Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marcos_Perez
Participant
Jump to solution

standby's outgoing traffic leaving through sync of active node

we have two different installation which we notice this strange behaviour...one is running on r81 (latest jumbo) and the second on R80.40 (also on latest jumbo)...both installations where upgraded to this target version from an older version (in-place upgarde)...the standby node sends all outgoing traffic (allthough there is a default gateway pointing to the isp's router) to the active firewall node and this through the dedicated sync interface...

does anyone out there has experience the same issue/behaviour?

thanks...

0 Kudos
1 Solution

Accepted Solutions
G_W_Albrecht
Legend Legend
Legend
4 Replies
G_W_Albrecht
Legend Legend
Legend

sk167453: Traffic from the Standby member to any other host goes through the SYNC interface

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
Marcos_Perez
Participant

hi günther,
thanks for this link...it looks like that this is the situation...good to know this...was not aware of it...thanks

cheers

0 Kudos
Olavi_Lentso
Contributor

This topic has been raised here earlier and this means this change is not well documented in upgrade documents or in the release notes. Only knowing the kernel parameter's name already, I was able to find a small note about this change under 'Software changes' chapter of 'R80.40 Release Notes', but it is not mentioned under What's New -> Clustering, which would be a logical place to mention behavioral changes of ClusterXL.

https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RN/Topics-RN/Software-Update...

ClusterXL - the default value of the parameter "fwha_cluster_hide_active_only" was changed from 0 to 1. For more information, see sk169154 > Section 3.4 - Standby member's connections.

 

They should have added a clear statement that traffic from the Standby member to any other host goes through the SYNC interface by default and what NAT rules should be removed, once this feature is active. Like in the sk167453 mentioned by G_W_Albrecht.

 
Marcos_Perez
Participant

hi olavi,

thanks for your explanation...i read through and it is good to have an option there...

cheers

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events