Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Troubleshooting
417
213455-L, October 2005
VRRP: both masters are active
In this scenario, both the master and the backup have assumed the active role. This may be
because the firewall policy on the cluster does not permit VRRP multicast packets, which are
required for the
VRRP election
process to work (see
VRRP election on page 119
).
Actions
Log in as root and check the output of the backup interface:
Watch for VRRP advertisement packets (multicast packets) which indicate VRRP active
master activity on the interface.
If you don’t see VRRP advertisement packets, check the firewall status:
If the Policy is
DefaultFilter
or
InitialPolicy
, push policies to the firewall that allow
VRRP advertisement packets.
Poor performance under heavy traffic
In this scenario, you notice some poor performance under heavy traffic.
Make sure the management station is configured as explained in
Tuning Check Point
NGX performance on page 400
.
root# tcpdump -i eth1
Prints out packet headers on interface
root# fw stat
HOST POLICY DATE
localhost InitialPolicy 20Mar2003 10:30:10 : [>eth0] [<eth0] [>eth1]
[<eth1] [>eth2] [<eth2] [>eth3] [<eth3]
Policy = InitialPolicy