<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129888#M19059</link>
    <description>&lt;P&gt;Your description definitely helps us hopefully give you a step in right direction. Here are some things I would try:&lt;/P&gt;
&lt;P&gt;-if you check route to say 8.8.8.8 on CP, what do you get (from active member run ip route get 8.8.8.8)&lt;/P&gt;
&lt;P&gt;-on active fw, if you run fw monitor -e "accept host(8.8.8.8);" ...what do you see?&lt;/P&gt;
&lt;P&gt;have you tried running fw ctl zdebug | grep 8.8.8.8 while simultaneously pinging 8.8.8.8 from a duplicate window to see if anything gets dropped?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 21 Sep 2021 18:41:39 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-09-21T18:41:39Z</dc:date>
    <item>
      <title>CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129886#M19058</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I am facing a strange issue where a pair checkpoint cluster(located behind F5) unable to reach internet. We need checkpoint cluster to have internet access to download geolocation package from CP cloud, client want to enable the geolocation feature.&lt;BR /&gt;CheckPoint cluster is not holding any public IP , it will being nated at F5 when go over internet.&lt;BR /&gt;&lt;BR /&gt;Troubleshooting step that have been done:&lt;BR /&gt;-Ping from both cluster member to F5 devices is success, but ping from checkpoint cluster to external(e.g 8.8.8.8) , packet is being forwarded from gateway via output of tcpdump but no reply packet is received.&lt;/P&gt;&lt;P&gt;-Output of tcpdump in F5 showing that&amp;nbsp; echo-reply have been returned to checkpoint but checkpoint does not show any receiving of icmp reply packet. Checked in checkpoint that there is no drop in firewall rule or kernel and interfaces level.&lt;/P&gt;&lt;P&gt;-Arp table in F5 devices shows that the mac address of CheckPoint VIP is bind to active member&lt;/P&gt;&lt;P&gt;-Meanwhile, this cluster have few working site-to-site vpn tunnels that established via through F5 devices.&lt;/P&gt;&lt;P&gt;-Tried failover of cluster member, it still does not resolve the issue.&lt;/P&gt;&lt;P&gt;-We have another single distributed checkpoint gateway that connect to the same F5 devices, it is able to reach internet and download the geolocation packages.&lt;BR /&gt;&lt;BR /&gt;I am wondering where is the icmp reply packet goes? since F5 can see icmp reply is forwarded to checkpoint VIP.&lt;BR /&gt;I suspect it is related to checkpoint VIP.&lt;BR /&gt;&lt;BR /&gt;Does anyone experienced the similar issue?&lt;BR /&gt;&lt;BR /&gt;Checkpoint management server and cluster version is R80.30.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:37:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129886#M19058</guid>
      <dc:creator>Wei_Soon_Heng</dc:creator>
      <dc:date>2021-09-21T18:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129888#M19059</link>
      <description>&lt;P&gt;Your description definitely helps us hopefully give you a step in right direction. Here are some things I would try:&lt;/P&gt;
&lt;P&gt;-if you check route to say 8.8.8.8 on CP, what do you get (from active member run ip route get 8.8.8.8)&lt;/P&gt;
&lt;P&gt;-on active fw, if you run fw monitor -e "accept host(8.8.8.8);" ...what do you see?&lt;/P&gt;
&lt;P&gt;have you tried running fw ctl zdebug | grep 8.8.8.8 while simultaneously pinging 8.8.8.8 from a duplicate window to see if anything gets dropped?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:41:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129888#M19059</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-21T18:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129899#M19068</link>
      <description>&lt;P&gt;Check the mac-address are correct in the packet captures, also is "auto last hop" enabled on the F5?&amp;nbsp; (Refer:&amp;nbsp;&lt;SPAN&gt;sk83420)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 00:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129899#M19068</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-09-22T00:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129900#M19069</link>
      <description>&lt;P&gt;Adding to what Chris said, if the F5 is sending return traffic to the wrong MAC then you should look at enabling VMAC mode on the cluster.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk50840&amp;amp;t=1632275904143" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk50840&amp;amp;t=1632275904143&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 03:13:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129900#M19069</guid>
      <dc:creator>mcatanzaro</dc:creator>
      <dc:date>2021-09-22T03:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129901#M19070</link>
      <description>&lt;P&gt;-Yes, the next hop is F5 devices if the destination is external.&lt;BR /&gt;-Only inspection point o and O are seen, no reply packet as same as the output of tcpdump.&lt;BR /&gt;-No drop in output of zdebug drop&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am wondering how does vpn tunnels is working because those initiation ike traffic also pass through the same F5 devices in order to establish with their peers.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 03:21:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129901#M19070</guid>
      <dc:creator>Wei_Soon_Heng</dc:creator>
      <dc:date>2021-09-22T03:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129902#M19071</link>
      <description>&lt;P&gt;How can we check in checkpoint if the F5 is sending return traffic to wrong MAC?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 03:23:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129902#M19071</guid>
      <dc:creator>Wei_Soon_Heng</dc:creator>
      <dc:date>2021-09-22T03:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129903#M19072</link>
      <description>&lt;P&gt;You can use the -e option with tcpdump on the F5 if it supports that flag. I imagine it would but am not the most familiar with that vendor.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 03:32:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129903#M19072</guid>
      <dc:creator>mcatanzaro</dc:creator>
      <dc:date>2021-09-22T03:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cluster behind F5 Load balancer unable to reach to internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129960#M19076</link>
      <description>&lt;P&gt;f5 use linux just as system to access HW. Most (arp, tcp, ssl,...) is handled inside tmm. So you can check ARP/auto-last-hop inside tmsh&lt;BR /&gt;show sys connection cs-client-addr &amp;lt;IP-of-Firewall&amp;gt; all-properties&lt;/P&gt;&lt;P&gt;BTW: For outgoing traffic CP doesn't use VMAC!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 15:20:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Cluster-behind-F5-Load-balancer-unable-to-reach-to/m-p/129960#M19076</guid>
      <dc:creator>Daniel_</dc:creator>
      <dc:date>2021-09-22T15:20:42Z</dc:date>
    </item>
  </channel>
</rss>

