Firewall-1

[FW-1] CCP broadcasts

Subject: [FW-1] CCP broadcasts
From: Andriy Malyuk <andreym AT PRONET DOT UA>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Thu, 24 Nov 2005 17:39:58 +0200
Hi all,
As I understand claster control protocol uses 8116/udp for connections table syncronization and status info exchange with other cluster members. So if dedicated syncronization network is defined and every cluster member has an interface wich looks to this network why broadcast to all interfaces ?

17:23:38.633646 0.0.0.0.8116 > x.x.x.0.8116: udp 37
17:23:38.926923 0.0.0.0.8116 > x.x.x.0.8116: udp 36
17:23:39.026896 0.0.0.0.8116 > x.x.x.0.8116: udp 37
17:23:39.033641 0.0.0.0.8116 > x.x.x.0.8116: udp 36
17:23:39.133640 0.0.0.0.8116 > x.x.x.0.8116: udp 37
17:23:39.526914 0.0.0.0.8116 > x.x.x.0.8116: udp 37
17:23:39.633660 0.0.0.0.8116 > x.x.x.0.8116: udp 37
17:23:40.026916 0.0.0.0.8116 > x.x.x.0.8116: udp 37

I can see such packets on all interfaces of every cluster member and Smart Centre as well.

I'm using NGX HA cluster, ccp is configured to multicast mode and diagnostics says
Sync:
       Version: new
       Status: Able to Send/Receive sync packets

Is it possible to prevent broadcasting ccp packets to all available interfaces ?

Thanks,
Andrey.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>