<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vip ip issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vip-ip-issue/m-p/23362#M1791</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where I would start is to see if your client has an ARP entry for your VIP when you try to ping or otherwise route traffic&amp;nbsp;to it.&lt;/P&gt;&lt;P&gt;If you don't see an ARP entry for the VIP, it's possible your switch isn't forwarding multicast traffic.&lt;/P&gt;&lt;P&gt;The VIP by default uses a Multicast MAC and some switches may not forward this unless configured to do so.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44898" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44898"&gt;Configuring Cisco Switch / Router to work with ClusterXL Multicast ARPs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also verify (using tcpdump) packets from the client are being received at the gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Aug 2018 23:21:39 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-08-29T23:21:39Z</dc:date>
    <item>
      <title>Vip ip issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vip-ip-issue/m-p/23361#M1790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all we have cluster deplyment in our environment , but some how one firewall is down and single firewall is working, we have one interface configured with 10.1.1.1 vip, when we confgure a server in same subnet 10.1.1.100 and we are using vip ip as aerver gateway server is unavailable. If we change the gateway with physical ip its started working even we check the maç address on switch virtual and physical ip having same mac address. Can some one look into this and give us solution?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2018 20:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vip-ip-issue/m-p/23361#M1790</guid>
      <dc:creator>AA_GSOC</dc:creator>
      <dc:date>2018-08-29T20:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Vip ip issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vip-ip-issue/m-p/23362#M1791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where I would start is to see if your client has an ARP entry for your VIP when you try to ping or otherwise route traffic&amp;nbsp;to it.&lt;/P&gt;&lt;P&gt;If you don't see an ARP entry for the VIP, it's possible your switch isn't forwarding multicast traffic.&lt;/P&gt;&lt;P&gt;The VIP by default uses a Multicast MAC and some switches may not forward this unless configured to do so.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44898" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44898"&gt;Configuring Cisco Switch / Router to work with ClusterXL Multicast ARPs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also verify (using tcpdump) packets from the client are being received at the gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2018 23:21:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vip-ip-issue/m-p/23362#M1791</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-29T23:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Vip ip issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vip-ip-issue/m-p/23363#M1792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are a number of things you can check to make sure both members are working as they should:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure 'cpconfig' shows that you can disable cluster membership&lt;/LI&gt;&lt;LI&gt;Best thing is to enable virtual MAC on the cluster page in the Smartconsole, now the MAV for the VIP should be different from the physical MAC&lt;/LI&gt;&lt;LI&gt;Look with 'cphaprob stat' what the status is according to each member.&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.checkpoint.com/"&gt;change the cluster control protocol to Broadcast &lt;/A&gt;to see if then 'cphaprob stat' shows active/standby, so you know multicast is not properly getting through your switch. Preferred would be to make multicast work and set it back to multicast.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 18:14:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vip-ip-issue/m-p/23363#M1792</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-08-30T18:14:11Z</dc:date>
    </item>
  </channel>
</rss>

