Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
sandeepsutar
Participant

Forwarding specific traffic from a particular cluster member(unicast LS)

Hello,

We have a ClusterXL setup with 3 members running in Load Sharing (Unicast) mode. During troubleshooting, whenever TAC needs to perform packet captures, it becomes difficult to identify which firewall member is actually processing a given flow. As a workaround, we currently check SmartConsole logs to determine which member handled the connection, and then run tcpdump or fw monitor on that specific gateway.

I’d like to improve this process. Is there any method to enforce or map a particular source host’s traffic so that it always gets handled by a specific cluster member (for example, Firewall A)?

 

Regards

0 Kudos
2 Replies
Vincent_Bacher

Hello!

Interesting question, but I've never heard of such a (supported) function.

The method that definitely works, but should of course only be carried out during a maintenance window and only if there are no problems during this step, would be to simply run “clusterXL_admin down” on the other two nodes for the duration of the test and then “clusterXL_admin up” again afterwards. If the remaining node then predictably crashes under the load, this is obviously not a particularly good idea.

I'm curious to hear the ideas of the other mates.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

There's no supported option for this that I am aware of. 

In R82 ElasticXL the connections are distributed with a basic IP address based hashing, so all connections between two specific hosts would always land on the same member gateway. I don't know the details of the decision mechanism in the old Load Sharing setup.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events