Link to home
Start Free TrialLog in
Avatar of tobyhansen
tobyhansen

asked on

Checkpoint NG65 - HA Failover issue with IP380 and IP390

I have an IP380 and IP380 running IPSO 4.2 HA / VRRP clustering. Active / Backup configuration. When we fail over to the IP390 everything seems to be fine for a couple days hoewever when we get a load on the device subnets and traffic start to get unresponsive completely and/or become very sluggish and inconsistant.

We have our core switch, CAT 4006, which accomodates most of our VLAN traffic, configured to point to our Checkpoint VIP for it's default route.

Before getting into much detail, has any one heard of or experiened a similar sitation?
Avatar of deimark
deimark
Flag of United Kingdom of Great Britain and Northern Ireland image

Things to check bud are the sync net stats:

fw ctl pstat

and look for similar type reports, ie similar sent and receive as well as no drops

also double check for cpu and ram usage
Avatar of tobyhansen
tobyhansen

ASKER

The problem was that SecureXL was enabled on the new FW and disabled in our current environment. Once we disabled the SecureXL, connections would not increase and failover was seamless.

THank you.
ASKER CERTIFIED SOLUTION
Avatar of deimark
deimark
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Yes, it was the SECUREXL service that was keeping this from working properly. We also uncovered a few minor configuration issues such as igmp and portfast issues.