Gurus of the list,
We're having problems with SecurClients running officemode not being able to
connect to the firewall. SecuRemote users are able to connect, likewise with
ordinary VPN Site-2-Site connections.
If we fail one node over to the other node SecurClients are able to connect for
a short while - approx 5-6 minutes - then it is impossible to create new
SecurClient sessions. When failing back to the original master once again it is
possible to connect to the firewall. We are using SecurID for authentication.
We notice the CPU load is around 80-90%, at times even more on the active node.
Memory usage is around 40%. The enforcement modules are two nokia boxes running
in VRRPmc. Software is NG AI R55 HFA017 and IPSO version 3.7.1 releng 1227.
We're really stumped to what the cause can be and wondering if anyone on the
list can shed some understanding light on the problem. Excessive CPU load comes
to mind, but I hope we can rule that out.
Best regards,
Børge Berg-Olsen
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|