Hi! Ping is successful. I have tried cphastop and cphastart several times without success. The both firewall modules are up and running.
cpstat ha -f all shows the following: Product name: High Availability Major version: 5 Minor version: 0 Service pack: 9 Version string: N/A Status code: 0 Status short: OK Status long: OK HA installed: 1 Working mode: Sync only HA protocol version: 2 HA started: yes HA state: active HA identifier: 1 Interface table ---------------------------------------------------------- |Name |IP |Status|Verified|Trusted|Shared| ---------------------------------------------------------- |eth-s3p1c0| 10.40.253.165|Up | 0| 0| 0| |eth-s1p1c0| 192.168.12.12 Up | 0| 0| 0| |eth4c0 | 10.40.251.18|Up | 1400| 0| 0| |eth2c0 | 10.40.254.165|Up | 0| 1| 0| |eth3c0 | 10.191.66.66|Up | 6600| 0| 0| |eth1c0 | 10.40.10.112|Up | 0| 0| 0| ---------------------------------------------------------- Problem Notification table ------------------------------------------------ |Name |Status|Priority|Verified|Descr| ------------------------------------------------ |Synchronization|OK | 0| 332463| | |Filter |OK | 0| 9885| | |fwd |OK | 0| 0| | |cphad |OK | 0| 0| | ------------------------------------------------ -lari- -----Original Message----- From: Mailing list for discussion of Firewall-1 on behalf of Reinhard Stich Sent: Fri 12/28/2007 12:33 PM To: [email protected] Subject: Re: [FW-1] Sync problem in VRRP cluster hi, do you have the connection between the 2 nokias on the sync-interface? can you ping the other box? if the connection 100Mbit/full-duplex? are the 2 firewall-modules up and running "cpstat fw"? try to run "cphastart" and check if clusterXL is enabled in "cpconfig". br reinhard At 11:02 28.12.2007, you wrote: >Hello Gurus, > >I have a VRRP cluster with two IP740s with IPSO 4.1_build013. I'm >here in the middle of a strange troubleshooting session. Here are the details: > >The sync is not working fine. cphaprob state gives the following output. > >fw1[admin]# cphaprob state > >Cluster Mode: Sync only (IPSO cluster)) > >Number Unique Address Firewall State (*) > >1 10.40.254.165 active >2 (local) 10.40.254.166 down > >I tried to unregister and re-register devices from cphaprob list, >but it didn't help. I also have rebooted the problematic cluster member. > >fw ctl pstat gives the following message. > >Sync: > Version: new > Status: > Unable to send sync packets > Unable to receive sync packets > >fwd.elg file is filled up with the following message: > >fwsyncn_connected: connection to 10.40.254.165 failed. error=-5 > >Any ideas anyone? > >Wishing You very happy New Year! > >-lari- > > >Lari Luoma >Senior Network Security Specialist >Mainframe Consulting Oy >[EMAIL PROTECTED] >+358-45-6576820 >www.mainframe.fi > > >================================================= >To set vacation, Out-Of-Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= -- Reinhard Stich [EMAIL PROTECTED] Internet Security AG, 1150 Wien, Johnstrasse 29 Tel: +43 1 3709440 RS784-RIPE Fax: +43 1 3709440-333 Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
