Hello.
We have two ClusterXL Gaia R77.30 identical nodes with following hotfixes installed:
• Jumbo Hotfix Accumulator General Availability for R77.30 Take 216
• HOTFIX_R77_30
Implicitly Installed Hotfixes (installed as part of another hotfix):
• Check_Point_R77_30_JUMBO_HF_1_Bundle_T205_FULL.tgz
Acceleration CoreXL and SecureXL are enabled on both nodes.
Cluster works in HA mode:
[Expert@gw2:0]# cphaprob stat
Cluster Mode: High Availability (Primary Up) with IGMP Membership
Number Unique Address Assigned Load State
1 172.16.0.2 100% Active
2 (local) 172.16.0.3 0% Standby
Problem:
Few days ago our stanby node (gw2) "automagically" - without any admin intervention - has started to forward some traffic (about 1000 pkt/s) and it's CPU load (as shown by SmartViewMonitor->System Counters->FireWall History) raised up to 30 - 40 %. The active node gw1 is proccessing much, much more traffic - about 20 000 pkt/s by 70% CPU. At the same time icmp probes (ping) time for traffic coming through the cluster raised from few ms to about 60-80 ms.
Gw2 behaves strange as it would work in LS pivot mode (?!), although is in HA for sure. We have installed security policies few times and even reboot both nodes (of course not simultanously), but it is still the same issue. What's wrong with gw2? If we switch gw2 from standby to active, than gw1 behaves the same (1000 pkt/s, 30 - 40 % CPU).
Regards
Mariusz1
Bookmarks