- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- R81.20 address problems
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R81.20 address problems
Since yesterday we are experiencing a rather unusual and strange issue with one of our 3100 R81.20 (Take 26). Traffic stopped flowing all of a sudden. From the logs it was registered going out but no inbound traffic was happening. After a lot of fumbling around, we've changed the gateway External IP address and traffic begun flowing again. This morning, same issue. Reverting the IP address back to the original solved, at least by now. Has anyone ever experienced such an problem?
Regards
Rui Meleiro
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not using VMAC mode. Nevertheless, after a power cycle to the ISP router the problem was solved as of now. I guesstimate the problem was on that router and not the appliance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like an urgent TAC case
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Rui,
ARP issue perhaps? Next time it happens, try doing a cluster failover, or if it's a single appliance run the following command:
#arping -c 4 -A -I eth1 10.20.10.20
Just replace 'eth1' with the correct interface and the IP address with whatever is configured on that interface.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your insight, Ruan. My first though was also ARP, and have flushed all dynamic ARP tables on switchs and routers, including the appliance. Not sure how an arping probe will further that, but I'll make sure to check it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What does fw ctl arp show when the issue occurs? Are you using a cluster?
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hadn't had the chance to get that while the issue was happening. At this moment - last IP address change is ongoing without any issues - I get all of the IP addresses listening on the same segment, using the same interface mac address the gateway has. Gateway IP is x.x.x.27 and IPs x.x.x.28 and x.x.x.29 are shown. This is a standalone gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We upgraded customer recently to R81.20 and only weird issue I recall they had was that lost of users had their MS teams and zoom get disconnected randomly, but it was fixed by allowing all users to access all ms teams/zoom apps by creating a rule within internal layey in network ordered layer.
I cant say why that happened, but Im fairly sure its due to R81.20, as it was never an issue before upgrade (R80.40 and R81.10)
Anyway, onto your problem. I agree with the guys, sounds like an ARP problem. Do fw ctl zrp as @Timothy_Hall advised, but I also second what @_Val_ said. It definitely warrants call to TAC, as it rather sounds like an urgent problem.
You can also simply run arp when it works and when its broken and compare.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have seen proxy ARP issues with R81.20 Take 24 so very interested to see the output of fw ctl arp when it happens. I assume you are not using VMAC mode?
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not using VMAC mode. Nevertheless, after a power cycle to the ISP router the problem was solved as of now. I guesstimate the problem was on that router and not the appliance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you all for the valuable input.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Happy to hear its fixed.
Andy
