Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RobertZdunek2
Explorer

Issue with Check Point Load Balancer Traffic Routing

Dear Team,

We recently configured a load balancer using the Check Point Load Balancer to distribute HTTPS traffic between two servers (Server A and Server B) using the round-robin method without session persistence. Based on my observations, the load balancer performs health checks using ICMP.

Due to specific project requirements, we needed to temporarily remove Server B from the load balancer's server group. After removing Server B from the configuration and installing the updated policy, traffic continued to be routed to Server B.

Could you please help clarify why this behavior occurred and advise on any potential misconfigurations or additional steps required to address the issue?

Thank you for your assistance.

Best regards,

Robert Zdunek

0 Kudos
7 Replies
the_rock
Legend
Legend

Hi Robert,

Can you confirm if that server is currently possibly being used elsewhere in the policy?

Andy

0 Kudos
RobertZdunek2
Explorer

Hi the_rock,

Server B object is never used directly in any policy, server group object (containing Server A and Server B) is used in two Load Balancer Objects. Load Balancer object (balancing requests to mentioned server group) that we're talking about is used twice, one for https request and one for communication on other port.

BR,

Robert

0 Kudos
the_rock
Legend
Legend

Got it. In that case, the only other place I can think of to check would be guidbedit.

Andy

0 Kudos
RobertZdunek2
Explorer

Do you know where to look for? Aren't there any magic refresh LB cache command?

 

BR,

Robert

0 Kudos
D_W
Advisor

The new policy will only affect new sessions. So you might have to manually kick existing sessions via the "fw ctl conntab -x" command. For syntax see https://support.checkpoint.com/results/sk/sk103876

0 Kudos
garrod
Contributor

I know limited resource in admin guide as well, can try to install database and install policy again to verify?

0 Kudos
RobertZdunek2
Explorer

I've done that, but it did not help.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events