segunda-feira, 21 de outubro de 2013

How to enable traffic on backup Firewall

In a clustered environment, we cannot communicate directly to the backup Firewall, an example is: ping the backup Firewall.

To solve this problem we can run this command on both Firewalls.


Run this command on all cluster members
fw ctl set int fwha_forw_packet_to_not_active 1


To set the value permanently:

Edit the $FWDIR/boot/modules/fwkern.confInclude:


Create the $FWDIR/boot/modules/fwkern.conf file, if it does not exist. The Security Gateway must be rebooted after any change in the $FWDIR/boot/modules/fwkern.conf file.*

