CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-08
tdvit tdvit is offline
Senior Member
 
Join Date: 2005-08-30
Posts: 139
Rep Power: 4
tdvit has an average reputation (10+)
Default VRRP - non sync (non secured)

Hi All,

My VRRP clusters are both in backup state. when I run cphaprob -a if it tells me all interfaces are non sync non secured and tells me that syncronization will not work.

I have specified a sync network in the topology info. The firewall is running ipso 4.2 with NGX R65.

need help asap.

thanks
__________________
tdvit
CCSA
CCSE
Reply With Quote
  #2 (permalink)  
Old 2007-10-08
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: VRRP - non sync (non secured)

Last time I saw this then the clusterxl was enabled and configured with clusterxl settings rather then 3rd party and Nokia VRRP.
Reply With Quote
  #3 (permalink)  
Old 2007-10-08
tdvit tdvit is offline
Senior Member
 
Join Date: 2005-08-30
Posts: 139
Rep Power: 4
tdvit has an average reputation (10+)
Default Re: VRRP - non sync (non secured)

this resolved my issue

Solutions ID: 1351701
Version: 1.0
Published: April 26, 2007

Symptoms
Check Point state sync is broken, the output of cphaprob -a if shows no secured sync interface and displays "Warning: Sync will not function since there aren't any sync(secured) interfaces"

nokia[admin]# cphaprob -a if

eth-s1p3c0 non sync(non secured)
eth-s1p1c2 non sync(non secured)
eth-s1p4c0 non sync(non secured)
eth-s1p2c1 non sync(non secured)
eth2c0 non sync(non secured)
eth3c1 non sync(non secured)
eth1c0 non sync(non secured)

Warning: Sync will not function since there aren't any sync(secured) interfaces

The output of cphaprob state shows the interface is configured for sync:

nokia[admin]# cphaprob state

Cluster Mode: Sync only (IPSO cluster))

Number Unique Address Firewall State (*)

1 (local) 192.168.54.3 active

(*) In IP Clustering/VRRP FW-1 also monitors the cluster status

Answer
Another VLAN on the same physical interface has been configured with a lower VLAN ID than the one used for the sync interface. The VLAN ID for the sync interface must be configured to be the lowest VLAN ID when there are multiple VLANS on the same physical interface.

To resolve the problem:-

1. On both cluster members, use Voyager to lower the VLAN ID on the logical interface used for the sync network. The new VLAN ID for the sync interface must be configured to be the lowest VLAN ID on the physical interface when there are multiple VLANS on the same physical interface.


2. Reconfigure the trunk on the switch connected to the interface to reflect the change in VLAN ID.


3. Reboot the cluster members to make the new VLAN active.


4. Push the policy to the firewalls.


5. On both members, execute the commands:


nokia[admin]# cphastop; cphastart


6. Check on both members that the correct CP sync interface is now shown as secured in the output of cphaprob -a if


7. Check that the correct interfaces are shown in the output of cphaprob state and the interfaces are shown as active.


8. Check that sync is now working with fw tab -t connections -s
__________________
tdvit
CCSA
CCSE
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:39.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0