CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nokia And IPSO
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-12
michael_chisholm michael_chisholm is offline
Junior Member
 
Join Date: 2006-05-12
Location: UK
Posts: 4
Rep Power: 0
michael_chisholm has an average reputation (10+)
Default VRRP not working

We have 2 x Nokia IPSO 3.8-BUILD039 in a VRRP setup. The master box is issuing/sending VRRP packets fine. The secondary (failover) box is not - it doesn't send out any VRRP packets onto the wire (if I tcpdump i don't see any, just the primary's).

Yet if I run iclid, sh vrrp or vrrp monitor it shows the secondary box's interfaces are happily in backup state.

So has anyone encountered a Nokia box that says its VRRP is working but not actually sending packets?
Reply With Quote
  #2 (permalink)  
Old 2006-05-13
karlk karlk is offline
Junior Member
 
Join Date: 2006-04-22
Posts: 4
Rep Power: 0
karlk has an average reputation (10+)
Default Re: VRRP not working

The backup is not supposed to advertise. See RFC 2338:

To minimize network traffic, only the Master for each virtual router sends periodic VRRP Advertisement messages. A Backup router will not attempt to pre-empt the Master unless it has higher priority...
Reply With Quote
  #3 (permalink)  
Old 2006-05-16
michael_chisholm michael_chisholm is offline
Junior Member
 
Join Date: 2006-05-12
Location: UK
Posts: 4
Rep Power: 0
michael_chisholm has an average reputation (10+)
Default Re: VRRP not working

Thanks, your absolutely right its not supposed to advertise. (I had been looking at HSRP and a packet capture I have since found to be incorrect - ie setup was wrong.)

However I still have the VRRP issue, or be one that revolves around VRRP (I think) not working correctly. Because when when the primary interface seems to fail for some reason (ocassionaly, and I don't know why), I have to change the priority of the secondary above the primary for it to kick in. When I do that the secondary kicks into life and assumes responsiblity (even thought the primary is back online and not doing anything).

Anyone experienced anything like this?
Reply With Quote
  #4 (permalink)  
Old 2006-05-16
luisrocha luisrocha is offline
Junior Member
 
Join Date: 2006-04-19
Posts: 26
Rep Power: 0
luisrocha has an average reputation (10+)
Default Re: VRRP not working

Are u using VRRP in monitored circuits ? if so what is the efective priority of each node the priority should be more than the total priority of the number of interfaces and by the way waht is the interface priority ?

Luis Rocha
Reply With Quote
  #5 (permalink)  
Old 2006-05-17
donshoutarp donshoutarp is offline
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 4
donshoutarp has an average reputation (10+)
Default Re: VRRP not working

I would also check with the vendor of your switch to see what they recommend for multicast. I've had a few problems with multi-layer switches doing the same thing. When I moved the connections to a layer 2 only swtich, the problem went away. There have been multiple posts on this site on configurations for Cisco.
Reply With Quote
  #6 (permalink)  
Old 2006-05-23
michael_chisholm michael_chisholm is offline
Junior Member
 
Join Date: 2006-05-12
Location: UK
Posts: 4
Rep Power: 0
michael_chisholm has an average reputation (10+)
Default Re: VRRP not working

Yes we are using VRRP in monitored circuits with one backup address (ie one virtual)

The priority of the master is 100
The priority of the slave is 99
The priority delta on both is 10.

I assume this setup is acceptable and will work?

I noticed there is a legacy VRRP setup. On looking at the configuration of this I notice you don't set a priority. How does this setup function as opposed to the one I am using

thanks
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:22.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0