Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Tommy_Kim
Participant

UDP connectivity issue when pushed policy set with securexl off status.

We have connectivity issue mainly udp 4172 and some kind of tcp service when pushed policy set with securexl off status.

Environment with R80.20 take_17 version and clusterxl unicast mode based on 40G interfaces.

As soon as have problem, tried change to securexl on, but it wasn't resolved issue.

And we have dubug "fw ctl debug + drop | grep address " at the same time, it didn't see any drop messages.

Finally take turn to active role another unit,  then it can cleared issue.

So I wonder who have same experience our issue.

 

Thank you in advance help.

 

0 Kudos
4 Replies
G_W_Albrecht
Legend Legend
Legend

I just wonder (apart from the absence of information):

- pushed policy set with securexl off in R80.20 ? How did you do that ?

- Jumbo Take 17: Please install Take 80 or at least GA Take 47

- udp 4172: Which rule matches that traffic and is it logged ?

- when you failover again to the first node, is the issue replicated ?

- did you check the switches ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Tommy_Kim
Participant

Hi  Albrecht,

 pushed policy set with securexl off in R80.20 ? How did you do that ?

-> I did just only change from secuxl on to off status and policy installed. after the issue occurred.

Jumbo Take 17: Please install Take 80 or at least GA Take 47

-> We have plan to upgrade job soon later. before I'd like to know same issue in the another site.

udp 4172: Which rule matches that traffic and is it logged ?

-> UDP 4172 is Vdi traffic for using the vmare horizon program. I can find log and matched accept rule when have issue.

when you failover again to the first node, is the issue replicated ?

-> I didn't fail back original node, due to have same issue again.

- did you check the switches ?

-> whenever it just happen issue with pushed policy. so I don't doubt of switch side.

This issue is not ordinary, I can't expect root cause.

Thank you concern to my issue.

0 Kudos
Tommy_Kim
Participant

Hi  Albrecht,

 pushed policy set with securexl off in R80.20 ? How did you do that ?
-> I did just only change from secuxl on to off status and policy installed. after the issue occurred.

Jumbo Take 17: Please install Take 80 or at least GA Take 47
-> We have plan upgrade job soon later. before I'd like to know same issue in the another site.

udp 4172: Which rule matches that traffic and is it logged ?
-> UDP 4172 is Vdi traffic for using the vmare horizon program. I can find log and matched accept rule when have issue.

when you failover again to the first node, is the issue replicated ?
-> I didn't fail back original node, due to have same issue again.

- did you check the switches ?
-> whenever it just happen issue with pushed policy. so I don't doubt of switch side.

This issue is not ordinary, I can't expect root cause.
Thank you concern to my issue.
0 Kudos
G_W_Albrecht
Legend Legend
Legend

I would suggest to involve CP TAC here !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events