If you are testing monitored-circuit VRRP by pulling an interface, and
the other interfaces do not release their IP addresses, check that the
priority delta is large enough that the effective priority is lower than
the master router.


You should also utilise a high value for the priority, the time VRRP
takes to transition is calculated using this number (skew time)

What method are you using for VRRP?


-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of E. M.
Recio
Sent: Thursday, 5 June 2008 1:16 AM
To: [email protected]
Subject: [FW-1] Nokia VRRP doesn't failover all interfaces

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

I have Nokia IPSO 560 (v4.1 b022). We are having a problem with the VRRP
failover. We have two nokias in a VRRP cluster, and three interfaces
within the same VRID. One is higher priority than the other.

The problem is that when we lose one interface, it does not pull the
other interfaces over with it. However, if I unplug the cable, or shut
down the port, the nokia's failover from primary to secondary OK.

For example, we lost our DMZ switch recently. The switch was dead, but
because the nokia is plugged into another switch in between (which was
OK) there was a link light still on all three nokia interfaces. The
problem is that the dmz interface was the only one to switch over to the
secondary nokia, but none of the other ones did.

Has anyone experienced this? Is it a bug in the code?

- --
Thanks,
E. Recio

MAC user's dynamic debugging list evaluator?  Never heard of that.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIRrGmKoXvoXXmAZ0RAov9AJ4n0093NPATnMEUgA805dvXNrofGACffdfB
sQufwTz5GYdPFu9lTVmRw7c=
=NbtR
-----END PGP SIGNATURE-----

Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
#####################################################################################
Important: This electronic message and attachments (if any) are confidential
and may be legally privileged. If you are not the intended recipient do not
copy, disclose or use the contents in any way. Please let us know by return
e-mail immediately and then destroy this message.
#####################################################################################

Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to