I'm having some weird packet loss/drop issues. The service in question happens to be NTP, but I doubt that the application layer has anything to do with this.
The setup is slightly complicated. I have two FW/VPN-1 NG-AI (R55) running as a synchronized cluster. Obviously, it is really nice to have times in the logs from these two boxes as closely synchronized as possible. The clear choice for that is NTP. The hosts do NTP to each other as well as to a number of external sources which happen to be nearby routers. The cluster is operating in a failover mode using Stonebeat. That is, only one of the pair is routing traffic at any given time. The backup is running with all interfaces down except for the synchronization interface between the two (connected by a cross-over cable). While in this configuration, all traffic to and from the "off-line" firewall gets routed over the synchronization link. Now all of this works, for the most part. But one little nagging problem is that the NTP daemon on the secondary firewall cannot reach any of the external NTP sources. This is allowed in the rulebase. The NTP traffic shows up as "Accepted" in the firewall logs. But it doesn't work. I first ran "snoop" on the primary firewall. You see the NTP packets come in on the synchronization interface, but packets are never seen at the outgoing interfaces. From there, I went on to "fw monitor." I found that the packets were seen coming into the synchronization interface, but never come out of the VM processing on the incoming interface. That sounds like the firewall is dropping them, but they are logged as accepted. WTF? There is no NAT going on. I've disabled cluster synchronization for NTP guessing that there was some weird race between NTP packets getting processed and the synchronization for the NTP from the secondary firewall. I lowered the time for keeping NTP state so that a single UDP "connection" wasn't being held open. Each attempt creates a new state entry. Nothing helps. The packets just disappear. This isn't a huge deal. The secondary still can talk to the NTP server on the primary, so they do sync up, but mysterious lost packets are unsettling. -- Crist J. Clark [EMAIL PROTECTED] Globalstar Communications (408) 933-4387 ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
