CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-14
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default NOKIA IP 2450 Rebooting-NEED HELP ASAP

Dears
i have setup 2 * IP2450 in cluster mode, everything was working fine, before putting them into production, the HA ports are connected to a cisco switch.
suddenly the boxes are rebooting every 5 minutes, any clue?

the boxes have R62 with IPSO 4.2, same versions as they came from manufacturer, and i have installed the R65 for the smartcenter.

please advise
Reply With Quote
  #2 (permalink)  
Old 2008-02-14
Senior Member
 
Join Date: 2007-06-04
Posts: 1,095
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Is there anything in the log files of the box, failing that I would raise a call with Nokia.

messages file in /var/logs/
Reply With Quote
  #3 (permalink)  
Old 2008-02-14
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

hmm... funny... lol

Are you using ClusterXL or Nokia VRRP??

What happens if you change them to each standalone? DO they still reboot constantly?
Reply With Quote
  #4 (permalink)  
Old 2008-02-14
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Well

i reviewed the logs from the voyager, there is not much,
and then i was checking what i have done before the boxes started rebooting,
i found that i have enabled any any traffic to allow , the last rule, then i made it "drop" and since 10 min, the boxes are not rebooting, i don't know if this is the problem, i am still testing now

Regards
Reply With Quote
  #5 (permalink)  
Old 2008-02-14
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by chuachongchee View Post
hmm... funny... lol

Are you using ClusterXL or Nokia VRRP??

What happens if you change them to each standalone? DO they still reboot constantly?
i m using IP clustering, i did not try to check each box at a side, since i changed the last rule and doing my tests again.
Reply With Quote
  #6 (permalink)  
Old 2008-02-14
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by CPone View Post
Well

i reviewed the logs from the voyager, there is not much,
and then i was checking what i have done before the boxes started rebooting,
i found that i have enabled any any traffic to allow , the last rule, then i made it "drop" and since 10 min, the boxes are not rebooting, i don't know if this is the problem, i am still testing now

Regards
Hmm.. u mean you have one rule allow any any, and the next drop any any??

Wont this not allow you to install since theres a policy conflict... prior to your changes... any issues when installing policy?? Warnings? Errors??
Reply With Quote
  #7 (permalink)  
Old 2008-02-14
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by chuachongchee View Post
Hmm.. u mean you have one rule allow any any, and the next drop any any??

Wont this not allow you to install since theres a policy conflict... prior to your changes... any issues when installing policy?? Warnings? Errors??
the last rule should be drop any any, i changed it to allow any any, and since then the boxes were rebooting, when i reverted back to drop any, the boxes are working fine...
Reply With Quote
  #8 (permalink)  
Old 2008-02-14
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by CPone View Post
the last rule should be drop any any, i changed it to allow any any, and since then the boxes were rebooting, when i reverted back to drop any, the boxes are working fine...
Hmm... doesnt sound logical though.... if rulebase was indeed the culprit.. we should see cpu 100% or the box died.. and not rebooting which we saw..
Reply With Quote
  #9 (permalink)  
Old 2008-02-15
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 913
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by CPone View Post
the last rule should be drop any any, i changed it to allow any any, and since then the boxes were rebooting, when i reverted back to drop any, the boxes are working fine...
Depending on what, if anything, you were dropping further up in the rule base, your firewall and internal network could have been wide open to the Internet and getting hit with who-knows-what.

Ray
Reply With Quote
  #10 (permalink)  
Old 2008-02-15
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by RayPesek View Post
Depending on what, if anything, you were dropping further up in the rule base, your firewall and internal network could have been wide open to the Internet and getting hit with who-knows-what.

Ray
hmm... high chance too... anything in /var/log/messages??
Reply With Quote
  #11 (permalink)  
Old 2008-02-15
Junior Member
 
Join Date: 2007-09-20
Posts: 9
Rep Power: 0
chrissamuel has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by CPone View Post
i m using IP clustering, i did not try to check each box at a side, since i changed the last rule and doing my tests again.
You might find it is an ip clustering thing, especially if the switch doesn't support the clustering mode you are using. Maybe take one node out of the cluster and see if you get the same issue.
Reply With Quote
  #12 (permalink)  
Old 2008-02-16
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by chuachongchee View Post
Hmm... doesnt sound logical though.... if rulebase was indeed the culprit.. we should see cpu 100% or the box died.. and not rebooting which we saw..
i did not see any cpu 100 %, once i reverted back to drop, it worked, note that i was doing all testing in staging area
Reply With Quote
  #13 (permalink)  
Old 2008-02-16
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

i had a downtime yesterday to put the wo nokia IP 2450 into production, once i plugged all cables to the new boxes, they started to restart, whenever the traffic was passing through the boxes, they were restarting, i removed one box from the cluster, and it was the same, once the box sees the traffic it rebbots,
please found the following errors logs, which i think are the problem and i need to know how to solve it:

Feb 16 03:21:27 QR-FW1 [LOG_CRIT] kernel: Note: FW SXL Ver: 222050328, IPSO SXL Ver: 255061120
Feb 16 03:21:27 QR-FW1 [LOG_CRIT] kernel: FW-1: Nokia IPSO SecureXL device detected.Feb 16 03:21:27 QR-FW1 [LOG_CRIT] kernel: FW-1: SecureXL: Connection templates are not possible for the installed policy. Please refer to the documentation for further details.Feb 16 03:21:46 QR-FW1 [LOG_CRIT] kernel: rtm driver loadable interface called.
Feb 16 03:21:47 QR-FW1 [LOG_NOTICE] pm[134]: Reaped: S99cpboot[268]
Feb 16 03:21:47 QR-FW1 [LOG_NOTICE] pm[134]: Program S99cpboot is finished.

please advise
Reply With Quote
  #14 (permalink)  
Old 2008-02-16
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by CPone View Post
i had a downtime yesterday to put the wo nokia IP 2450 into production, once i plugged all cables to the new boxes, they started to restart, whenever the traffic was passing through the boxes, they were restarting, i removed one box from the cluster, and it was the same, once the box sees the traffic it rebbots,
please found the following errors logs, which i think are the problem and i need to know how to solve it:

Feb 16 03:21:27 QR-FW1 [LOG_CRIT] kernel: Note: FW SXL Ver: 222050328, IPSO SXL Ver: 255061120
Feb 16 03:21:27 QR-FW1 [LOG_CRIT] kernel: FW-1: Nokia IPSO SecureXL device detected.Feb 16 03:21:27 QR-FW1 [LOG_CRIT] kernel: FW-1: SecureXL: Connection templates are not possible for the installed policy. Please refer to the documentation for further details.Feb 16 03:21:46 QR-FW1 [LOG_CRIT] kernel: rtm driver loadable interface called.
Feb 16 03:21:47 QR-FW1 [LOG_NOTICE] pm[134]: Reaped: S99cpboot[268]
Feb 16 03:21:47 QR-FW1 [LOG_NOTICE] pm[134]: Program S99cpboot is finished.

please advise
I remember one of my users were mentioning about disabling nokia flows? Not sure if that helps.

Another thing... Did you enable SecureXL? Not soo sure, but my understanding is that Nokia boxes come with onboard acclerator cards and do not need SecureXL? Check that both on Nokia box and Dashboard are both on or off, and the appropriate license is there??
Reply With Quote
  #15 (permalink)  
Old 2008-02-16
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by chuachongchee View Post
I remember one of my users were mentioning about disabling nokia flows? Not sure if that helps.

Another thing... Did you enable SecureXL? Not soo sure, but my understanding is that Nokia boxes come with onboard acclerator cards and do not need SecureXL? Check that both on Nokia box and Dashboard are both on or off, and the appropriate license is there??
how to disable the nokiA FLOws, and how to check the SecureXL option,
i opened anotther thread in the licensing section about the license, because i have an error on both nodes about the clusterXL, and i want to know what exactly the required licenses that should be installed on the smartcenter, knowing that i have two nokia in IP clustering, IPSO4.2, NGX r62 and smartcenter ngx r65
Reply With Quote
  #16 (permalink)  
Old 2008-02-16
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: NOKIA IP 2450 Rebooting-NEED HELP ASAP

Quote:
Originally Posted by CPone View Post
how to disable the nokiA FLOws, and how to check the SecureXL option,
i opened anotther thread in the licensing section about the license, because i have an error on both nodes about the clusterXL, and i want to know what exactly the required licenses that should be installed on the smartcenter, knowing that i have two nokia in IP clustering, IPSO4.2, NGX r62 and smartcenter ngx r65
Sorry man... about the nokia flows thingy.. i'm really not too sure.. i'm not a nokia kinda guy.. hehe...

On the SecureXL portion... check in the firewall unit.. run cpconfig... see if performance pack or securexl is enabled or not.... not too sure for nokia... check if you have enabled state sync or ha for nokia too...

For license... you should be configured on the mgmt server that this is a 3rd party cluster... in the firewall object, under "configured products", uncheck securexl and cluster xl...., next, on the clusterxl portion or something.. (cant remember.... i dont have a gui with me atm)... change the HA to Nokia VRRP... the other settings can leave default... then install policy..

On license portion, you'll need 2 gateway license, one VPN1-Power/UTM license, and a HA gateway license... You'll need the managment server to be able to manage the gateways too... check how many sites you can manage on the mgmt server, one site = one gateway..

Be sure the backup everything, your firewall, mgmt server b4 making any changes.. haha.. play safe and be cautious...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:52.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0