8
Configuring Router Services
462
Voyager Reference Guide
The Authentication Method selected must be the same for all routers running
VRRP on the shared media network.
Monitored Circuit
Running VRRP in a static routed environment can lead to a “black hole"
failure scenario. If a link on the VRRP master fails, it may accept packets
from an end host but be unable to forward them to destinations reached via the
failed link. This creates an unnecessary black hole for those destinations if
there is an alternate path available via the VRRP backup.
The VRRP monitored circuit feature allows the virtual router master election
priority to be made dependent on the current state of the access link. With
proper selection of base priority and dynamic priority update based on
interface status, the virtual router forwarding responsibility can be made to
gracefully failover due to interface failure on the master router.
In order to utilize the monitored circuit feature, you must select a virtual
router address that does not match an interface address or any IP address
allocated to a host. The ICMP redirect messages must be disabled as well.
You can select either monitored circuit mode or VRRP v.2.
Configuring VRRP Rules for Check Point NG
When you are using Check Point NG FP1 and FP2, you must define an
explicit VRRP rule in the rulebase to allow VRRP Multicast packets to be
accepted by the gateway. It is also possible to block the VRRP traffic with an
explicitly defined rule.
Caution
The VRRP rule constructions used in Check Point FireWall-1 4.1 and
earlier does not work with Check Point NG, and using these
constructions could result in VRRP packets being dropped by the
cleanup rule.
Summary of Contents for Network Voyager
Page 1: ...Voyager Reference Guide Part No N450820002 Rev A Published December 2003 ...
Page 4: ...4 Voyager Reference Guide ...
Page 30: ...2 How to Use Voyager 30 Voyager Reference Guide ...
Page 32: ...3 Command Line Utility Files 32 Voyager Reference Guide ...
Page 220: ...5 Configuring Interfaces 220 Voyager Reference Guide ...
Page 446: ...7 Configuring Traffic Management 448 Voyager Reference Guide ...
Page 618: ...10 Configuring Security and Access 620 Voyager Reference Guide ...
Page 668: ...14 Configuring IPv6 670 Voyager Reference Guide ...
Page 672: ...15 IPSO Process Management 674 Voyager Reference Guide ...
Page 700: ...Index 702 Voyager Reference Guide ...