- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-18-2011 02:21 PM
I have a NLB Cluster configured for our Exchange 2010 environment. I have manually added the ARP entry for the Cluster to the interface of the PA. Everything works fine, until you make any change to the PA and commit it. Once you commit it, the PA can no longer ping the Exchange cluster and the entry in the ARP table is not present. All traffic inbound from the Internet to the Cluster shows "incomplete" in the traffic logs and ActiveSync and OWA are not accessible.
To fix the situation, the ARP entry must be removed and then re-added to the interface. This sometimes has to be done multiple times before the ARP entry shows up in the the tables and/or the cluster can be pinged.
Has anybody had this problem and been able to resolve the issue? It's a bit annoying and unacceptable to have connectivity to your email services "die" everytime you make a change to the firewall config. This symptom never occured until we replace our PIX with the PA.
03-20-2012 12:12 PM
can u fix this problem?
03-20-2012 12:19 PM
Yes, I was able to resolve this issue as it effected our environment. It was actually a pretty easy fix, once the problem was identified. I've run into the issue a couple of times since then with other "clusters" in our environment and the addition of the static ARP entry on the PA. You can give me a ring or I can add the procedure to an email.
03-20-2012 12:25 PM
thanks alot
can u add the procedura to an email?
regards
03-20-2012 12:37 PM
I am running a PA-500 with software version 4.1.1
1. Login to your PA GUI and navigate to the "Network" tab.
2. From the "Network" tab, select "Interfaces" from the left hand side and then select the interface that faces your NLB cluster.
3. From the "Ethernet Interface" window, select the "Advanced" tab and then the "ARP Entries" tab.
4. In the "ARP Entries" tab, select Add
5 Enter the IP address and MAC Address of the NLB Cluster
6. Select OK and then Commit
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!