CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nokia And IPSO
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-11
jbailey01 jbailey01 is offline
Junior Member
 
Join Date: 2006-05-11
Posts: 11
Rep Power: 0
jbailey01 has an average reputation (10+)
Default VRRP Problem

Hello,

We have two Nokia IP330s running IPSO 3.8 and Check Point NG R55. The two firewalls are configured for HA and had been running fine for over a year. This past week we pushed a new policy and after the policy was pushed both firewalls reported their status as Master for all 7 interfaces we have clustered. I rebooted one of the firewalls and as it was booting the following was logged:

Information: cluster_info: (3rd Party Cluster) State change of member
2 (x.x.x.x) from active to down was canceled, since all other members
are down. Member remains active.

After this message was logged both firewalls again reported as Master for all clustered interfaces.

I have checked the topology and everything looks good, the only thing I noticed was that I can not ping the other side of the sync network I have setup. I am not sure if this is normal, but its just something I noticed while troubleshooting.

I have not been able to do much troubleshooting due to the connectivity problems that are caused when both firewalls are up.

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 2006-05-11
rpaige rpaige is offline
Junior Member
 
Join Date: 2006-04-18
Posts: 1
Rep Power: 0
rpaige has an average reputation (10+)
Default Re: VRRP Problem

It would appear that the policy installed is blocking the receiving of VRRP advertisments. You did not indicate how you resolved the problem, I assume you shutdown or removed one of the pair from the network. I would check the firewall logs from when this happened for dropped VRRP (IP Dest 224.0.0.18) packets. Also check the monitoring page in Voyager for VRRP stats and check for errors.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:31.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0