
Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
416
Troubleshooting
213455-L, October 2005
VRRP: active master backup fails
In this scenario, the active master fails, but failover doesn’t take place. A likely cause is loss of
trust between the firewall and the SmartCenter Server.
Actions
Log in as root and check the firewall status:
If the SmartCenter Server and the firewall are not communicating, the firewall will return
a status message indicating that the policy and host identities are unknown:
You can repair this condition by reestablishing trust with the firewall.
Open the SMART Client application and verify the SIC status between the management
station and the firewall. If, as suspected, the devices are not communicating:
Reset SIC at the SMART Client (see
Re-establishing SIC on page 410
) and at the CLI
(see
/cfg/fw/sync on page 361
).
Push policies from the SmartCenter Server to the firewall.
After SIC completes (which may take several minutes) log back in to the firewall as root
and check the firewall status:
This status message indicates that trust has been established. When trust is established on
a system running VRRP, failover should take place in less than 1 second.
N
OTE
–
The policy must allow VRRP advertisement (multicast) packets for VRRP failover to
work properly.
root# fw stat
HOST POLICY DATE
-- --- --- [>eth0] [<eth0] [>eth1] [<eth1] [>eth2]
[<eth2] [>eth3] [<eth3]
root# fw stat
HOST POLICY DATE
localhost VRRP 14Mar2003 14:08:05 : [>eth0] [<eth0] [>eth1]
[<eth1] [>eth2] [<eth2] [>eth3] [<eth3]