CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nokia And IPSO
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-21
Junior Member
 
Join Date: 2008-07-31
Posts: 17
Rep Power: 0
linkstate has an average reputation (10+)
Default Nokia IP390 Firewalls simply hang

Good Morning to all you folks.


I have a strange situation happening.

I have two redundant nokia appliances running in Active / Standby mode.

From now and then they tend to just stop at all and none of them replies even to a console connection.

Has this ever happened to you guys ? The only thing I see that can cause this kind of effect (the two appliances simply hang) is the failover cable, because it's a common factor to both firewalls.

All the information found relevant after rebooting the devices was this
"

login: Aug 20 15:43:46 ctdfw01 [LOG_ERR] xfer_crash: A kernel crash exists but cannot be transferred. Remote dump server not configured or configured with TFTP protocol. Run savecore -r command manually.
CPHA : Getting into preconfigured mode...
vpn1 driver loadable interface called."

Could anyone shed some light into these events ?


Best Regards,
Reply With Quote
  #2 (permalink)  
Old 2008-08-21
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 268
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Nokia IP390 Firewalls simply hang

Another common factor is the version of IPSO being 4.2?
Had similar issues, crashing firewalls no apparent reason, just install them clean with 4.1 and your problems are over.
Reply With Quote
  #3 (permalink)  
Old 2008-08-22
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Nokia IP390 Firewalls simply hang

Hi,

1) Doublecheck that in Smartdefense settings Aggressive Aging is off
2) If this doesnt help look for SecureXL error messages in the logs.
3) Does hand occur on random hours of the day or specific time period for each crash?
Reply With Quote
  #4 (permalink)  
Old 2008-08-22
Junior Member
 
Join Date: 2008-07-31
Posts: 17
Rep Power: 0
linkstate has an average reputation (10+)
Default Re: Nokia IP390 Firewalls simply hang

Quote:
Originally Posted by abusharif View Post
Hi,

1) Doublecheck that in Smartdefense settings Aggressive Aging is off
2) If this doesnt help look for SecureXL error messages in the logs.
3) Does hand occur on random hours of the day or specific time period for each crash?


3) It happens almost every day around 3 AM...


Also, before it hangs up completely we get the following console output:

"Aug 21 02:59:15 [LOG_NOTICE] snmpd: Updating physical contents table."

Last edited by linkstate; 2008-08-22 at 04:23.
Reply With Quote
  #5 (permalink)  
Old 2008-08-22
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Nokia IP390 Firewalls simply hang

Quote:
Originally Posted by linkstate View Post
3) It happens almost every day around 3 AM...


Also, before it hangs up completely we get the following console output:

"Aug 21 02:59:15 [LOG_NOTICE] snmpd: Updating physical contents table."


my memory serves me bad at the moment but I had similar issues. It was almost every day at arround 01:00. In my case it was Smartview monitor.
Try disabling Smartview monitor from the gateway object (checkbox), push policy and let it go for day or two and you will see if this helped.

Not sure how i solved it at last (since i activated monitor afterwards again) and didnt have any issues.
Reply With Quote
  #6 (permalink)  
Old 2008-08-29
Member
 
Join Date: 2007-02-27
Posts: 80
Rep Power: 2
th0i3 has an average reputation (10+)
Default Re: Nokia IP390 Firewalls simply hang

Abu may be right as you may be hitting a bug with RTM.

run the following command. This will crash your firewall.

rtm monitor -k ip -v pkt dir=in acc=sum -v pkt dir=out acc=sum -v pkt acc=sum sort=bottom -i 10

If your firewall crashes, this means you hit the RTM bug. If not, focus elsewhere.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:08.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0