CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2009-06-27
Junior Member
 
Join Date: 2008-11-01
Posts: 5
Rep Power: 0
spacyfreak has an average reputation (10+)
Default R65 IPSO4.2 - Critical Issue with IWFD and log_buffer_full error

Migration to the new brave checkpoint world was a real challenge...

Anyway, now that it (mostly) runs (Cluster with two nokia ipso4.2 IP690 Nodes wit CP R65), we got an issue where the whole cluster went to hell..

What happens?
Many rules, logging enabled on mostly every rule (over 1000 policies and many many objects).

Then on console error message "log buffer full" and lost 500 logs or something like that.
So, cause much traffic and much logging, log buffer on fw was full.
This "seems" to lead to a problem so that fwd deamon crashes completely.
Both nodes where not able to provide functionality anymore.


So questions are..

1. Did you have such an issue with fwd crashing? Whats the cause?

2. Is nokia IFWD the fwd process you can see on smartMonitor or are this two different things?

4. Is log buffer on VPN-1 only in RAM or is it written on the hard disc?

5. is log buffer the file fw.log?

6. What is the most recommended High Availability Configuration for this type of NOkia/IPSO/Checkpoint Cluster? ClusterXP + IPSO VRRP Managed Circuits? Or ONLY Nokia VRRP? These different HA modes and advatage/disadvantage is not completely clear to me, why should it be configured this way or that way and how this all works together.
Reply With Quote
  #2 (permalink)  
Old 2009-06-27
Senior Member
 
Join Date: 2005-08-14
Location: Gig Harbor, WA, USA
Posts: 617
Rep Power: 5
PhoneBoy has an average reputation (10+)
Default Re: R65 IPSO4.2 - Critical Issue with IWFD and log_buffer_full error

There's an SK article about the log buffer being full. In short, it is a circular buffer that stores what needs to be logged before it either writes to disk (if logging locally) or sends it to a remote logging server (either SmartCenter server or a specific logging server). You can increase this buffer if needed, but there are limits to how big you can make it.

Generally, if you're logging everything under the sun, though, you might want to examine why you need to log so many things and reduce the amount of stuff you are logging. It might explain why fwd is crashing (and yes, if fwd crashes, you lose lots of functionality).

ifwd is not the same thing as fwd, ifwd is a legacy process that used to signal to Firewall-1 that a failover needs to occur. It has not been necessary since roughly R55 and should be disabled (done in Voyager).

Neither VRRP or IP Clustering is "any better" than one another, but they serve different needs. If you are running a site-to-site VPN and you want to load balance the two machines, IP Clustering is the way to go. If you're not doing VPN or are mostly interested in active/standby, VRRP Monitored Circuits is the way to go. There are some exceptions to these rules, of course, but these are the general guidelines.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:14.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2