Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Checkpoint NGX R65 Anti-spoofing issues

Status
Not open for further replies.

rickrude11

IS-IT--Management
Jul 15, 2007
71
NZ
Hey guys, I have a 2 node cluster, just upgraded from R60 to R65. Only 1 firewall is active at the moment because when I bring the other one up, both fw become active.

I found that I cannot even ping ANY internal interface of the active firewall from the other firewall box. In the tracker it reports 'cluster member ip is spoofed' or words to that effect. This i guess is why the cluster is not happening. this policy is taken directly from the R60 management server.

my topology is correct, i am sure of that. The sync network is a dedicated interface (eth1) on the same segment (vlan99)

these are fresh installs.

any input really appreciated. Any direction to look even.
 
find the policy object that is that firewall under manage ,network objects , highlight the object, fw, edit

look at the topology option , in there it should list all your interfaces if you edit these there is an option to enable antispoofing , it shouldn't be ticked if you have designed your network without taking into account the antispoofing setup , in the ideal world they should all be ticked, the antispoofing works by knowing about all the networks that pass through it and knowing what interface to expect the requests on , it means declaring all internal subnets etc.

for testing tho just untick
 
ok i am now running without antispoofing enabled and it works. i can ping all checkpoint interfaces from each node.

i feel vulnerable now :(



 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top