- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Delay when standby member to came up
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Delay when standby member to came up
HI Checkmates
Today i have seen new issue on cluster XL.
Environment: Distribution architecture
Version : R81.20
Hotfix : 84
Cluster members : 2 checkpoint appliances
When i do a cluster failover, secondary member takes at least 10 minutes to process the traffic. That time our all the services are goes down, after 10 minutes everything works fine. i did not observe any drops on log (smart console).
but the cluster state show active/standby states correctly. no delay on this part.
Kindly help me to sort out the new problem.
Thanks
Rajkumar T
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please send outputs of below when this happens?
Andy
**********************
cphaprob roles
cphaprob state
cphaprob -a if
cphaprob -i list
cphaprob -l list
cphaprob syncstat
********************************
Personally, never seen such an issue myself, even back in R55.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there any dynamic routing involved or are there issues with stale ARP entries?
Do the issue occur regardless of which member is active or standby?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HI Chris
There is no dynamic routing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you run any tcpdumps and/or traffic captures to see if the packets are reaching the gateway during the outage period?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like a Gratuitous ARP issue (which is the default setting), do you have VMAC set on the cluster object? That should help but if you still experience a 10-12 second delay upon failover even after setting VMAC you'll need to set portfast (NOT disable STP) on the switch ports the firewalls are connected to.
If everything is working properly, upon failover you should see the following traffic behavior:
Catastrophic Failover (active completely dies/crashes): Outage of up to 2.5 seconds
Non-Catastrophic Failover (active interface failure, clusterXL_admin down, etc.): Outage of up to 300 milliseconds
CET Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Timothy
Thanks i will try this.
Thanks
Rajkumar T
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try to toggle that option and install policy and then do a failover test and see what happens. If no change, naybe open TAC case to further investigate.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
share fw tab -t connections -s from both members at the same time.
This will show if the connections are synced.
If you like this post please give a thumbs up(kudo)! 🙂
