tobyhansen
asked on
Checkpoint NG65 - HA Failover issue with IP380 and IP390
I have an IP380 and IP380 running IPSO 4.2 HA / VRRP clustering. Active / Backup configuration. When we fail over to the IP390 everything seems to be fine for a couple days hoewever when we get a load on the device subnets and traffic start to get unresponsive completely and/or become very sluggish and inconsistant.
We have our core switch, CAT 4006, which accomodates most of our VLAN traffic, configured to point to our Checkpoint VIP for it's default route.
Before getting into much detail, has any one heard of or experiened a similar sitation?
We have our core switch, CAT 4006, which accomodates most of our VLAN traffic, configured to point to our Checkpoint VIP for it's default route.
Before getting into much detail, has any one heard of or experiened a similar sitation?
ASKER
The problem was that SecureXL was enabled on the new FW and disabled in our current environment. Once we disabled the SecureXL, connections would not increase and failover was seamless.
THank you.
THank you.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Yes, it was the SECUREXL service that was keeping this from working properly. We also uncovered a few minor configuration issues such as igmp and portfast issues.
fw ctl pstat
and look for similar type reports, ie similar sent and receive as well as no drops
also double check for cpu and ram usage