Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor

SolarWinds Orion

Hi Mates!

The customer is experiencing intermittent ICMP DOWN  alert events reported by SolarWinds, i checked on the firewall site but i dont'see nothing realted, have any idea?
Orion polls ICMP every 3 minutes.

0 Kudos
26 Replies
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

What address is being probed is there a VPN involved or is the gateway under load?

CCSM R77/R80/ELITE
0 Kudos
RemoteUser
Advisor

Orion go out through a cluster, there is no VPN involved 

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey brother,

Are there any relevant logs in Smart Console you can see about this?

Best,
Andy
0 Kudos
RemoteUser
Advisor

the only thing that i see it is that:
dropped by fw_first_packet_state_checks Reason: ICMP reply does not match a previous request;

0 Kudos
RemoteUser
Advisor

yeah brother, i know about that, but the main purpose it's to understand why it happens

0 Kudos
the_rock
MVP Platinum
MVP Platinum

My most educated guess is assymetric routing. Thats what I always experienced, since R55 days.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey bro,

Just curious. when did this issue happen?

Best,
Andy
0 Kudos
RemoteUser
Advisor

one month ago brother

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Can you find any relevant logs around that time that could potentially help us figure out why this may have happened?

Best,
Andy
0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Any aggressive aging active log messages or cluster failover events that correspond?

CCSM R77/R80/ELITE
0 Kudos
RemoteUser
Advisor

I'm sorry, I don't understand your question.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Its aggressive aging protection, brother, check out below.

https://sc1.checkpoint.com/documents/R80.20/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R8...

Best,
Andy
0 Kudos
Shyy
Participant

Happened to me once due to asymetric routing,
I'd suggest to check the revisions and look at the changes that were probably made around the time the issue started.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey brother,

I did some more research on this and found some notes about this tool when I worked with one of our customers few years ago on some alerts and it turned out to be false positive. Can you check with the client if thats a possibility?

Best,
Andy
genisis__
MVP Silver
MVP Silver

Is this just polling a standard gateway or VSX? 

Only issue I've seen is when you attempt to ping the cluster IP and a real IP on the node.

0 Kudos
RemoteUser
Advisor

standard gw, what you mean by the real IP

0 Kudos
genisis__
MVP Silver
MVP Silver

If you are ping the cluster IP and the real IP it likely won't work on the active gateway (See SK26874),  I specifically experienced this on VSX, so may not be relevant.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

But is it cluster or single gw?

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey brother,

Any news about this?

Best,
Andy
0 Kudos
RemoteUser
Advisor

hey brother,
seems to be Asymmetric routing

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Thats what we initially thought as well.

Best,
Andy
0 Kudos
genisis__
MVP Silver
MVP Silver

Did you resolve it then?

0 Kudos
RemoteUser
Advisor

nope not yet, what kind of actions do you usually take to determine whether the issue is caused by asymmetric routing?

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey bro,

I would double check interface topology, if not sure, just set it per routing option, thats default anyway and recommended too. Now, obviously, goes without saying, dont make any changes if not sure, as it would break things.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Maybe do ip r g command to relevant IP address. Example ip r g 8.8.8.8

Best,
Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events