NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW1] Policy pushing weirdness.




Hi folks,

For a while now I've been trying to figure out a strange
problem I'm seeing with a pair of IP650's which use VRRPmc.

When I push a policy to the active firewall, I will 9 out
of 10 times have the policy downloaded but not installed,
giving the error 'connection timedout'. The other firewall
never has the problem...so if I swap the firewalls around
and make the backup the active firewall, I see the same
problem! The active (which was backup and working fine) now
installs the policy but fails with 'connection timedout' and
the backup (which was primary before and causing problems)
will install and apply the policy without problem. 

Also, whichever is primary at the time of the policy being
installed will pause for up to 30seconds and pause all 
connections...very annoying. None of my other boxes
do this weirdness.

Due to the policy being installed 10% of time I do know I have
the correct keys betweens the two firewalls, and there is no
congestion on the network which would cause these timeouts...

It's a mystery to me. If anyone has seen such behavior, please
let me know what you did to resolve this problem.

Thanks.

dave.

-- 
Dave Dunaway [[email protected]]


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.