Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gaurav_Pandya

Secondary firewall is not accessible through 443 or not accessible through IPSEC tunnel

I encountered the issue described below and successfully resolved it using the steps listed. Sharing it here so that fellow CheckMates users can benefit from the solution

Issue - Secondary firewall is not accessible through 443 or not accessible through IPSEC tunnel or TCP connection failure port=18191" while pushing policy on secondary member

Check value with below command
# fw ctl get int fwha_forw_packet_to_not_active
fwha_forw_packet_to_not_active = 0

Set value with with below commands

Enable
fw ctl set int fwha_forw_packet_to_not_active 1
Disable
fw ctl set int fwha_forw_packet_to_not_active 0

The fw ctl set int fwha_forw_packet_to_not_active 1 command enables ClusterXL to forward packets to a standby member for specific services, facilitating management access (SSH/Ping) to the standby unit

Command (for permanent solution): Edit $FWDIR/boot/modules/fwkern.conf and add fwha_forw_packet_to_not_active=1.

1 Reply
Vincent_Bacher
MVP Silver
MVP Silver

Thanks for sharing. Interesting this is still required. I haven't seen or used this setting in ages.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events