Junior Member
 
Join Date: 2006-02-20
Location: Switzerland, Burgdorf
Posts: 22
Rep Power: 0
baboo has an average reputation (10+)
Default Re: Splat Pro Ospf

Hi Maurox

I think we're having the same problem.
During the fail-over to the standby-node there's an interrupt of 73 seconds.

If we trigger a failover (cpstop on active-node(gate3) ) the fail-over succed (to gate4), but the sync-interface on the node that became active (gate4) goes to "down". Which results in a topology change I think.
If we do that the other way (cpstop on the active-node gate4 to fail-over to gate3) the state of the sync-interface keeps "up".

I dont know if this is just related to the standby-clustering or also to the load-sharing. Can you verify this ?

We're also having troubles with the policy-installation. (see the other thread)
Do you also have problems with the policy-installation?

Regards, Manuel
Reply With Quote
  #7 (permalink)  
Old 2006-05-03
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 4
maurox has an average reputation (10+)
Default Re: Splat Pro Ospf

Hi Baboo,
unfortunately I can't verify what you asked because dor the moment we are working with static routes and OSPF is disabled.
For the other question , when we tried to implement ospf in our cluster , we didn't have any problems with policy installation.
Best regards,
maurox
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:08.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0