Hi everybody,

I installed a ClusterXL cluster yesterday, using Sun servers and FW-1 NG
AI (R54).  Without going into great detail, all connections through the
cluster work great.  My problem is connections that initiate from the
cluster.
Both cluster nodes resolve off name servers on one of the directly
attached DMZ networks.  DNS connections appear to come from the virtual
IP, rather than the individual node IPs.
The problem is, only one node can make a DNS request at any given time.
Also, once a node has made a request, it seems there is a certain
time-limit before the other node can make a request.  The name server
responds to all requests (discovered using snoop), but the individual
nodes just don't see the reply.
Has anyone seen this erratic behaviour before?  I would think the solution
might be to have host-initiated traffic come from the node IP, but can't
think of how to force that.
While DNS isn't critical functionality for the firewall, there are always
niggling problems when DNS isn't working.  Any thoughts people might have
would be appreciated.
Thanks,

David Aitchison.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to