I'm having some weird packet loss/drop issues. The service in question
happens to be NTP, but I doubt that the application layer has anything
to do with this.

The setup is slightly complicated. I have two FW/VPN-1 NG-AI (R55) running
as a synchronized cluster. Obviously, it is really nice to have times in
the logs from these two boxes as closely synchronized as possible. The
clear choice for that is NTP. The hosts do NTP to each other as well
as to a number of external sources which happen to be nearby routers.
The cluster is operating in a failover mode using Stonebeat. That is,
only one of the pair is routing traffic at any given time. The backup
is running with all interfaces down except for the synchronization interface
between the two (connected by a cross-over cable). While in this
configuration, all traffic to and from the "off-line" firewall gets
routed over the synchronization link.

Now all of this works, for the most part. But one little nagging problem
is that the NTP daemon on the secondary firewall cannot reach any of the
external NTP sources. This is allowed in the rulebase. The NTP traffic
shows up as "Accepted" in the firewall logs. But it doesn't work.

I first ran "snoop" on the primary firewall. You see the NTP packets
come in on the synchronization interface, but packets are never seen
at the outgoing interfaces. From there, I went on to "fw monitor." I
found that the packets were seen coming into the synchronization
interface, but never come out of the VM processing on the incoming
interface. That sounds like the firewall is dropping them, but they
are logged as accepted. WTF?

There is no NAT going on. I've disabled cluster synchronization for
NTP guessing that there was some weird race between NTP packets getting
processed and the synchronization for the NTP from the secondary
firewall. I lowered the time for keeping NTP state so that a single
UDP "connection" wasn't being held open. Each attempt creates a new
state entry. Nothing helps. The packets just disappear.

This isn't a huge deal. The secondary still can talk to the NTP server
on the primary, so they do sync up, but mysterious lost packets are
unsettling.
--
Crist J. Clark                               [EMAIL PROTECTED]
Globalstar Communications                                (408) 933-4387

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to