CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nokia And IPSO
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-09-16
Junior Member
 
Join Date: 2006-05-04
Posts: 19
Rep Power: 0
tkalas has an average reputation (10+)
Default VRRP -Secondary Firewall flapping

Hi guys,

When I check the logs , i see that my secondary firewall in a nokia cluster keeps flapping. There is no error or change of state on the primary firewall.

The firewall physical interface contains 4 vlans but only one vlan flaps suggesting it is not the interface that is the problem. Does anyone have a take on this?

-----------------------------------------------------------------------------------------------------------------
Aug 29 09:12:18 FW02 [LOG_NOTICE] ipsrd[272]: vrrp_vr_master: interface eth-s1p4c1, VRID 41: state=MASTER
Aug 29 09:12:18 FW02 [LOG_NOTICE] snmpd: Trap sent to 10.39.24.22: Version - 2c, Type - Enterprise Specific, VRRP New Master
Aug 29 09:12:18 FW02 [LOG_NOTICE] ipsrd[272]: vrrp_recv_advertise: priority override
Aug 29 09:12:18 FW02 [LOG_NOTICE] ipsrd[272]: vrrp_vr_backup: interface eth-s1p4c1, VRID 41: state=BACKUP
------------------------------------------------------------------------------------------------------------------
Reply With Quote
  #2 (permalink)  
Old 2008-09-16
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 312
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: VRRP -Secondary Firewall flapping

Are you sure the 2 firewalls see each other properly on all vlan's?
It sounds like the interface is missing updates from its peer, could be due to Multicasts being dropped.
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS
Reply With Quote
  #3 (permalink)  
Old 2008-09-17
Junior Member
 
Join Date: 2006-05-04
Posts: 19
Rep Power: 0
tkalas has an average reputation (10+)
Default Re: VRRP -Secondary Firewall flapping

There are 4 vlans configured on the interface vlans 41, 42, 43, 44 but the logs show just vlan 41...you would expect this from all the vlans if it is an interface problem.

It happens like every 30mins. Both firewall interfaces are connected to the same cisco switch.
Reply With Quote
  #4 (permalink)  
Old 2008-09-17
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 312
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: VRRP -Secondary Firewall flapping

Do you see any errors on the Cisco switch? Duplex mismatches? Spanningtree disabled?
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS
Reply With Quote
  #5 (permalink)  
Old 2008-09-19
Member
 
Join Date: 2007-02-27
Posts: 80
Rep Power: 2
th0i3 has an average reputation (10+)
Default Re: VRRP -Secondary Firewall flapping

I have seen a couple of incidents of late. If you perform TCPDUMP on the interface (active and standby), you will see the primary firewall isn't sending out multicast VRRP hello for 'n' seconds/intervals.

The command is:
tcpdump -i <interface> proto vrrp > tcpdump1.out

The question to ask is why isn't the multicast being sent out the interface? I don't know and I am looking for the answers myself. Do you have similar symptoms?

Last edited by th0i3; 2008-09-19 at 07:10.
Reply With Quote
  #6 (permalink)  
Old 3 Weeks Ago
Junior Member
 
Join Date: 2007-04-10
Posts: 12
Rep Power: 0
tohhwee72 has an average reputation (10+)
Default Re: VRRP -Secondary Firewall flapping

Just encounter a similar problem using IP2450 with IPSO 6.0 How to resolve this problem?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:27.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0