Firewall-1

[FW-1] Juniper Secure Access (SSLVPN) versus Nokia Cluster : problem

Subject: [FW-1] Juniper Secure Access (SSLVPN) versus Nokia Cluster : problem
From: Mark Elsen <mark.elsen AT GMAIL DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Fri, 31 Mar 2006 23:45:24 +0200
Hi ,

We recently switched our CP Firewall environment, from a Windows 2000 server
based solution to a Nokia cluster :

  - 2x IP380  ( IPSO : 4.0.1-BUILD08 releng 1515  01.23.2006-190719 i386)
  - CP : NGX (HFA_01)

After migration of FW policy, everything went fine, except for our
SSLVPN access based on a 'Juniper(Netscreen) Secure Access' box , located
on the DMZ.

With the Nokia Cluster active, we sometimes get hanging connections
to the SSLVPN box, and or login screen not appearing when trying to
connect (e.g.).

When I pull one node out of the Nokia Cluster, everything goes fine
for SSLVPN access thru that dmz-box.

Only with the 2 nodes in the Nokia Cluster, it stops working (most
of the time, that is).

What could cause this problem syndrome ?

Thanks for all info,

(mark.elsen AT gmail DOT com)

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>
  • [FW-1] Juniper Secure Access (SSLVPN) versus Nokia Cluster : problem, Mark Elsen <=