<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DHCP Relay Troubles when both Cluster Members are Online in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/122792#M17572</link>
    <description>&lt;DIV&gt;Hello,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We're running R80.40 jumbo main Take 77.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We're having a strange issue, but are able to replicate it quite easily.&amp;nbsp; We have an IP subnet which relays DHCP through the checkpoint, back to our internal DHCP server (Windows) to obtain an address.&amp;nbsp; This is for our Guest network.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;With both cluster members in an "Up" state via "&lt;I&gt;clusterXL_admin up"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;as shown below, new DHCP requests fail to obtain an IP Address.&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;&amp;nbsp;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;[Expert@CP-GW5600-HA:0]# cphaprob state&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Cluster Mode: &amp;nbsp; High Availability (Active Up) with IGMP Membership&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ID &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Unique Address &amp;nbsp;Assigned Load &amp;nbsp; State &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Name&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10.5.5.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;100% &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ACTIVE&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CP-GW5600&lt;/DIV&gt;&lt;I&gt;&lt;SPAN&gt;2 (local) &amp;nbsp;10.5.5.2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0% &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;STANDBY&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CP-GW5600-HA&lt;/SPAN&gt;&lt;BR /&gt;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;If I run a "&lt;I&gt;clusterXL_admin down"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;on one of the members, it continues to not allow new client DHCP requests nor obtain an IP Address.&amp;nbsp; On the member that we "downed", if we issue a Reboot on that member and it goes offline for a couple of minutes, the active cluster member then will allow DHCP requests and new clients&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;are able&lt;/U&gt;&amp;nbsp;to&amp;nbsp;obtain an IP address.&amp;nbsp; That client will hang onto its IP address even after the downed member boots back up and goes to a STANDBY state.&amp;nbsp; If that same client forgets the network, or releases its IP Address, it is then unable to renew or obtain a new address until one of the cluster members goes offline for a reboot.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;To me, this either appears to be a bug in R80.40 Take 77, or some sort of MAC caching issue with the Cluster VIP when both members are in an Active/Standby state.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;The strange part is this happened 2 weeks ago, but rebooting one of the cluster members fixed the issue at that time.&amp;nbsp; This morning, it started happening again out of the blue with no admins working on the firewalls.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thoughts on what could be happening and how to solve it?&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Rory&lt;/DIV&gt;</description>
    <pubDate>Fri, 02 Jul 2021 04:56:56 GMT</pubDate>
    <dc:creator>00071491</dc:creator>
    <dc:date>2021-07-02T04:56:56Z</dc:date>
    <item>
      <title>DHCP Relay Troubles when both Cluster Members are Online</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/122792#M17572</link>
      <description>&lt;DIV&gt;Hello,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We're running R80.40 jumbo main Take 77.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We're having a strange issue, but are able to replicate it quite easily.&amp;nbsp; We have an IP subnet which relays DHCP through the checkpoint, back to our internal DHCP server (Windows) to obtain an address.&amp;nbsp; This is for our Guest network.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;With both cluster members in an "Up" state via "&lt;I&gt;clusterXL_admin up"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;as shown below, new DHCP requests fail to obtain an IP Address.&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;&amp;nbsp;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;[Expert@CP-GW5600-HA:0]# cphaprob state&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Cluster Mode: &amp;nbsp; High Availability (Active Up) with IGMP Membership&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ID &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Unique Address &amp;nbsp;Assigned Load &amp;nbsp; State &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Name&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10.5.5.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;100% &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ACTIVE&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CP-GW5600&lt;/DIV&gt;&lt;I&gt;&lt;SPAN&gt;2 (local) &amp;nbsp;10.5.5.2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0% &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;STANDBY&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CP-GW5600-HA&lt;/SPAN&gt;&lt;BR /&gt;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;/DIV&gt;&lt;DIV&gt;If I run a "&lt;I&gt;clusterXL_admin down"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;on one of the members, it continues to not allow new client DHCP requests nor obtain an IP Address.&amp;nbsp; On the member that we "downed", if we issue a Reboot on that member and it goes offline for a couple of minutes, the active cluster member then will allow DHCP requests and new clients&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;are able&lt;/U&gt;&amp;nbsp;to&amp;nbsp;obtain an IP address.&amp;nbsp; That client will hang onto its IP address even after the downed member boots back up and goes to a STANDBY state.&amp;nbsp; If that same client forgets the network, or releases its IP Address, it is then unable to renew or obtain a new address until one of the cluster members goes offline for a reboot.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;To me, this either appears to be a bug in R80.40 Take 77, or some sort of MAC caching issue with the Cluster VIP when both members are in an Active/Standby state.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;The strange part is this happened 2 weeks ago, but rebooting one of the cluster members fixed the issue at that time.&amp;nbsp; This morning, it started happening again out of the blue with no admins working on the firewalls.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thoughts on what could be happening and how to solve it?&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Rory&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Jul 2021 04:56:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/122792#M17572</guid>
      <dc:creator>00071491</dc:creator>
      <dc:date>2021-07-02T04:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Relay Troubles when both Cluster Members are Online</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/122794#M17573</link>
      <description>&lt;P&gt;I assume this worked previously?&lt;BR /&gt;Have you done any troubleshooting to see what the issue might be?&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97642&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97642&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 05:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/122794#M17573</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-02T05:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Relay Troubles when both Cluster Members are Online</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/122795#M17574</link>
      <description>&lt;P&gt;Hi, yes it has been working for a couple years with little to no issues until recently. We’ve been on R80.40 take 77 &amp;nbsp;for 6-8 months with no issues. I’ve been working with CP support and we started to run though that same article you listed but it’s now being escalated and plan to reach out again tomorrow. I figured I’d post here to see if anyone has any suggestions.&lt;/P&gt;&lt;P&gt;At this point, support was unable to find any dropped traffic, but the engineer wanted to escalate it to someone more familiar with tracking down these types of logs and traffic. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Rory&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 05:26:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/122795#M17574</guid>
      <dc:creator>00071491</dc:creator>
      <dc:date>2021-07-02T05:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Relay Troubles when both Cluster Members are Online</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/143599#M22323</link>
      <description>&lt;P&gt;Hi Rory - did you ever get a resolution for this problem?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Mar 2022 18:27:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-Relay-Troubles-when-both-Cluster-Members-are-Online/m-p/143599#M22323</guid>
      <dc:creator>SeanAllison</dc:creator>
      <dc:date>2022-03-13T18:27:33Z</dc:date>
    </item>
  </channel>
</rss>

