CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-10
ryan_m ryan_m is offline
Junior Member
 
Join Date: 2007-05-02
Posts: 1
Rep Power: 0
ryan_m has an average reputation (10+)
Default Rulebase problems when mgmt auto-sync enabled

I recently began having an issue where various rules would work sometimes, and not others. Generally re-pushing out the rulebase would correct it. Sometimes only until the next time I pushed a rule, sometimes not. Very sporadic. Called our support folks and they said there was a known issue with managment high availibility setups that causes this. The fix is to delete all excess database revisions, keeping less than 15 at any time, and also to disable the automatic synchronizing of the management servers in the global properties. This did indeed seem to fix the problem. Just to test I re-enabled the auto sync the other day and sure as heck began experiencing flaky rules again. I am seeing this on two different installations, both are R62 for both the managment stations (running SPLAT) and the gateways themselves (Nokia IP560's on IPSO 4.2).

This is apparently a known issue and yet no fixes are out for it, which sounds very odd to me, anybody else have any experience with this, or know any more about it? I *really* don't like the solution of leaving auto-sync off... what's the point of having an HA mgmt server then?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:32.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0