sk180531 - Cluster in High Availability mode fails to establish data connection with FTP server through VPN tunnel

Cluster in High Availability mode fails to establish data connection with FTP server through VPN tunnel

Product

ClusterXL

Version

R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

OS

Gaia

Last Modified

2024-03-13

Symptoms

Indication that Hide Active Only is enabled: the value of fw ctl get int fwha_cluster_hide_active_only is 1

Indication that Silent Standby Mode is enabled: the value of fw ctl get int fwha_silent_standby_mode is 1.

@;12852;[vs_0];[tid_2];[fw4_2];fwha_ccl_send_via_active: <dir 1, 178.100.200.253:47304 -> 172.200.190.200:49687 IPP 6> is not flagged for correction;

Cause

When the Standby cluster member opens a data connection, it sends packets to the FTP server through the Active member. After a few seconds, the Standby member stops sending packets to the FTP server through the Active member. Instead, the Standby member attempts to send the packets from its own physical interfaces. This connection fails.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2023-01-25

Last Modified: 2024-03-13