- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: adding/configuring interface causing error in ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
adding/configuring interface causing error in cluster setup - policy error
On a cluster firewall with VRRP , I have tried to configure one of the interfaces on the firewall , when I first tried with get topology but could not get the correct topology,
I have configured it on the active firewall of the cluster but when I installed the policy I am getting below error
Installation Targets Version Policy Type Details
NEWYORK-CLUSTER R77.30 Network Security The Topology information must be configured for object newyorkfw1, interface eth6, in order to use the selected features.
NEWYORK-CLUSTER R77.30 Network Security Failed to generate the rulebase
NEWYORK-CLUSTER R77.30 Network Security Operation ended with errors.
NEWYORK-CLUSTER R77.30 Network Security Operation ended with errors.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You have a cluster object NEWYORK-CLUSTER which consists of newyorkfw1 and newyorkfw2, I suppose. Open NEWYORK-CLUSTER object properties, go to Topology tab, click Edit button. There is eth6 in the list of interfaces, what type of interface is set there, cluster/private/sync? Cluster interfaces must have cluster virtual IP address defined. Right click on it, choose Edit interface, go to Topology tab, define topology. Be careful, as if you incorrectly define topology you might block access to the firewall. If it is not a cluster interface, you need to do the same for eth6 interface of the second member of the cluster.
Also if you got some topology, but didn't get the correct one, probably it is configured in a wrong way on devices themselves.
I would highly recommend to read Admin Guides before configuring firewalls.
ClusterXL Administration Guide
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would also add that personally, I would stay away from "Get Interfaces with Topology" option, except when deploying a brand new cluster.
It's been known to cause some unpleasant issues as well as creates "phantom" network objects.
IMHO, best to "Get Interfaces" and define topology manually.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I fully agree.
Jessica, configure your cluster topology consistent on both, the gateway side as well as the centrally configured management side. Stay away from reading in the topology from the getways as Vladimir recommended.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you Aleksei, Vladimir and Danny you all are the best, all working
