also to mention that when doing a cphaprob stat i see that on the problem device says "clusterxl is inactive or down"
cluster xl is unchecked in the policy cluster object, but i guess once sic has been estblished this will show the correct status?? Thanks --- On Sat, 5/12/09, Peter Addy <[email protected]> wrote: From: Peter Addy <[email protected]> Subject: help please SIC and CPHA To: "Mailing list for discussion of Firewall-1" <[email protected]> Date: Saturday, 5 December, 2009, 10:12 Hi In order to have SIC working in a cluster running vrrp, does the sync need to be configured on the module? what i mean by this is that one module has a different sync address than the other, this must change i know but will this prevent sic working initially from the management server to the module, also when it states HA module not started and in cpconfig enable cluster ha is on, does that usually mean HA module is not stated because the two boxes are unable to see each other for HA, the ClusterXL option in the gui of the cluster is unchecked, If the sync link changes and SIC has not been established then I guess HA will not work, but the issue is that sic does not initialize, done t e usual reset via cpconfig, can ping from the management server to the module vrrp is not configured on the module that sic has not been established, i wouldn’t have thought vrrp needs to be configured in order to have the sic working, Finally does sic work over the sync link in cluster environment? Current state is one module has sic working, with the gui object to reflect the new sync, however the operating system ip for the synch link has not been altered but has to be to reflect the gui, the other module has the correct sync ip and no vrrp, I can sort out the config to match and both modules, but will that then make sic work? Sorry if it all sounds confusing, any help is appreciated ============= Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
