Juniper Netscreen SSG550

Posted on 2009-02-23
Last Modified: 2012-05-06
I have 2 FW in nsrp HA active/passive mode.
when FW-A is active, everything is working, but when FW-A become passive and FW-B become active , I loose 4 networks that are on the same module.  
 the module has 4 ethernet ports.  I replaced with a new module, same problem.
at least once aday, I have to switch back to FW-A.  I don't know why it keeps switching from FW-A to FW-B and B is not working right, I have reload the firmware on FW-B and it only works for approx 45 minutes before I lost the entire 4 networks on the same module.  Any ideas, help would be appreciated.
Question by:dcs-user
    LVL 18

    Expert Comment

    Are both units exact same hardware?  ie all same PIMs etc?

    Are both units the same version of screenos too?

    What may help is get the following from each firewall:

    get nsrp

    This will show us a bit more on the config of the cluster and also what is being monitored.

    Also, when it fails over, what log entries do you have for both units?  ie when FW-A fails, are there any indications as to what caused the failover?  And for FW-B,. what does it say when the unit takes over and then subsequently fails?

    I would also compare any track-ip settings you may have on the nodes, as these settings are NOT synced across the cluster, they are device dependant.

    Author Comment

    the two units are identical, hardware and software. it used to work before with no issue, it just acting up lately.  all the interfaces are monitored, when it fails over, the log only show the FW-A become primary backup and the FW-B become master.  I don't know nor could find what trigger the fail over, but it only seems to fail over from A to B, not from B to A.

    Please give me more details on how to find and compare track-ip settings.
    LVL 18

    Expert Comment

    A "get nsrp", as above, from both nodes will give a good indication of what is configured on the cluster and from there we can then look a bit deeper.

    Author Comment

    Please see attached  
    the FW-A is 251 and and FW-B is 252
    LVL 18

    Expert Comment

    Thanks for the info here.

    The nsrp info tells me that:
    *  Both units have same priority, so if a failover occurs from A to B, when A recovers, it stays as the backup firewall
    *  Interfaces being monitored are:
    *  track-ip is disabled.
    *  RTO sync is on

    From this it would seem that an interface is failing on A to cause the initial failover from A to B.

    B seems to be in some way out of sync with A, in that when its the master, the networks do not all come up.  There may be some config out of sync between the 2 member.

    I would try the following:

    1.  Run on the backup (FW-B):
    exec nsrp sync global-config check-sum

    This will compare the config on B to that on A and tell you if it matches.

    If it does not match, do this

    exec nsrp sync global-config save

    reset but do not save config

    If this does not correct the issue, it may be prudent to rebuild the cluster.

    Given that A seems to be fine in all of this, we can use this as a base.

    1.  Take a copy of the config from A, either copy off via TFTP or use the web UI to save a copy.

    2.  Open the file in notepad, look for device specific entries.

    The main ones include:
    *  hostname
    *  NSRP priority (if needed)
    *  NSRP Pre empt (if needed)
    *  manage-ip settings
    *  physical interface info (ie speed, duplex etc)

    Edit these to reflect firewall B and save as a new config.

    Apply this config to B and reset.

    This ensures that both firewalls are completely in sync with each other and should correct the failover issues.

    If you want to have FW-A as the master whenever it is capable of doing so, we cna set the NSRP priority less than on B.

    Points to note tho, if you have a busy firewall with lots of sessions to sync etc, consider using a timer delay for taking over the mastership to give the firewalls time to sync connections.  Something like 60-90 secs is normally fine.

    Author Comment

    When  I run below command on FW-B
    exec nsrp sync global-config check-sum,
    it does not do anything, any ideas?

    LVL 18

    Accepted Solution

    Run "exec nsrp sync global-config" then hit ? to see what options you may have.

    The syntax may be slightly different on your system.

    Can you tell us what version of screenos you are running?

    Author Comment

    when I run the exec nsrp sync global-config and hit enter, it does nothing.
    it only give me the command prompt again, I believe the syntax is correct.
    the version I am running is 6.1.0r4.0
    it is wierd that a few days ago, I reloaded the same version of screenos on the FW-B, and the
    networks on the same module started to work, but it only works for approx 45.  
    everything started when I upgraded to the new firmware and later have to downgrade back to the 6.1.0r4.0, after that, the FW-A working with no issue but FW-B
    thanks for help

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
    Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    21 Experts available now in Live!

    Get 1:1 Help Now