CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-24
kagarner kagarner is offline
Junior Member
 
Join Date: 2006-07-17
Posts: 4
Rep Power: 0
kagarner has an average reputation (10+)
Default magic mac number

I have 2 firewalls running NG AI R55 HFA_18 on HP DL 380's, Active/Standby on the standby firewall I am seeing the following error:

FW-1: fwha_receive_fwhap_msg: received HAP packet with bad magic number c

Has anyone seen anything like this before? any idea what could be causing this.

Thanks,
K.
Reply With Quote
  #2 (permalink)  
Old 2007-01-24
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: magic mac number

Do you have more than one cluster connected to the same VLAN? if so look at sk25977
Reply With Quote
  #3 (permalink)  
Old 2007-01-25
kagarner kagarner is offline
Junior Member
 
Join Date: 2006-07-17
Posts: 4
Rep Power: 0
kagarner has an average reputation (10+)
Default Re: magic mac number

Thanks I will look at that article. But according to my network guy the 2 sets of firewall's we have here are on different vlan's.
Reply With Quote
  #4 (permalink)  
Old 2007-01-25
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: magic mac number

Have him check again epically the sync interfaces, that is the only way you should see that error that I know of.
Reply With Quote
  #5 (permalink)  
Old 2007-01-26
kagarner kagarner is offline
Junior Member
 
Join Date: 2006-07-17
Posts: 4
Rep Power: 0
kagarner has an average reputation (10+)
Default Re: magic mac number

Our sync interfaces are cross-over cables between the firewalls. Would that make a difference in this error I am seeing.

Thanks for your help.
Reply With Quote
  #6 (permalink)  
Old 2007-01-26
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: magic mac number

No it shouldn't. The error means that the cluster member is seeing sync traffic from a gateway that's not in its cluster.
Reply With Quote
  #7 (permalink)  
Old 2007-01-26
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: magic mac number

It has been a LONG time since last I configured a CP cluster, but I remember them being quite "chatty". Check logs to see what interface is seeing the packets.
Reply With Quote
  #8 (permalink)  
Old 2007-01-30
kagarner kagarner is offline
Junior Member
 
Join Date: 2006-07-17
Posts: 4
Rep Power: 0
kagarner has an average reputation (10+)
Default Re: magic mac number

I checked the logs but it does not point to a specific interface it just has the error msg:

kernel: FW-1: fwha_receive_fwhap_msg: received HAP packet
with bad magic number c

Any suggestion on how I can tell where it is seeing that from.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:31.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0