<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: new interface cluster vip not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108209#M14587</link>
    <description>&lt;P&gt;Yeah, that would do it.&lt;/P&gt;
&lt;P&gt;I would suggest NOT doing "Get Interfaces with topology", if it is a production environment.&lt;/P&gt;
&lt;P&gt;Instead, open the network properties of the cluster and manually define new Cluster interface equivalent to 1.1.1.1 with 1.1.1.2 and 1.1.1.3 as members.&lt;/P&gt;
&lt;P&gt;Then publish changes and install policy.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 18:47:41 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2021-01-19T18:47:41Z</dc:date>
    <item>
      <title>new interface cluster vip not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108203#M14584</link>
      <description>&lt;P&gt;r80.40&lt;/P&gt;&lt;P&gt;new vlan interface on both fw&lt;/P&gt;&lt;P&gt;working with 2 physical fw + virtual mgmt appliance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;each fw is working fine on it's own&lt;/P&gt;&lt;P&gt;fw 1 : 1.1.1.2&lt;/P&gt;&lt;P&gt;fw 2 : 1.1.1.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vip 1.1.1.1&lt;/P&gt;&lt;P&gt;so if i set a vm with dgw of 1.1.1.2 or 3, it's working as expected per my policy&lt;/P&gt;&lt;P&gt;but if i set 1.1.1.1, not responding&lt;/P&gt;&lt;P&gt;what am i missing here? i can see the vip at the mgmt console&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 18:01:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108203#M14584</guid>
      <dc:creator>cpmatesuser2020</dc:creator>
      <dc:date>2021-01-19T18:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: new interface cluster vip not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108204#M14585</link>
      <description>&lt;P&gt;Without diving deeper into troubleshooting and if you are showing actual IPs used in your configuration, consider the possibility that the OS where you are defining 1.1.1.1 as a dgw may be aware of it as a dedicated secure DNS service IP from Clodflare.&lt;/P&gt;
&lt;P&gt;If that is the case, there may be issues declaring it a routing hop.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 18:36:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108204#M14585</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-01-19T18:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: new interface cluster vip not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108208#M14586</link>
      <description>&lt;P&gt;the 1.1.1.1 is for the example, it's actually another one&lt;/P&gt;&lt;P&gt;maybe it's because i haven't did "get interfaces" at the cluster mgmt?&lt;/P&gt;&lt;P&gt;i only did it on the firewalls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i do that on the cluster vip mgmt, i get a message warning me about changes in topology&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 18:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108208#M14586</guid>
      <dc:creator>cpmatesuser2020</dc:creator>
      <dc:date>2021-01-19T18:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: new interface cluster vip not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108209#M14587</link>
      <description>&lt;P&gt;Yeah, that would do it.&lt;/P&gt;
&lt;P&gt;I would suggest NOT doing "Get Interfaces with topology", if it is a production environment.&lt;/P&gt;
&lt;P&gt;Instead, open the network properties of the cluster and manually define new Cluster interface equivalent to 1.1.1.1 with 1.1.1.2 and 1.1.1.3 as members.&lt;/P&gt;
&lt;P&gt;Then publish changes and install policy.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 18:47:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/new-interface-cluster-vip-not-working/m-p/108209#M14587</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-01-19T18:47:41Z</dc:date>
    </item>
  </channel>
</rss>

