Firewall-1

[FW-1] Management HA problem on NG AI

Subject: [FW-1] Management HA problem on NG AI
From: Claudio Patrone <claudio.patrone AT SICURINT DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Mon, 22 Sep 2003 19:25:03 +0200
Hi all,
I've a problem with primary and secondary managements on W2k that are 
enforcying a couple of Nokia ip530 and are managing external fw module.
CP is NG AI R54 and Nokia are on 3.7 cluster mode.
These managements are natted out and connect control are enabled.
The configuration has worked fine till two weeks ago, and on audit I've seen 
sincronization peer till this date. No change has been applied on 
configuration. Only one remark about of power blackout in this period.

Now, Smartview status of primary mngt is no response and svn ok, while 
secondary mngt is ok, svn ok.
Primary works, receives logs from module, and enforce rules, but on Management 
HA doesn't show his status and peer, and you got "incorrect reply from server".
Logging on secondary, when you change state to active, it does, but fail to 
notify to peer  (primary): in fact you can see primary not reachable and in 
advanced status.
If you change secondary state to active, it works but failing to notify, is not 
aligned and you can see, on status, the two managements active. 
Sic is ok between managements, as I've tried to reinstall the secondary, but 
primary doesn't push any data to secondary.
As reinstallation of primary can solve the problem, but involve a lot of work 
(vpn's certificates),  has anyone suggestions about ?
<Prev in Thread] Current Thread [Next in Thread>
  • [FW-1] Management HA problem on NG AI, Claudio Patrone <=