- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Has anyone encountered issues with loss of connection state during policy installation to a Maestro cluster where the SGMs have mismatched dynamic coreXL allocations?
The main problematic traffic is SIP control connections that are very long lived. A chassis_admin failover to the standby site restores connectivity. Since the standby site starts with consistent coreXL splits across the SGMs, it makes me suspicious of the coreXL split mismatch resulting from the dynamic balancing functionality. We have another datacenter with very similar traffic profile that runs the same policy and similar maestro config, but dynamic balancing is not enabled there. That site has no issues when policy is installed.
What setting you have here under the relevant SmartConsole firewall object?
Open FW object -> Other -> Connection Persistance.
And the relevant SIP services and other used in the firewall rule. -> find the services in object list. Open and go to advanced. In here you have setting ''Keep connections open after policy has been installed"
Hi @Lloyd_Braun
And one more useful tip: change the SIP port to simple UDP/5060 without protocol detection.
Akos
This was in issue related to hyper flow sk181671. Fixed with JHF 54.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
14 | |
5 | |
4 | |
3 | |
3 | |
2 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY