Problem with CARP-CLUSTER



  • Ive set up a CARP-CLUSTER for some month ago but I have big problems with it getting it stable.

    The problem Im experiencing is that sometimes i get big lagspikes and even get time outs on all interfaces. Often when I use multicasts and when this happens you cant even access the fw:s from the console or the webinterface. The solution when this happens is to unplug the cable for the wan-interface on fw2. Then all goes back to normal and the lag disappears.

    Is there anyone else that has experienced something like this? All help is appreciated.



  • I had similar problems and the combination of the following solved it:
    1./ My state table size was set up as too small, when it filled up there have been some connectivity problems.
    2./ 70MBps of traffic created about 90% interrupt load, which I was able to slash down with switching Polling on.
    3./ I had to switch off state table sync, since it generated too much traffic (20MBps)

    Juraj



  • @juraj_bond:

    I had similar problems and the combination of the following solved it:
    1./ My state table size was set up as too small, when it filled up there have been some connectivity problems.
    2./ 70MBps of traffic created about 90% interrupt load, which I was able to slash down with switching Polling on.
    3./ I had to switch off state table sync, since it generated too much traffic (20MBps)

    Juraj

    Thanks for helping me..

    1. My table-size is already set to 100000
    2. Tried device polling with no result.
    3. Where can I disable the sync of the state table?



  • In Firewall-Virtual IPs-Carp Settings-Synchronize Enabled.



  • @juraj_bond:

    In Firewall-Virtual IPs-Carp Settings-Synchronize Enabled.

    Yea I figured it out… Ive now tried with device polling, disabling syncing the state table, changed the table size with no result.

    Still when Im ghosting with multicast I get the same high ping issues and interrupts...


Log in to reply