<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gaia Webui and SNMP not reachable via routing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68388#M12121</link>
    <description>&lt;P&gt;OK most likely that the WebUI etc only allowed from a local network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you can WebUI in then under&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;System Management / Host Access&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then what is it set too&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeing in the whole inbound chain in the fwmonitor so presuming you mean&lt;/P&gt;&lt;P&gt;pre-inspection i stage&lt;/P&gt;&lt;P&gt;post-inspection I stage&lt;/P&gt;&lt;P&gt;This would indicate that the traffic getting through the Security Policy, also any Address Spoofing&lt;/P&gt;&lt;P&gt;Hence why suspect that locked down under the Host Access&lt;/P&gt;&lt;P&gt;As can access from local network then process must be responding and be attempting on the correct port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2019 13:18:28 GMT</pubDate>
    <dc:creator>mdjmcnally</dc:creator>
    <dc:date>2019-11-25T13:18:28Z</dc:date>
    <item>
      <title>Gaia Webui and SNMP not reachable via routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68382#M12120</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I got the following problem:&lt;BR /&gt;Accessing Gaia from a non-lokal network fails. With another device as a jumphost in the same local network, ssh works. The incoming packets for :4434 are shown in fw monitor and are passing the complete inbound chain, but there are not outbound packets. A tcpdump does not show these packages, so the operating system and gaia webui cannot receive that traffic. A kernel debug with zdebug + drop doesn't show any dropped packages.&lt;/P&gt;&lt;P&gt;In apache access_log, no requests are seen.&lt;/P&gt;&lt;P&gt;Unfortunately it's a R77.30 on openserver, which is still in production, but other routing works perfectly on that machine.&lt;/P&gt;&lt;P&gt;I'm confused - does anybody got an idea what the problem is?&lt;/P&gt;&lt;P&gt;Best Regards&lt;BR /&gt;Johannes&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 12:37:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68382#M12120</guid>
      <dc:creator>Johannes_Schoen</dc:creator>
      <dc:date>2019-11-25T12:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Webui and SNMP not reachable via routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68388#M12121</link>
      <description>&lt;P&gt;OK most likely that the WebUI etc only allowed from a local network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you can WebUI in then under&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;System Management / Host Access&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then what is it set too&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeing in the whole inbound chain in the fwmonitor so presuming you mean&lt;/P&gt;&lt;P&gt;pre-inspection i stage&lt;/P&gt;&lt;P&gt;post-inspection I stage&lt;/P&gt;&lt;P&gt;This would indicate that the traffic getting through the Security Policy, also any Address Spoofing&lt;/P&gt;&lt;P&gt;Hence why suspect that locked down under the Host Access&lt;/P&gt;&lt;P&gt;As can access from local network then process must be responding and be attempting on the correct port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 13:18:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68388#M12121</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-11-25T13:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Webui and SNMP not reachable via routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68406#M12122</link>
      <description>Allowed-Networks are existent and my networks are allowed - I can see from Smartlog incoming 4434 to the firewall and I can see the packets in the inbound stage i and I but not on the outgoing stage o or O.&lt;BR /&gt;Address spoofing is disabled and all topology interfaces are set as external&lt;BR /&gt;In case the Allowed-Clients aren't working, is there a log to consult?</description>
      <pubDate>Mon, 25 Nov 2019 15:06:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68406#M12122</guid>
      <dc:creator>Johannes_Schoen</dc:creator>
      <dc:date>2019-11-25T15:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Webui and SNMP not reachable via routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68409#M12123</link>
      <description>&lt;P&gt;Traffic being passed by the Firewall Policy but no log on the apache server log&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sk91380 is the SK article on debugging Gaia Portal.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/var/log/httpd2_error_log&amp;nbsp; is a log file worth looking at and mentioned in the SK article&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The fact that works when local&amp;nbsp; indicates that the actual port etc itself is correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what do you get from&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show static-route destination client_ip&lt;/P&gt;&lt;P&gt;just make sure the next hop is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 15:24:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68409#M12123</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-11-25T15:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia Webui and SNMP not reachable via routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68502#M12124</link>
      <description>Routing looks good, so it's the expected routing interface, and we have production traffic on the firewalls, due to some old vpn-tunnels, still terminated at the check point.&lt;BR /&gt;&lt;BR /&gt;I helped myself with Hide-Natting the traffic with the new firewall to the Check Point node IPs and now it's working again - I won't do more troubleshooting, because of that workaround.&lt;BR /&gt;&lt;BR /&gt;Many thanks for your inputs</description>
      <pubDate>Tue, 26 Nov 2019 10:28:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-Webui-and-SNMP-not-reachable-via-routing/m-p/68502#M12124</guid>
      <dc:creator>Johannes_Schoen</dc:creator>
      <dc:date>2019-11-26T10:28:23Z</dc:date>
    </item>
  </channel>
</rss>

