13.07.2015 Views

Firewall - Check Point

Firewall - Check Point

Firewall - Check Point

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

gated_xl[1383]: task_change_role re-initializingThese messages can be safely ignored.SecurePlatform30. When executing the command clusterXL_admin down on a cluster configurationwhich includes Dynamic Routing, be sure to wait 10 seconds or so before runningthe command clusterXL_admin up. Failing to do so may result in a delay of a fewseconds before the cluster member returns to normal (active or standby) state, andthe following error message:Operation failed: member is still down, run 'cphaprob list' for furtherdetails.This occurs because the command clusterXL_admin down causes the active clustermember running Dynamic Routing to start a sync of the FIB table, and will notenter the UP state until the sync completes.31. When using the Advanced Routing Suite with ClusterXL, make sure to perform thefollowing:1. In order to keep routes synchronized among cluster members, allow the serviceFIBMGRD in the Rule Base.2. To prevent FIBMGRD connections from exceeding the timeout threshold, add thefollowing lines to the file $FWDIR/lib/user.def on the management station:/*Cluster related definitions - cluster fold and others */#include "cluster.def"deffunc user_accept_non_syn() {(src in cluster_members_ips,dst in cluster_members_ips,( sport = 2010 ) or (dport = 2010))};32. When using VTIs on a ClusterXL gateway with Hitless Restart configured, be sure toset Hitless Restart to restart-type signaled.33. To ensure RIB synchronization in NGX (R60A), the following steps should beperformed:1. Define a new TCP service with destination port of 1024-65535 and source portof 2010.2. In the Advanced Properties tab, uncheck Match for ANY.3. Add a rule allowing the above service and the service FIBMGR between all thecluster members.Enterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!