Firewall-1

[FW-1] VLAN change = no longer reachable

Subject: [FW-1] VLAN change = no longer reachable
From: "David CALLEBAUT [AEMS Be]" <david.callebaut AT AEMS DOT NET>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 21 Mar 2007 07:19:49 +0100
Dear listmembers,

Did anybody ever encountered this:

Gateway is a CP NG w. AI R55 with latest HFA on a Nokia IP 530 with
3.8.1-BUILD033.

A physical interface is configured to have 2 logical IP's using VLAN
tagging. 
Both interfaces were re-distributed in OSPF to our backbone routers
(through another interface).
Requested by the switching team we needed to change the VLAN number on 1
of those interfaces.
So I simply changed the VLAN number in the interface configuration
(through voyager), applied and saved. 
The VLAN changed ok since I could ping a machine from the gateway on
that (changed) VLAN. 
However the interface was no longer distributed in OSPF. On our core
routers the route was gone. 
In the tracker we saw no unusual drops (except from the packets being
routed to an incorrect gateway).
Turning off the logical interface and turning back on did not change
anything. 
Turning off the redistribution in OSPF and back on: no change.

So we did a rollback to the previous VLAN... But the route does not
return anymore...
During all this no policy push was done.

Now we have created a static route on our core routers, but this is a
situation that is not wanted..

Did anyone ever run in the same issue? Should I remove the interface
completely instead of simply changing the VLAN number?
Any help would be great!

David C.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>