Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: Virtual Interfaces in Cluster with Fw-1 NG R55W


Status: Offline
Posts: 2
Date:
Virtual Interfaces in Cluster with Fw-1 NG R55W


Hi to everyone!

This is my first post, and first of all I want to thank phoneboy
and the whole community for the very useful contribution you
have done to people like me.

Before using this forum I have tried checking the FAQ of the
web but I have not been able to find anything related to my
particular case.

Thanks in advance for your answers or readings.

I have recently set up a two members firewall cluster over
Windows 2003 (I could not choose the platform). This configuration
has 5 different network interfaces, one for synchronization
between the members, one for the internal network, one for
the Internet (pub) and the rest for creating two DMZs.

The problem is that one of the DMZs virtual interfaces is not
visible from the subnet. This DMZ has assigned the
subnet 192.168.18.0 / 24. I have serveral servers inside this
subnet and they cannot reach the Virtual IP of the cluster
firewall for this subnet but they _can_ reach the single IPs of
both members of the cluster.

It seems that none of the firewalls is replying the ARP
requests for the virtual IP, however the Firewall responds properly
for the other interfaces and virtual IPs.

The Smart Tracker does not show me any entry about any
kind of drop, neither filter drops nor anti-spoofing.

I have reviewed several times the topology sections of both
members and the cluster and they seem to be right. Maybe
like this interface is not properly synchronized, but I cannot
imagine why.

Could anybody help me? any advice? any command to get
info or check something more useful than the smart dashboard
and tracker?

P.S: Sorry if my english is very mistaken.

__________________


Status: Offline
Posts: 2
Date:
RE: Virtual Interfaces ... More Info


I am afraid I was a little mistaken.

There is only one interface that is working properly, and the virtual IP
is accesible. The others are not, the two DMZs, and the Internet Pub,
the sync is not configured to have a virtual IP.

If we see the topology section there is no difference between the
Internal interface and one DMZ interface (IP ranges apart). And
I cannot understand this behaviour.

Has anyone found any problem with FW-1 Version R55W?
I found some problems with the general setup for the installation
and I had to install every component separately, maybe this
is related with the "apparently" wrong behaviour... (some bug?)

I will keep on trying making changes and even though maybe
I will try installing R55 and I will inform you back of the results.

Thanks to you all.



__________________
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard