- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Issue with Check Point Load Balancer Traffic R...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Issue with Check Point Load Balancer Traffic Routing
Dear Team,
We recently configured a load balancer using the Check Point Load Balancer to distribute HTTPS traffic between two servers (Server A and Server B) using the round-robin method without session persistence. Based on my observations, the load balancer performs health checks using ICMP.
Due to specific project requirements, we needed to temporarily remove Server B from the load balancer's server group. After removing Server B from the configuration and installing the updated policy, traffic continued to be routed to Server B.
Could you please help clarify why this behavior occurred and advise on any potential misconfigurations or additional steps required to address the issue?
Thank you for your assistance.
Best regards,
Robert Zdunek
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Robert,
Can you confirm if that server is currently possibly being used elsewhere in the policy?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi the_rock,
Server B object is never used directly in any policy, server group object (containing Server A and Server B) is used in two Load Balancer Objects. Load Balancer object (balancing requests to mentioned server group) that we're talking about is used twice, one for https request and one for communication on other port.
BR,
Robert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Got it. In that case, the only other place I can think of to check would be guidbedit.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you know where to look for? Aren't there any magic refresh LB cache command?
BR,
Robert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The new policy will only affect new sessions. So you might have to manually kick existing sessions via the "fw ctl conntab -x" command. For syntax see https://support.checkpoint.com/results/sk/sk103876
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know limited resource in admin guide as well, can try to install database and install policy again to verify?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've done that, but it did not help.
