CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-29
Senior Member
 
Join Date: 2005-08-30
Posts: 147
Rep Power: 4
tdvit has an average reputation (10+)
Default A strange thing happened today

Hi guys,

I recently upgraded my mgmt server (hardware only) and since then I have had intermittent problems with mgmt my redundent firewalls. From time to time when I test the sic status one of them fails saying no tcp connectivity. However I can ping it just fine and the both remain in working order as far as the cluster goes.

They are both in a Nokia IP Cluster HA and today I decided to reset the sic between mgmt and firewall. BANG our internet went down. I am pretty sure it was acting as the master when I reset the sic. Why would this happen can anyone tell me? The working firewall should have taken over??
__________________
tdvit
CCSA
CCSE
Reply With Quote
  #2 (permalink)  
Old 2006-08-29
Junior Member
 
Join Date: 2006-06-22
Posts: 21
Rep Power: 0
masterloo has an average reputation (10+)
Default Re: A strange thing happened today

When you upgraded the hardware did you move to another box? Did you keep the same ip, hostname, fqdn, and perform an upgrade_import?

When you say clustering HA with Nokia, I assume you are talking about VRRP.

If you reset SIC on the primary and if your VRRP wasn't functioning/configured properly or you had VRRP firewall monitoring off you could've had service interruption while the CP services were restarting.

1) You may want to check whether your VRRP is functioning/configured properly.

nokia> clish
in clish on both boxes: show vrrp

one should have all interfaces as master and the other all as backup

2) you could do a tcpdump/fw monitor to see what the SIC traffic is doing at the Firewall when you test it. e.g. nokia> fw monitor -e 'sport=18191 or dport=18191,accept;'

There could be many reasons why this happened and these are just a few starting ideas on where to begin to look for the problem(s) working with the few details provided
Reply With Quote
  #3 (permalink)  
Old 2006-08-30
Senior Member
 
Join Date: 2005-08-30
Posts: 147
Rep Power: 4
tdvit has an average reputation (10+)
Default Re: A strange thing happened today

thanks for the reply.

Im running a load sharing nokia IP cluster not vrrp.

Mick
__________________
tdvit
CCSA
CCSE
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 09:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0