CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-08
dwmaas dwmaas is offline
Junior Member
 
Join Date: 2006-05-16
Posts: 5
Rep Power: 0
dwmaas has an average reputation (10+)
Default Loss of internet connectivity after policy push

Hi,
I am adding to this post since this is similar to a problem I am seeing with my secureplatorm R55 HFA-17 active/active cluster. We use automatic nats and have a manual NAT rule that does not nat between management and firewalls.

Upon completion of policy push, we loose connectivity to the next hop router. I ping the router from the firewall during the push, the ping stops upon completion of the push. I try to re-push with no change. I have to perform a reboot of both firewalls to re-establish connectivity again.

This just started a few days ago, and we have not seen this before.
Any ideas of what the issue maybe or what I can do?
Reply With Quote
  #2 (permalink)  
Old 2008-02-09
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Loss of internet connectivity after policy push

Check "fw ctl arp" before and after the policy push. See if you're losing ARP resolution for the router. Is the default route set to point to the router? If you take one gateway down, does it work OK?

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-02-10
dwmaas dwmaas is offline
Junior Member
 
Join Date: 2006-05-16
Posts: 5
Rep Power: 0
dwmaas has an average reputation (10+)
Default Re: Loss of internet connectivity after policy push

Thanks. I will try that the next time I push a policy.
Yes the inet router is set as default route.
Yes, currently I have 1 member down, and this seemed to work but then it happened again with the one down.
Reply With Quote
  #4 (permalink)  
Old 2008-02-10
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 681
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: Loss of internet connectivity after policy push

I experienced the exact same issue you referred to. I am also running
SPLAT on HFA_17 as well. I had to do the following to fix it:

1- perform cpstop on both firewalls:
2- cd $FWDIR/state
3- mv * /var/tmp
4- reboot both firewalls
5- repush policy to the cluster

It fixed my issue. Hopefully, it will fix yours as well.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:54.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0