| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| We have 2 x Nokia IPSO 3.8-BUILD039 in a VRRP setup. The master box is issuing/sending VRRP packets fine. The secondary (failover) box is not - it doesn't send out any VRRP packets onto the wire (if I tcpdump i don't see any, just the primary's). Yet if I run iclid, sh vrrp or vrrp monitor it shows the secondary box's interfaces are happily in backup state. So has anyone encountered a Nokia box that says its VRRP is working but not actually sending packets? |
| |||
| The backup is not supposed to advertise. See RFC 2338: To minimize network traffic, only the Master for each virtual router sends periodic VRRP Advertisement messages. A Backup router will not attempt to pre-empt the Master unless it has higher priority... |
| |||
| Thanks, your absolutely right its not supposed to advertise. (I had been looking at HSRP and a packet capture I have since found to be incorrect - ie setup was wrong.) However I still have the VRRP issue, or be one that revolves around VRRP (I think) not working correctly. Because when when the primary interface seems to fail for some reason (ocassionaly, and I don't know why), I have to change the priority of the secondary above the primary for it to kick in. When I do that the secondary kicks into life and assumes responsiblity (even thought the primary is back online and not doing anything). Anyone experienced anything like this? |
| |||
| Are u using VRRP in monitored circuits ? if so what is the efective priority of each node the priority should be more than the total priority of the number of interfaces and by the way waht is the interface priority ? Luis Rocha |
| |||
| I would also check with the vendor of your switch to see what they recommend for multicast. I've had a few problems with multi-layer switches doing the same thing. When I moved the connections to a layer 2 only swtich, the problem went away. There have been multiple posts on this site on configurations for Cisco. |
| |||
| Yes we are using VRRP in monitored circuits with one backup address (ie one virtual) The priority of the master is 100 The priority of the slave is 99 The priority delta on both is 10. I assume this setup is acceptable and will work? I noticed there is a legacy VRRP setup. On looking at the configuration of this I notice you don't set a priority. How does this setup function as opposed to the one I am using thanks |
![]() |
| Thread Tools | |
| Display Modes | |
| |