<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NSX-V Redirect issue in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/NSX-V-Redirect-issue/m-p/71424#M2637</link>
    <description>Hi Javier,&lt;BR /&gt;&lt;BR /&gt;Can you please run summarize_dvfilter on the esxi server and share the output ?&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
    <pubDate>Wed, 01 Jan 2020 06:49:00 GMT</pubDate>
    <dc:creator>Kfir_Bachar</dc:creator>
    <dc:date>2020-01-01T06:49:00Z</dc:date>
    <item>
      <title>NSX-V Redirect issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NSX-V-Redirect-issue/m-p/70629#M2636</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;im working on a small nsx environment, previous to a POC on the production environment, the thing is that i have some issues putting the partner services redirection rules to work. I have some servers in 2 security groups, connected via tos logical switches and a nsx edge gw, but the trafic is only reaching the vmware distribute firewalls not the redirect ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess im missing some basic config, but the sk is confussing on not complete at least for my understanding, and mixing that with the nsx complexitiy is making me hitting my head against the wall more than what i would like, any config pieces to check ? Has anyone faced any simillar issues ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filters on the nsx manager.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;NSX-Manager&amp;gt; show dfw host host-506 filter nic-77726-eth0-vmware-sfw.2 rules&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;ruleset domain-c481 {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# generation number: 1576544216814&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# realization time : 2019-12-17T00:43:09&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1003 at 1 inout protocol ipv6-icmp icmptype 136 from any to any accept;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1003 at 2 inout protocol ipv6-icmp icmptype 135 from any to any accept;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1002 at 3 inout protocol udp from any to any port 67 accept;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1002 at 4 inout protocol udp from any to any port 68 accept;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1001 at 5 inout protocol any from any to any drop;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;}&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;ruleset domain-c481_L2 {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# generation number: 1576544216814&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# realization time : 2019-12-17T00:43:09&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1004 at 1 inout ethertype any stateless from any to any accept;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Filters specific to partner services, punt action as all the vms are under the same ESX,&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;N&lt;/FONT&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;SX-Manager&amp;gt; show dfw host host-506 filter nic-77726-eth0-serviceinstance-5.4 rules&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;ruleset 1745 {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# generation number: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# realization time : 2019-12-17T00:43:10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1777 at 1 inout protocol any from addrset ip-securitygroup-19 to any punt with log;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;rule 1775 at 2 inout protocol any from any to addrset ip-securitygroup-19 punt with log;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;}&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;ruleset 1745_L2 {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# generation number: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;# realization time : 2019-12-17T00:43:10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 09:33:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NSX-V-Redirect-issue/m-p/70629#M2636</guid>
      <dc:creator>Javier_Sanchez</dc:creator>
      <dc:date>2019-12-17T09:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-V Redirect issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NSX-V-Redirect-issue/m-p/71424#M2637</link>
      <description>Hi Javier,&lt;BR /&gt;&lt;BR /&gt;Can you please run summarize_dvfilter on the esxi server and share the output ?&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Wed, 01 Jan 2020 06:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NSX-V-Redirect-issue/m-p/71424#M2637</guid>
      <dc:creator>Kfir_Bachar</dc:creator>
      <dc:date>2020-01-01T06:49:00Z</dc:date>
    </item>
  </channel>
</rss>

