<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Management-HA: Address spoofing error for FW_Log when gateway sends logs cross-site in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276811#M105333</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;R82 Management High Availability (Management-HA)&lt;/LI&gt;
&lt;LI&gt;Two geographically separated offices: &lt;STRONG&gt;Office A&lt;/STRONG&gt; and &lt;STRONG&gt;Office B&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Topology&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="network.png" style="width: 629px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34229i891EB7DFB7340CC5/image-size/large?v=v2&amp;amp;px=999" role="button" title="network.png" alt="network.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue description&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Log forwarding works correctly when traffic stays local:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GW-A → Mgmt-A: &lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;GW-B → Mgmt-B: &lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;However, as soon as a gateway sends logs to the management server in the &lt;EM&gt;other&lt;/EM&gt; site, an &lt;STRONG&gt;address spoofing error for FW_Log&lt;/STRONG&gt; is triggered:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GW-A → Mgmt-B: &lt;STRONG&gt;Spoofing error&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;GW-B → Mgmt-A: &lt;STRONG&gt;Spoofing error&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The root cause appears to be that each gateway uses the same source IP regardless of which log server it targets. When the log packet traverses the inter-site link and arrives at the remote gateway, the source IP belongs to the wrong network segment, causing the receiving gateway to flag it as spoofed.&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;What I have tried / investigated&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;CODE&gt;$FWDIR/conf/masters&lt;/CODE&gt; — this file controls which log servers a gateway forwards to (the &lt;EM&gt;destination&lt;/EM&gt;), but it does not provide a way to specify which &lt;EM&gt;source IP&lt;/EM&gt; the gateway should use when initiating the log connection.&lt;/LI&gt;
&lt;LI&gt;We would prefer to &lt;STRONG&gt;avoid NAT&lt;/STRONG&gt; if at all possible.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Is there a supported method in R82 to control the source IP a gateway uses when sending logs to a specific log server?&lt;/P&gt;
&lt;P&gt;For example, GW-A has multiple interfaces. When it sends logs to Mgmt-B across the WAN, is there a way to tell it to use a specific interface IP as the source — similar to how you can pin a source interface for other connections?&lt;/P&gt;
&lt;P&gt;Any pointers to sk articles, CLI parameters, or configuration files would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 11 May 2026 22:30:29 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2026-05-11T22:30:29Z</dc:date>
    <item>
      <title>Management-HA: Address spoofing error for FW_Log when gateway sends logs cross-site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276811#M105333</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;R82 Management High Availability (Management-HA)&lt;/LI&gt;
&lt;LI&gt;Two geographically separated offices: &lt;STRONG&gt;Office A&lt;/STRONG&gt; and &lt;STRONG&gt;Office B&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Topology&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="network.png" style="width: 629px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34229i891EB7DFB7340CC5/image-size/large?v=v2&amp;amp;px=999" role="button" title="network.png" alt="network.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue description&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Log forwarding works correctly when traffic stays local:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GW-A → Mgmt-A: &lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;GW-B → Mgmt-B: &lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;However, as soon as a gateway sends logs to the management server in the &lt;EM&gt;other&lt;/EM&gt; site, an &lt;STRONG&gt;address spoofing error for FW_Log&lt;/STRONG&gt; is triggered:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GW-A → Mgmt-B: &lt;STRONG&gt;Spoofing error&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;GW-B → Mgmt-A: &lt;STRONG&gt;Spoofing error&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The root cause appears to be that each gateway uses the same source IP regardless of which log server it targets. When the log packet traverses the inter-site link and arrives at the remote gateway, the source IP belongs to the wrong network segment, causing the receiving gateway to flag it as spoofed.&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;What I have tried / investigated&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;CODE&gt;$FWDIR/conf/masters&lt;/CODE&gt; — this file controls which log servers a gateway forwards to (the &lt;EM&gt;destination&lt;/EM&gt;), but it does not provide a way to specify which &lt;EM&gt;source IP&lt;/EM&gt; the gateway should use when initiating the log connection.&lt;/LI&gt;
&lt;LI&gt;We would prefer to &lt;STRONG&gt;avoid NAT&lt;/STRONG&gt; if at all possible.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Is there a supported method in R82 to control the source IP a gateway uses when sending logs to a specific log server?&lt;/P&gt;
&lt;P&gt;For example, GW-A has multiple interfaces. When it sends logs to Mgmt-B across the WAN, is there a way to tell it to use a specific interface IP as the source — similar to how you can pin a source interface for other connections?&lt;/P&gt;
&lt;P&gt;Any pointers to sk articles, CLI parameters, or configuration files would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 22:30:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276811#M105333</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2026-05-11T22:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Management-HA: Address spoofing error for FW_Log when gateway sends logs cross-site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276812#M105334</link>
      <description>&lt;P&gt;This looks like an asymmetric routing issue on the network path between A and B. &amp;nbsp;You can also update the incoming interface on each gateway to "not check packets from" ... and select a group object containing the gateway in question.&lt;/P&gt;
&lt;P&gt;When FWD fires up and initiates the connection to the log server, it binds to the interface closest to said gateway. &amp;nbsp;It will use this interface until FWD is restarted. &amp;nbsp;This will explain why the source is always "that" IP on the gateway. There's also a logging_worker process in (at least R82.10) that I believe handles the log forwarding when gateways become disconnected.&lt;/P&gt;
&lt;P&gt;If you can afford it, and you can induce a log server failover, SSH into the problematic gateway and restart FWD manually to see if the source IP changes on a new process. &amp;nbsp;That'll give you the answer. &amp;nbsp;Then do the "don't check packets from" config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 23:38:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276812#M105334</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-05-11T23:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Management-HA: Address spoofing error for FW_Log when gateway sends logs cross-site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276821#M105337</link>
      <description>&lt;P&gt;&lt;EM&gt;"Don't check packets from"&lt;/EM&gt;&amp;nbsp;only applies to external interfaces.&lt;BR /&gt;Check Point fixed it by itself automagically by switching to another source IP:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FW1_log_spoof.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34232i0A1126EA19D27703/image-size/large?v=v2&amp;amp;px=999" role="button" title="FW1_log_spoof.png" alt="FW1_log_spoof.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 06:40:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276821#M105337</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2026-05-12T06:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: Management-HA: Address spoofing error for FW_Log when gateway sends logs cross-site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276824#M105339</link>
      <description>&lt;P&gt;This is MDS but they refer only to a NAT solution:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181701" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181701&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;But if you are going to do NAT you will get new issues like:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk163415" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk163415&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk171665" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk171665&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If issues occurs again, after a restart I would still look into above NAT solution / SK's.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 07:09:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276824#M105339</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-05-12T07:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Management-HA: Address spoofing error for FW_Log when gateway sends logs cross-site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276846#M105351</link>
      <description>&lt;P&gt;Excellent.. so FWD worked itself out after a time. &amp;nbsp;Certainly not "the best" situation, but good that it does adjust. &amp;nbsp;If this is R82 and lower, you might want to look into the log-forwarding configuration to have the gateway send over its disconnected logs to the management on an interval. &amp;nbsp;R82.10 has this enabled by default now (yay!).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 13:07:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276846#M105351</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-05-12T13:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Management-HA: Address spoofing error for FW_Log when gateway sends logs cross-site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276847#M105352</link>
      <description>&lt;P&gt;Thats true, only applies to external interface though.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 13:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-HA-Address-spoofing-error-for-FW-Log-when-gateway/m-p/276847#M105352</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-05-12T13:19:34Z</dc:date>
    </item>
  </channel>
</rss>

