13.07.2015 Views

Firewall - Check Point

Firewall - Check Point

Firewall - Check Point

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

AuthenticationClusterXL31. When performing manual client authentication (using port 900) to a cluster wherethe IP addresses of the members are not routable, the URLs returned in the HTMLfrom the replying cluster member contain the non-routable IP address of themember instead of the cluster IP address. This fails subsequent operations. Theworkaround is to configure the cluster to use a domain name instead of an IPaddress in the client authentication HTML pages, using theahttpclientd_redirected_url global property. Make sure that your DNS serversresolve this domain name to the IP address of the cluster.32. Issues may arise when using automatic or partially automatic client authenticationfor HTTP on Load Sharing clusters (both ClusterXL and OPSEC clusters). Aworkaround is to define a decision function based only on IP addresses in order forconnections to open. For ClusterXL, go to the ClusterXL tab > Load Sharing >Advanced, and select IPs only. For OPSEC clusters, refer to the productdocumentation for more information.State Synchronization33. A cluster member will stay in the down state if it is detached and then reattachedto the cluster, as it does not automatically perform a full sync upon reattachment.To force a full sync, run the following commands on the module: fw ctl setsyncoff and fw ctl setsync start.34. Upon completion of full synchronization (Full sync), an error message Statesynchronization is in risk, is displayed on the cluster member on which thesynchronization is taking place. If this message occurs only once immediatelyfollowing Full sync, it can be safely ignored. If this message appears erratically,consult the ClusterXL user guide in the section Blocking New Connections UnderLoad.SmartConsole35. When working with a 3rd party Cluster Object with QoS, if you move from theTopology tab to a different tab, the following error message appears: No interfacewas activated in QoS tab for this host (Inbound or Outbound). Do you want to continue?Select Yes and continue your operation. This error message can be safely ignored.36. SmartUpdate shows cluster members as distinct Gateways without the commoncluster entity. When cluster members are not of the same version, applying Get<strong>Check</strong> <strong>Point</strong> Gateway Data on a cluster member will set the member's version on theCluster object. To set the version of the cluster correctly, apply the Get <strong>Check</strong> <strong>Point</strong>Gateway Data command to the cluster member with the latest version.Enterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!