CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nokia And IPSO
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-23
luisrocha luisrocha is offline
Junior Member
 
Join Date: 2006-04-19
Posts: 26
Rep Power: 0
luisrocha has an average reputation (10+)
Default VRRPmc Cluster Members outgoing connections

Good Afternoon Guys.......

Can you tell me what to expect whent initiating a connection from a standby member of a VRRPmc configuration about source mac address and ip address used.

issue :
HA Mode
Cluster XL for sync
VRRPmc for all 8 interfaces
In the Cluster Object "3rd Party Configuration" i have checkbox in "Hide Cluster Members for outgoing traffic behind Cluster ip address"
NGX with IPSO 4

Assuming this when i initiate a connection from the active member if i make a tcpdump i see the connection SourceMac=VRRP_MAC and SourceIP=VIP, well this is the normal behaviour, but if i make a connection from the Standby node i see the connection getting out with the SourceMac=Local and SourceIP=VIP well with this behavior i see the SYN getting out from the node and no SYNACK because the SYNACK will return to the VIP address and will be processed by the active member and so i cannot connect to anything in the standby member.
Another problem is this is not true on all interfaces of the standby member, in some interfaces the connection is initiated with SourceMAC=Local and SourceIP=LocaLIP and the connection works fine.

Can you tell me what to expect, wich behaviour is the normal one ?



Luis Rocha
Reply With Quote
  #2 (permalink)  
Old 2006-08-07
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: VRRPmc Cluster Members outgoing connections

I would expect to see sourcemac=localmac, and sourceIP=VRRP IP, for all outbound connections from the secondary member. Some outbound connections won't be natted though - there is a file somewhere that defines which ones.

If you're running VRRP, I think you're better off turning off the "hide behind cluster IP" option - in fact, turn off all three options in 3rd party config, for slightly better performance.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:19.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0