hi,
I don't think it a "monitor firewall state" issue in ipso because the
ipso-vrrp would be in backup-state then, not the fw1 itself.
can you just try to delete the cluster-object and recreate it to see
if this helps?
br
reinhard
At 16:57 28.12.2007, you wrote:
Hello Din,
Thank You for your comment, but there is one thing that makes me
doubt patching would be the solution...
My customer has several similar configurations (HW and SW) that are
working fine. If it were a hotfix issue, they all had failed, hadn't they?
-lari-
-----Original Message-----
From: Mailing list for discussion of Firewall-1 on behalf of Din Cox
Sent: Fri 12/28/2007 4:07 PM
To: [email protected]
Subject: Re: [FW-1] Sync problem in VRRP cluster
Lari,
This is a full synchronization issue that HFA_06 for IPSO should
resolve.
Din
-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Lari
Luoma
Sent: Friday, December 28, 2007 8:36 AM
To: [email protected]
Subject: Re: [FW-1] Sync problem in VRRP cluster
Thanks for all the information. Unfortunately I already tried all these
before posting my message on the list...;-) I have also rebooted the
problematic device.
Sync-interfaces on both cluster members are running multicast, but I
have tried broadcast as well.
eth2c0 sync(secured), multicast
-lari-
-----Original Message-----
From: Mailing list for discussion of Firewall-1 on behalf of Reinhard
Stich
Sent: Fri 12/28/2007 2:48 PM
To: [email protected]
Subject: Re: [FW-1] Sync problem in VRRP cluster
hi,
did you try cphastop and cphastart on both modules? are the
interfaces defined as sync on the cluster-object?
br
reinhard
At 12:54 28.12.2007, you wrote:
>Hi!
>
>Ping is successful. I have tried cphastop and cphastart several
>times without success. The both firewall modules are up and running.
>
>cpstat ha -f all shows the following:
>
>Product name: High Availability
>Major version: 5
>Minor version: 0
>Service pack: 9
>Version string: N/A
>Status code: 0
>Status short: OK
>Status long: OK
>HA installed: 1
>Working mode: Sync only
>HA protocol version: 2
>HA started: yes
>HA state: active
>HA identifier: 1
>
>
>Interface table
>----------------------------------------------------------
>|Name |IP |Status|Verified|Trusted|Shared|
>----------------------------------------------------------
>|eth-s3p1c0| 10.40.253.165|Up | 0| 0| 0|
>|eth-s1p1c0| 192.168.12.12 Up | 0| 0| 0|
>|eth4c0 | 10.40.251.18|Up | 1400| 0| 0|
>|eth2c0 | 10.40.254.165|Up | 0| 1| 0|
>|eth3c0 | 10.191.66.66|Up | 6600| 0| 0|
>|eth1c0 | 10.40.10.112|Up | 0| 0| 0|
>----------------------------------------------------------
>
>
>
>Problem Notification table
>------------------------------------------------
>|Name |Status|Priority|Verified|Descr|
>------------------------------------------------
>|Synchronization|OK | 0| 332463| |
>|Filter |OK | 0| 9885| |
>|fwd |OK | 0| 0| |
>|cphad |OK | 0| 0| |
>------------------------------------------------
>
>-lari-
>
>
>
>-----Original Message-----
>From: Mailing list for discussion of Firewall-1 on behalf of Reinhard
Stich
>Sent: Fri 12/28/2007 12:33 PM
>To: [email protected]
>Subject: Re: [FW-1] Sync problem in VRRP cluster
>
>hi,
>
>do you have the connection between the 2 nokias on the
>sync-interface? can you ping the other box?
>if the connection 100Mbit/full-duplex?
>
>are the 2 firewall-modules up and running "cpstat fw"?
>
>try to run "cphastart" and check if clusterXL is enabled in "cpconfig".
>
>br
>reinhard
>
>At 11:02 28.12.2007, you wrote:
> >Hello Gurus,
> >
> >I have a VRRP cluster with two IP740s with IPSO 4.1_build013. I'm
> >here in the middle of a strange troubleshooting session. Here are
> the details:
> >
> >The sync is not working fine. cphaprob state gives the following
output.
> >
> >fw1[admin]# cphaprob state
> >
> >Cluster Mode: Sync only (IPSO cluster))
> >
> >Number Unique Address Firewall State (*)
> >
> >1 10.40.254.165 active
> >2 (local) 10.40.254.166 down
> >
> >I tried to unregister and re-register devices from cphaprob list,
> >but it didn't help. I also have rebooted the problematic cluster
member.
> >
> >fw ctl pstat gives the following message.
> >
> >Sync:
> > Version: new
> > Status:
> > Unable to send sync packets
> > Unable to receive sync packets
> >
> >fwd.elg file is filled up with the following message:
> >
> >fwsyncn_connected: connection to 10.40.254.165 failed. error=-5
> >
> >Any ideas anyone?
> >
> >Wishing You very happy New Year!
> >
> >-lari-
> >
> >
> >Lari Luoma
> >Senior Network Security Specialist
> >Mainframe Consulting Oy
> >[EMAIL PROTECTED]
> >+358-45-6576820
> >www.mainframe.fi
> >
> >
> >=================================================
> >To set vacation, Out-Of-Office, or away messages,
> >send an email to [EMAIL PROTECTED]
> >in the BODY of the email add:
> >set fw-1-mailinglist nomail
> >=================================================
> >To unsubscribe from this mailing list,
> >please see the instructions at
> >http://www.checkpoint.com/services/mailing.html
> >=================================================
> >If you have any questions on how to change your
> >subscription options, email
> >[EMAIL PROTECTED]
> >=================================================
>
>--
>Reinhard Stich [EMAIL PROTECTED]
>Internet Security AG, 1150 Wien, Johnstrasse 29
>Tel: +43 1 3709440 RS784-RIPE Fax: +43 1 3709440-333
>
>
>Scanned by Check Point Total Security Gateway.
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================
>
>
>
>
>Scanned by Check Point Total Security Gateway.
>
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================
--
Reinhard Stich [EMAIL PROTECTED]
Internet Security AG, 1150 Wien, Johnstrasse 29
Tel: +43 1 3709440 RS784-RIPE Fax: +43 1 3709440-333
Scanned by Check Point Total Security Gateway.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
Scanned by Check Point Total Security Gateway.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
Scanned by Check Point Total Security Gateway.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
Scanned by Check Point Total Security Gateway.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
--
Reinhard Stich [EMAIL PROTECTED]
Internet Security AG, 1150 Wien, Johnstrasse 29
Tel: +43 1 3709440 RS784-RIPE Fax: +43 1 3709440-333
Scanned by Check Point Total Security Gateway.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================