<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway not replying to pings in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64653#M12338</link>
    <description>&lt;P&gt;How are you filtering your tcpdump?&amp;nbsp; The destination IP of the ping request is being NATted from 10.x.78.1 to 10.x.78.3, is 10.x.78.3 the dedicated IP address of the active firewall?&amp;nbsp; Is there an echo request coming back sourced from 10.x.78.3?&lt;/P&gt;
&lt;P&gt;This sounds a bit like this:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk26874&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," data-hasqtip="42" aria-describedby="qtip-42" target="_blank"&gt;sk26874: Cannot simultaneously &lt;STRONG&gt;ping&lt;/STRONG&gt; Virtual IP &lt;STRONG&gt;address&lt;/STRONG&gt; of the &lt;STRONG&gt;cluster&lt;/STRONG&gt; and IP addresses of physical interfaces on &lt;STRONG&gt;cluster&lt;/STRONG&gt; members fr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2019 14:44:52 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2019-10-09T14:44:52Z</dc:date>
    <item>
      <title>Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64588#M12330</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we upgraded one Security Gateway to R80.20 and we have a really strange behavior.&lt;/P&gt;&lt;P&gt;The gateway doesn't reply to ping requests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We see logs that the request is accepted, and the tcpdump and fwmonitor shows that the requests successfully reach the gateway, but both tcpdump and fwmonitor don't show replies. Also on zdebug we don't see any drops at all.&lt;/P&gt;&lt;P&gt;We disabled SecureXL with "fwaccel off", because it has caused some problems on others upgrades and the issue persists.&lt;/P&gt;&lt;P&gt;It is really weird, and we cannot think what may cause this problem.&lt;/P&gt;&lt;P&gt;Find below tcpdump output with some requests but without replies!&lt;/P&gt;&lt;P&gt;08:27:18.461003 IP 10.x.78.154 &amp;gt; 10.x.78.1: ICMP echo request, id 6556, seq 38729, length 87&lt;BR /&gt;08:27:19.462044 IP 10.x.78.154 &amp;gt; 10.x.78.1: ICMP echo request, id 6556, seq 38730, length 87&lt;BR /&gt;08:27:20.463021 IP 10.x.78.154 &amp;gt; 10.x.78.1: ICMP echo request, id 6556, seq 38731, length 87&lt;/P&gt;&lt;P&gt;The&amp;nbsp;10.x.78.1 is the VIP of the cluster, and the server with&amp;nbsp;10.x.78.154 is an esxi that has to ping the default gateway as a Keep Alive mechanism.&lt;/P&gt;&lt;P&gt;Can you think of something to investigate, because we have reached a wall.&lt;/P&gt;&lt;P&gt;Thank you all&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 05:33:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64588#M12330</guid>
      <dc:creator>gtzakis</dc:creator>
      <dc:date>2019-10-09T05:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64589#M12331</link>
      <description>Do you have vMAC enabled? If not enable it and see how that works?&lt;BR /&gt;There is no impact in doing so, it will take a little while for the new vMAC to be used on all equipment, so give it a few minutes.&lt;BR /&gt;Also look at the latest jumbo. There have been a lot problems with R80.20, including memory leaks, that are resolved in the latest jumbo.&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Oct 2019 05:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64589#M12331</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-09T05:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64593#M12332</link>
      <description>&lt;P&gt;Can you initiate the ping to the esxi from the gateway? Is IPS active? Do you see anything in the logfiles?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 07:37:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64593#M12332</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2019-10-09T07:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64595#M12333</link>
      <description>&lt;P&gt;Yes we can initiate the ping from the gateway to esxi, and works fine.&lt;/P&gt;&lt;P&gt;IPS is not active, and the logs show that the icmp is accepted as excepted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 07:47:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64595#M12333</guid>
      <dc:creator>gtzakis</dc:creator>
      <dc:date>2019-10-09T07:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64596#M12334</link>
      <description>&lt;P&gt;Very strange. Did you check NAT-Rules and Anti-Spoofing configuration? Can you please post a censored screenshot of SmartLog?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 07:54:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64596#M12334</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2019-10-09T07:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64601#M12335</link>
      <description>&lt;P&gt;Yes we checked all of them. NATing, antispoof, static routes, anything. We couldn't find anything that's why is so strange.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 08:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64601#M12335</guid>
      <dc:creator>gtzakis</dc:creator>
      <dc:date>2019-10-09T08:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64609#M12336</link>
      <description>&lt;P&gt;Anything strange if you execute "dmesg"? Also check "netstat -s" starting at "Icmp:", you should see something like this&lt;BR /&gt;&lt;BR /&gt;XXXX ICMP messages received&lt;BR /&gt;XXX input ICMP message failed.&lt;BR /&gt;ICMP input histogram:&lt;BR /&gt;destination unreachable: XXXX&lt;BR /&gt;timeout in transit: XX&lt;BR /&gt;echo requests: XXX&lt;BR /&gt;echo replies: XX&lt;BR /&gt;XX ICMP messages sent&lt;BR /&gt;X ICMP messages failed&lt;BR /&gt;ICMP output histogram:&lt;BR /&gt;destination unreachable: X&lt;BR /&gt;time exceeded: XX&lt;BR /&gt;echo request: X&lt;BR /&gt;echo replies: XXX.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 09:39:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64609#M12336</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2019-10-09T09:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64616#M12337</link>
      <description>&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;In dmesg we don't see anything weird about the interfaces and the IPs that we see the problem.&lt;/P&gt;&lt;P&gt;Here is the netstat -s output for icmp&lt;/P&gt;&lt;P&gt;Icmp:&lt;BR /&gt;4979831 ICMP messages received&lt;BR /&gt;36 input ICMP message failed.&lt;BR /&gt;ICMP input histogram:&lt;BR /&gt;destination unreachable: 28880&lt;BR /&gt;echo requests: 4950917&lt;BR /&gt;echo replies: 28&lt;BR /&gt;984185 ICMP messages sent&lt;BR /&gt;0 ICMP messages failed&lt;BR /&gt;ICMP output histogram:&lt;BR /&gt;destination unreachable: 70178&lt;BR /&gt;time exceeded: 27&lt;BR /&gt;echo request: 36&lt;BR /&gt;echo replies: 913944&lt;BR /&gt;IcmpMsg:&lt;BR /&gt;InType0: 28&lt;BR /&gt;InType3: 28880&lt;BR /&gt;InType8: 4950917&lt;BR /&gt;OutType0: 913944&lt;BR /&gt;OutType3: 70178&lt;BR /&gt;OutType8: 36&lt;BR /&gt;OutType11: 27&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 10:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64616#M12337</guid>
      <dc:creator>gtzakis</dc:creator>
      <dc:date>2019-10-09T10:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64653#M12338</link>
      <description>&lt;P&gt;How are you filtering your tcpdump?&amp;nbsp; The destination IP of the ping request is being NATted from 10.x.78.1 to 10.x.78.3, is 10.x.78.3 the dedicated IP address of the active firewall?&amp;nbsp; Is there an echo request coming back sourced from 10.x.78.3?&lt;/P&gt;
&lt;P&gt;This sounds a bit like this:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk26874&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," data-hasqtip="42" aria-describedby="qtip-42" target="_blank"&gt;sk26874: Cannot simultaneously &lt;STRONG&gt;ping&lt;/STRONG&gt; Virtual IP &lt;STRONG&gt;address&lt;/STRONG&gt; of the &lt;STRONG&gt;cluster&lt;/STRONG&gt; and IP addresses of physical interfaces on &lt;STRONG&gt;cluster&lt;/STRONG&gt; members fr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:44:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64653#M12338</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-10-09T14:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway not replying to pings</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64697#M12339</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes the&amp;nbsp;10.x.78.3 is the original IP of the gateway interface. And yes indeed, sometimes we see an echo request from the Gateway(10.x.78.3) targeting the servers.&lt;/P&gt;&lt;P&gt;The simultaneously ping was our first thought, this one of the first changes we made to fix the issue but made things even worse for some reason.&lt;/P&gt;&lt;P&gt;Also the tcpdump is filtered like "tcpdump -nni eth2.xx host &amp;lt;server-IP&amp;gt; and icmp".&amp;nbsp; The filter is alright we see the whole traffic(and replies) if there are any.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 04:30:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-not-replying-to-pings/m-p/64697#M12339</guid>
      <dc:creator>gtzakis</dc:creator>
      <dc:date>2019-10-10T04:30:55Z</dc:date>
    </item>
  </channel>
</rss>

