Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Troubleshooting
413
213455-L, October 2005
Action
Increase the session limit on the management station. Refer to
Tuning Check Point NGX
performance on page 400
.
Check Point synchronization
Use the Check Point Sync function to enable or disable session state synchronization between
clustered firewalls in a redundant configuration.
Message appears after checking synchronization status
Scenario
: The message, HA module not started, appears after you check the synchronization
status using the CLI command /maint/fw/sync.
Actions
Invoke the Firewall CLI command, /cfg/fw/sync/ena, to verify that Check Point Sync is
enabled.
Verify the cluster configuration on the SmartCenter Server and ensure that at least one
interface is defined for Sync.
Verify that the State Synchronization option on the SmartCenter Server is selected.
TIP
: To verify that 1 sync is selected, go to the Gateway Cluster Properties page, select
Topology
, select
Edit
Topology. The Edit Topology appears.
Reestablish the trust between the SmartCenter Server and the Firewalls, as required.
TIP
: If communication fails, reset the SIC. To verify communication, go to the Gateway
Cluster Properties page. Select
Cluster Member
. Double-click the
Firewall object
.
Select
Communication
. Select
Test SIC status
.
Push the policy from the SmartCenter server to the Firewall..