<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP Redundancy not working on R80.30 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96392#M10576</link>
    <description>&lt;P&gt;Which hosts did you monitor for the ISP-links, are these are different hosts for every ISP-link?&lt;/P&gt;
&lt;P&gt;Your „ cpstat fw“ shows „a host not responding“ for both links. If no monitored host response this ISP link will be down.&lt;/P&gt;
&lt;P&gt;To bring an ISP-link down you have to use the name of your link. In your case you should run „&lt;SPAN&gt;fw isp_link ISP-2 down“ not&amp;nbsp; „fw isp_link eth3 down“.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2020 17:43:38 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2020-09-09T17:43:38Z</dc:date>
    <item>
      <title>ISP Redundancy not working on R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96375#M10574</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I had trouble with the isp redundancy on a production environnement, because it didn't switched to the backup link when the main link failed.&lt;/P&gt;&lt;P&gt;In order to troubleshoot this issue, I created the following virtual lab, but I can't make it work as expected.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic1.png" style="width: 587px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7987iF4C4D00195D798CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic1.png" alt="pic1.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ISP failover is configured as following :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7988i89E6CCFD26119971/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic2.png" alt="pic2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And Access/ThreatPrevention Policy were installed on the cluster.&lt;/P&gt;&lt;P&gt;Now, if I shutdown the link eth0 from the Main Router, like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic3.png" style="width: 159px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7989iD3DF39443559BE23/image-size/small?v=v2&amp;amp;px=200" role="button" title="pic3.png" alt="pic3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And if I tcpdump icmp traffic on the main router, I can see the icmp response "unreachable" to the gateway which is testing the link as following :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7990iDF2E60722FA232EE/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic4.png" alt="pic4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the default gateway don't change on the active cluster member. Did I missed something ?&lt;/P&gt;&lt;P&gt;-&amp;gt; I can't ping the internet from internal lan&lt;/P&gt;&lt;P&gt;-&amp;gt; I can't ping the internet from the active gateway, and the default gateway do not change automaticaly.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7991iDD55DBA82E5C1C6A/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic5.png" alt="pic5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and if I try to make the isplink down it says no isp link :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic6.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7995i374A4A45BDF6E0EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pic6.png" alt="pic6.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;cpstat fw :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic7.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7994i18C83CBBA53C8B91/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pic7.png" alt="pic7.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you for reading.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 16:10:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96375#M10574</guid>
      <dc:creator>mistercinux</dc:creator>
      <dc:date>2020-09-09T16:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy not working on R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96387#M10575</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Well, if you shutdown the interface ( .198 ) which is not directly connected to the firewall cluster, then I guess it's a normal behavior since it's responsive/reachable from the fw in the same subnet.&lt;/P&gt;&lt;P&gt;For situations where you might experience a failure of link, like in this case, if the equipment is a cisco to create a track ip sla and monitor reachability, make decisions based on that to what happens with the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you disable the interface where the .254 ip is assigned is the behaviour changing ?&lt;/P&gt;&lt;P&gt;Do you also have multiple default static routes on the GW with different priorities ?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 16:59:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96387#M10575</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-09-09T16:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy not working on R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96392#M10576</link>
      <description>&lt;P&gt;Which hosts did you monitor for the ISP-links, are these are different hosts for every ISP-link?&lt;/P&gt;
&lt;P&gt;Your „ cpstat fw“ shows „a host not responding“ for both links. If no monitored host response this ISP link will be down.&lt;/P&gt;
&lt;P&gt;To bring an ISP-link down you have to use the name of your link. In your case you should run „&lt;SPAN&gt;fw isp_link ISP-2 down“ not&amp;nbsp; „fw isp_link eth3 down“.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 17:43:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96392#M10576</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-09-09T17:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy not working on R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96494#M10577</link>
      <description>&lt;P&gt;Hello all, and thanks for helping.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36091"&gt;@funkylicious&lt;/a&gt;&amp;nbsp;:&lt;/P&gt;&lt;P&gt;I didn't set multiple static routes in gaia because I configured the default routes in the smartconsole with isp redundancy. Shoud I also add the 2 default routes with clish on both gateways?&lt;/P&gt;&lt;P&gt;If I shutdown the .254 interface on the main router, it do not change anything.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Default route is not changed on the gateway&lt;/LI&gt;&lt;LI&gt;cpstat fw shows the same state.&lt;/LI&gt;&lt;LI&gt;According to the text in the smart console, if one of the ip fails, the link should change to isp2 no ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic10.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8026i4E79E830710423B7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pic10.png" alt="pic10.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;:&lt;/P&gt;&lt;P&gt;I have configured different monitored ip on the 2 isp links&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;@everybody :&lt;/P&gt;&lt;P&gt;In order to debug this, I turned up all interfaces on the routers, and configured 2 routes as following in gaia with clish :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;set static-route default nexthop gateway address 203.0.113.254 priority 1 on&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set static-route default nexthop gateway address 203.0.114.254 priority 2 on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Here are the tcpdumps en the .254 interfaces on both routers :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic8.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8024iB5B4DAB0A8A17C5D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pic8.png" alt="pic8.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The cpstat fw still command output this :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic9.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8025i58894D5600573719/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pic9.png" alt="pic9.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I can't understand why the 2 links are seen down since even with the 2 routers full operationnal, they are showed down in cpstat fw. (tcpdump shows the icmp response from the monitored ip on the gateway)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 15:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96494#M10577</guid>
      <dc:creator>mistercinux</dc:creator>
      <dc:date>2020-09-10T15:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy not working on R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96536#M10578</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;At this point, it's hard to figure out where the issue is, but I would start to investigate why in the ISP link table you see both ISP's ( routers ) as host not responding.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65341&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65341&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk40958" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk40958&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61692&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61692&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Then, I would start to tshoot with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;Use the fw isp_link command to force the ISP link state to Up or Down. Use this to test installation and deployment, or to force the Security Gateway to recognize the true link state if it cannot (the ISP link is down but the gateway sees it as up).

You can run this command on the Security Gateway or the Security Management Server: fw isp_link [target-gw] &amp;lt;link_name&amp;gt; {up|down}
&amp;lt;link_name&amp;gt; is the name in the ISP Link window.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can also see ISP-1 is on eth3 and ISP-2 on eth5 .If it still doesn't work, as a last resort, I would redo the &lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/150990" target="_self"&gt;configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 05:41:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/96536#M10578</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-09-11T05:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy not working on R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/99311#M10579</link>
      <description>&lt;P&gt;Hello, and sorry for the late feed back,&lt;/P&gt;&lt;P&gt;In my case, the issue was related to the "perform_cluster_hide_fold" value. (see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65341&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65341&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Thank you for your help guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 15:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-not-working-on-R80-30/m-p/99311#M10579</guid>
      <dc:creator>mistercinux</dc:creator>
      <dc:date>2020-10-16T15:11:18Z</dc:date>
    </item>
  </channel>
</rss>

