CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-18
Member
 
Join Date: 2006-11-21
Posts: 42
Rep Power: 0
eldo37 has an average reputation (10+)
Default Urgent - Add Nokia Ipso cluster problem

We have the following problem at work :



We tried to bring in the secondary firewall into the cluster.



The issue that we are seeing is that when the secondary node joins the cluster then outgoing NAT starts to fail randomly.



When I try and telnet on port 80 to an external website from the firewall command line it is successful from one and not the other firewall. I don’t believe this is normal behaviour



Also I am not seeing any “permanent published (proxy only)” when I do an arp –a. I should be seeing them as we are doing auto NAT



When running under following command



stylecpf2[admin]# fw ctl arp

No proxy ARP entries



Which appears incorrect



Below is the fw ver command



stylecpf2[admin]# fw ver

This is Check Point VPN-1(TM) & FireWall-1(R) NG with Application Intelligence (R55) HFA_06 for IPSO 3.8, Hotfix 624 - Build 004





We have also tried to reboot to solve this issue but without success.

it's Nokia IP380 box.



If you have any idea?

Thank you
Reply With Quote
  #2 (permalink)  
Old 2008-02-18
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 293
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Urgent - Add Nokia Ipso cluster problem

I have suspicions that you need to use the Proxy ARP section in IPSO and add ARP entries using the CLUSTER MAC (as opposed to the previously unclustered single firewall before). You do say you are using auto-NAT but R55 is so old, I can't remember the caviats to Auto-NAT on an IPSO cluster.

I always used auto-nat just so I wouldn't have to mess with manual rules and then added Proxy ARP entries for all of my public IPs into IPSO so that my upstream routers would always be able to forward traffic to my gateways even if the firewall rejected it (so I could see drops in logs for unused IPs).

There are MANY ways to do ARP... maybe this info will help you.
__________________
There's no place like 127.0.0.1

Last edited by lammbo; 2008-02-18 at 13:12.
Reply With Quote
  #3 (permalink)  
Old 2008-02-18
Member
 
Join Date: 2007-08-04
Posts: 72
Rep Power: 2
eduardw has an average reputation (10+)
Default Re: Urgent - Add Nokia Ipso cluster problem

Also check the "external gateway" for the firewall it is possible that the arp time out on the routers is to high. When you have access to the gateway recreate the problem and try to manual delete the arp entry. Also make sure that both the node in the cluster use the same magic mac addressing.

Eduard
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:27.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0