CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 5 of 5

Thread: trouble creating cluster interface in cluster XL

  1. #1
    Join Date
    2020-04-30
    Posts
    1
    Rep Power
    0

    Default trouble creating cluster interface in cluster XL

    i am having trouble in creating a cluster interface in the smartconsole. Management server is running R80.30 and security servers (2 nodes) are running R80.10.

    I have created virtual interfaces on security servers without any problem but when i try to create cluster interface in the smartconsole i get errors for both nodes. cluster interface get created but it does not appear in cphaprob -a if.

    Is it due to different versions of mangement server and security servers or i am missing something.

    appreciate help in this case.

    Click image for larger version. 

Name:	Skjermbilde.PNG 
Views:	38 
Size:	95.3 KB 
ID:	1439Click image for larger version. 

Name:	Skjermbilde2.PNG 
Views:	44 
Size:	102.5 KB 
ID:	1440

    the error messages appears for both nodes.

  2. #2
    Join Date
    2007-03-30
    Location
    DFW, TX
    Posts
    359
    Rep Power
    14

    Default Re: trouble creating cluster interface in cluster XL

    The first screenshot is telling you someone else is making changes to gate01, so you can't make your changes.

    The second screenshot is telling you it doesn't like something about the change you are trying to make. Generally an invalid character in an interface name, or the like.

    Does the new interface still appear in the cluster object?

    Have you pushed policy since adding the new interface?

  3. #3
    Join Date
    2010-07-16
    Posts
    15
    Rep Power
    0

    Default Re: trouble creating cluster interface in cluster XL

    Hi,

    I would like to tag onto this thread. I'm a colleague of original poster, we fixed the bit with permissions.

    The problem with creating a new VLAN interface is still there, hope someone can see what we have missed.

    - Both Gateways have eth5 - trunked interface - with existing VLAN layer 3 sub-interfaces

    - Added a new interface to both nodes
    -- node1:
    -- add interface eth5 vlan 46
    -- set inteface eth5.46 ipv-address 192.168.x.2 mask-length 20
    -- save config
    -- node2
    -- add interface eth5 vlan 46
    -- set inteface eth5.46 ipv-address 192.168.x.3 mask-length 20
    -- save config

    - created VLAN on the switches, allowed on all tagged ports
    - verified that I can ping .2 and .3

    - added Cluster interface in SmartDashboard
    -- gateways & servers -> doubleclicked on the clusterXL resource -> network management
    -- actions -> new interface
    --- network type : cluster
    --- ipv4: 192.168.x.1 / 20
    --- member IPs: added node01 and node02 ipv4 addresses and mask-length
    --- clicked OK to create
    -- clicked Get Interfaces -> Get Interfaces With Topology
    - in SmartDashboard the interface now looks identical to other sub-interfaces
    - did a policy install, no errors.

    - unable to ping 192.168.x.1 from server on different VLAN, from both gateways, and from a server placed on the VLAN with .x.1 as gateway
    - logged on the gateway web GUI, the interfaces are marked as up and looks normal.
    - checked 'cphaprob -a if' and it does not list the interface. other cluster interfaces are listed.

    what step have we missed? why doesnt 'cphaprob -a if' show the cluster IP?

  4. #4
    Join Date
    2007-03-30
    Location
    DFW, TX
    Posts
    359
    Rep Power
    14

    Default Re: trouble creating cluster interface in cluster XL

    Quote Originally Posted by mrbob View Post
    - added Cluster interface in SmartDashboard
    -- gateways & servers -> doubleclicked on the clusterXL resource -> network management
    -- actions -> new interface
    --- network type : cluster
    --- ipv4: 192.168.x.1 / 20
    --- member IPs: added node01 and node02 ipv4 addresses and mask-length
    --- clicked OK to create
    -- clicked Get Interfaces -> Get Interfaces With Topology
    So you're aware, the last step in that list undid all the earlier steps in that list. That button exists specifically for people who don't want to build the interface themselves. I would guess that put the interface definition in the object in a bad state. Try deleting the interface definition in the cluster object, then either using Get Interfaces or building it manually.

  5. #5
    Join Date
    2006-04-20
    Posts
    5
    Rep Power
    0

    Default Re: trouble creating cluster interface in cluster XL

    Did you re-add in the cluster interface after you did the get topology??

    Quote Originally Posted by mrbob View Post
    Hi,

    I would like to tag onto this thread. I'm a colleague of original poster, we fixed the bit with permissions.

    The problem with creating a new VLAN interface is still there, hope someone can see what we have missed.

    - Both Gateways have eth5 - trunked interface - with existing VLAN layer 3 sub-interfaces

    - Added a new interface to both nodes
    -- node1:
    -- add interface eth5 vlan 46
    -- set inteface eth5.46 ipv-address 192.168.x.2 mask-length 20
    -- save config
    -- node2
    -- add interface eth5 vlan 46
    -- set inteface eth5.46 ipv-address 192.168.x.3 mask-length 20
    -- save config

    - created VLAN on the switches, allowed on all tagged ports
    - verified that I can ping .2 and .3

    - added Cluster interface in SmartDashboard
    -- gateways & servers -> doubleclicked on the clusterXL resource -> network management
    -- actions -> new interface
    --- network type : cluster
    --- ipv4: 192.168.x.1 / 20
    --- member IPs: added node01 and node02 ipv4 addresses and mask-length
    --- clicked OK to create
    -- clicked Get Interfaces -> Get Interfaces With Topology
    - in SmartDashboard the interface now looks identical to other sub-interfaces
    - did a policy install, no errors.

    - unable to ping 192.168.x.1 from server on different VLAN, from both gateways, and from a server placed on the VLAN with .x.1 as gateway
    - logged on the gateway web GUI, the interfaces are marked as up and looks normal.
    - checked 'cphaprob -a if' and it does not list the interface. other cluster interfaces are listed.

    what step have we missed? why doesnt 'cphaprob -a if' show the cluster IP?

Similar Threads

  1. IPSO Cluster cphaprob -a if missing cluster interface
    By ecesureshkumar in forum Check Point IP Appliances and IPSO (Formerly Sold By Nokia)
    Replies: 5
    Last Post: 2017-04-19, 09:38
  2. No traffic on Cluster Sync interface - Splat 2.6 Cluster XL HA
    By Xoron in forum Clustering (Security Gateway HA and ClusterXL)
    Replies: 11
    Last Post: 2009-02-17, 09:05
  3. VPN cluster trouble...
    By drhex2000 in forum IPsec VPN Blade (Virtual Private Networks)
    Replies: 4
    Last Post: 2007-10-03, 06:41
  4. cluster trouble
    By ligmania in forum Clustering (Security Gateway HA and ClusterXL)
    Replies: 4
    Last Post: 2006-03-09, 03:20

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •