CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-19
jonadam5 jonadam5 is offline
Junior Member
 
Join Date: 2007-06-18
Posts: 3
Rep Power: 0
jonadam5 has an average reputation (10+)
Default Time Drift on HA Cluster

Hi,

I have a curly issue that I have been unable to solve.
I have 2 SPLAT PRO gateways running on IBM x206 Servers. The problem is that the clocks are running too fast. The 2 gateways stay in perfect time sync with each other but not with anything else on our Network.
I have gone through the time zone settings under sysconfig on a couple of occasions so I'm sure they are set correctly. I have also used the ntp -n command to sync the time against the separate Smart centre server. There is also an accept rule in my policy to allow this traffic.

If anyone has any ideas I would really appreciate it.
Jon
Reply With Quote
  #2 (permalink)  
Old 2007-06-20
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 850
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Time Drift on HA Cluster

First, set up your ntp file with an ntp server, I've displayed mine as a reference. You can find a more complete list of ntp servers here. The interval specifies how often to sync the time in seconds.

# cat /etc/sysconfig/ntp
INTERVAL=3600
SERVER1=pool.ntp.org
USE_NTP=true

Then start the ntp service:

# ntpstart
#

Check the status:

# ntpstat
ntp is running
#

You should set this up on all of your gateways irregardless of whether or not they're exhibiting time drifts.
Reply With Quote
  #3 (permalink)  
Old 2007-06-20
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Time Drift on HA Cluster

Don't forget to create a drift file, that's important. But, melipla is correct.

Not that familiar with SPLAT, but Linux has its own version of the clock that is different from the hardware clock on the board. Most flavors have a hwclock command for setting this. It should be available in expert mode.

Check the manpage on the web for more information on this command.
Reply With Quote
  #4 (permalink)  
Old 2007-06-21
jonadam5 jonadam5 is offline
Junior Member
 
Join Date: 2007-06-18
Posts: 3
Rep Power: 0
jonadam5 has an average reputation (10+)
Default Re: Time Drift on HA Cluster

Thanks for the Feedback.
I have edited my NTP file and am now getting success. The main problem was the NTP servers I previously tried syncing from. I had tried a couple and felt sure they were ok as I've used them previously from other Windows servers.

I'm not sure about the drift file, I can't find much information about it. Does it tell SPLAT how to deal with the time skew?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:58.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0