AFAIK, I never did any changes on implied rules EXCEPT, I have change the log redirection from default to another hard drive. During that time, only one cluster member is online. The other member is offline. Emm...Does modifying log redirection have certain effects on cluster members?

Regards,
            Alex


Charalambos Klitiropoulos wrote:

Have you by any chance disabled the implied rules? If so you need to allow
traffic from the management server to the firewall modules. Enable logging
on those rules and check your logs. If not, enable the logging feature for
the implied rules and check your logs.


On 14/01/06, Alexander Simbun <[EMAIL PROTECTED]> wrote:
Hi,
I'm only able to install on first cluster members but not the second.
ClusterXL shows status "unknown". In fact all status under second
cluster member are "unknown'. I have checked the synchronization link
between two members and it shows no problem at all (I'm using cphaprob
state), firewall sync (using fw ctl pstat) also okay. Any thought about
this?

Regards,
            Alex Simbun


Ramakrishnan Pillai wrote:

Are you able to install policy successfully on both the cluster
members?  What is the status of CLusterXL in the smartview status?.....RK

[EMAIL PROTECTED] 01/14/06 3:27 AM >>>


Dear Techie,

I have a problem recently regarding our firewall cluster. The secondary
firewall's status showed "unknown" in SmartView Status. I had taken down
the secondary firewall for more than a month. No changes been made on
the secondary firewall in terms of system settings and so on. By right,
when it boot up, all the latest policies are automatically retrieves
from the management server. Yes, I did made some changes on policies
recently, but only related to the service but not to the firewall
cluster itself. The primary firewall currently is the only one 'alive'
in the cluster and the only machine receives the latest policies, when
secondary firewall is temporarily offline. I have checked some important
configurations especially when dealing with synchronization, SIC, time
and system config.  I'm not sure how to solve this problem at this
moment. Kindly assist me on this matter. Thanks.

Peace & regards,

Alex

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================



=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to