CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 5 of 5

Thread: Nortel 5111 Clustering HA with R62

  1. #1
    Join Date
    2006-05-24
    Posts
    30
    Rep Power
    0

    Default Nortel 5111 Clustering HA with R62

    Hi,

    We had NSF 5111 on R62 in cluster HA, unfortunatly one of the box(FW2) went faulty and now new box has arrived. Ti join new box in cluster what are the steps involved?

    HA configuration is such a way that my FW1(Firewall 1) will be always preferred master. Currently FW1 is up and fine and all the traffic is flowing via FW1 only.

    We have tried to join the new box (FW2) by factory defaulting FW2 and then join but we are getting error after putting FW2 IP, MIP and admin password
    "Unable to contact the system"

    At the time of joining its asking following:-

    [Setup Menu]

    clone - Clone the configuration
    join - Join an existing cluster
    new - Initialize host as a new installation
    boot - Boot menu
    info - Information menu
    exit - Exit [global command, always available]

    >> Setup# join

    Setup will guide you through the initial configuration of the Firewall.

    Enter port number for the management interface [1-6]: 1

    Enter IP address for this machine: 1.1.1.2

    Enter network mask [255.255.255.0]:

    Enter VLAN tag id (or zero for no VLAN) [0]: 0

    The system is initialized by connecting to the management server

    on an existing Firewall, which must be operational and initialized.

    Enter the Management IP (MIP) address: 1.1.1.3

    Enter the existing admin user password:

    ...Error:
    Unable to contact the system

    Please note that I am putting existing admin user password for Firewall 1 which is currently working and master.

    1.1.1.1 -- FW1 management interface IP

    1.1.1.2 -- FW2 management interface IP

    1.1.1.3 -- MIP for the cluster

    Please let me know if I am correct.

  2. #2
    Join Date
    2005-12-29
    Posts
    37
    Rep Power
    0

    Default Re: Nortel 5111 Clustering HA with R62

    Hi ,

    I am not sure how 5111 work as we have 6426 or 6626 Cluster , However you can give it a try .

    One way is to login to your fw1 and go to /cfg/pnp/list will give you the cluster member IP address , if you see your fw2 there then del it and app and then again add the same . Make sure when you are adding this the second box should not be connected , apply the settings and then try repluging the second box and see whether its able to join automatically or not , if not then power cycle the second box .

    Otherway is the one which you are trying but if possible then try issuing the command /maint/diag/unldplcy that will unload the current policies from the fw1 and then try rejoing the same with the process which you described in your problem . remember that will cost you downtime for sometime . Also verify that you have allowed the firewall network in /cfg/sys/accesslist/ .

    Regards,
    Sudhir

  3. #3
    Join Date
    2008-09-02
    Posts
    5
    Rep Power
    0

    Default Re: Nortel 5111 Clustering HA with R62

    Hi,

    Hey just check the sync cable on both directors. Which should be on another netwok range.

    Thanks
    shridhar


    Quote Originally Posted by brijesh_techno View Post
    Hi,

    We had NSF 5111 on R62 in cluster HA, unfortunatly one of the box(FW2) went faulty and now new box has arrived. Ti join new box in cluster what are the steps involved?

    HA configuration is such a way that my FW1(Firewall 1) will be always preferred master. Currently FW1 is up and fine and all the traffic is flowing via FW1 only.

    We have tried to join the new box (FW2) by factory defaulting FW2 and then join but we are getting error after putting FW2 IP, MIP and admin password
    "Unable to contact the system"

    At the time of joining its asking following:-

    [Setup Menu]

    clone - Clone the configuration
    join - Join an existing cluster
    new - Initialize host as a new installation
    boot - Boot menu
    info - Information menu
    exit - Exit [global command, always available]

    >> Setup# join

    Setup will guide you through the initial configuration of the Firewall.

    Enter port number for the management interface [1-6]: 1

    Enter IP address for this machine: 1.1.1.2

    Enter network mask [255.255.255.0]:

    Enter VLAN tag id (or zero for no VLAN) [0]: 0

    The system is initialized by connecting to the management server

    on an existing Firewall, which must be operational and initialized.

    Enter the Management IP (MIP) address: 1.1.1.3

    Enter the existing admin user password:

    ...Error:
    Unable to contact the system

    Please note that I am putting existing admin user password for Firewall 1 which is currently working and master.

    1.1.1.1 -- FW1 management interface IP

    1.1.1.2 -- FW2 management interface IP

    1.1.1.3 -- MIP for the cluster

    Please let me know if I am correct.

  4. #4
    Join Date
    2011-04-18
    Location
    Mumbai, India
    Posts
    12
    Rep Power
    0

    Default Re: Nortel 5111 Clustering HA with R62

    The same issue occurring here.

    Does anybody successfully joined the secondary box in cluster ??

    Please share the procedure to follow the process.....

  5. #5
    Join Date
    2011-04-18
    Location
    Mumbai, India
    Posts
    12
    Rep Power
    0

    Default Re: Nortel 5111 Clustering HA with R62

    Had bad experience with Nortel ASF 5111

    • Primary Firewall (172.16.68.24) was running up in the network
    • Tried to join secondary firewall (172.16.68.25) in cluster with primary but error occurred “Unable to contact system”
    • Changed secondary firewall IP as 172.16.68.22 which brought FW2 in cluster but received error pertaining to old IP (172.16.68.25) on console.
    • To avoid the conflict & complexity, removed old 172.16.68.25 on FW1, post which FW1 started malfunctioning. Traffic/Services were impacted and observed ports were flapping between UP & DOWN states.
    • Post discussing with customer, we tried to configure FW2 manually. During which, the MGMT server was unreachable from gateway. The traceroute path was leading to external (outside) segment instead Internal. This was seemed like software bug.

    we taken customer approval to configure checkpoint on desktop having 3 NICs. same was installed @ network after having huge DT

Similar Threads

  1. clustering with nokia clustering-services - failure after power fail
    By bytes in forum Clustering (Security Gateway HA and ClusterXL)
    Replies: 1
    Last Post: 2010-01-27, 03:09
  2. Getting sync warning on Nortel 5111 Cluster
    By brijesh_techno in forum Nortel ASF/NSF
    Replies: 0
    Last Post: 2009-09-14, 03:06
  3. NGX HFA3 with nortel contivity
    By jnantel in forum Interoperability
    Replies: 1
    Last Post: 2009-02-18, 17:27
  4. Nortel Alteon 5409
    By halod in forum Nortel ASF/NSF
    Replies: 3
    Last Post: 2007-12-27, 22:57
  5. Nortel Alteon 5109
    By netspezi in forum Nortel ASF/NSF
    Replies: 1
    Last Post: 2007-11-04, 10:26

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •