<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw with destination host unreachable in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132084#M19532</link>
    <description>&lt;P&gt;Note that the interface name order is not the same on both nodes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are the interfaces mapped correctly according to the phisical position and their names/aliases ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean:&lt;/P&gt;&lt;P&gt;does phisical interface X really corresponds to ethX ?&lt;/P&gt;&lt;P&gt;does phisical interface Y really corresponds to ethY ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check cabling, unplug each by each one at a time and confirm that the one that goes down is really the desired one .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What about arp table ?&amp;nbsp; are they the same on the switch side ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you see correct / expected traffic on tcpdump and/or fw monitor ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 10:51:54 GMT</pubDate>
    <dc:creator>rrbranco</dc:creator>
    <dc:date>2021-10-19T10:51:54Z</dc:date>
    <item>
      <title>fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132038#M19523</link>
      <description>&lt;P&gt;Good morning,&lt;BR /&gt;it's been a few days since I migrated the backup of my production environment to completely isolated servers, in order to prepare the environment and then migrate everything to the new ones. I migrated the first node and after some problems and changing the routes, I managed to get out of it. but now I have migrated the second one and despite having changed the routes to reach the switch, it still cannot communicate with anyone but itself. I looked at all the settings that came to my mind and they are the same as what works now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;trying to ping node 1 from node 2 (node 2 is the one having problems)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14006iE8ED4C6B98926805/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 624px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14011i1734BD2D3E8DE52D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the switch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 691px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14008iBEEF96E8BD573305/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the only difference I have found that I am not sure about is this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 520px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14009i0ECC36B994078B79/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;node 1 (working)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 531px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14010iC2B40F868C7E3963/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;node 2 (not working)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to clarify that before migrating it, I had installed gaia, created the cluster and verified that everything worked, I don't think it is a physical configuration problem. any suggestions?&amp;nbsp;if you need some more data, just ask. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 07:32:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132038#M19523</guid>
      <dc:creator>fabiofabio</dc:creator>
      <dc:date>2021-10-19T07:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132054#M19524</link>
      <description>&lt;P&gt;Does the second node have any policy installed? Check it is not an initial policy. Also, unload, before you push the new one.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 08:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132054#M19524</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-10-19T08:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132072#M19526</link>
      <description>&lt;P&gt;since i can't access the webUI, i looked for the commands to manage the policies from the cli but i found almost nothing. I tried with the command&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;fw unloadlocal&lt;/EM&gt;&lt;/STRONG&gt; and then with the command &lt;STRONG&gt;&lt;EM&gt;fw fetch local&lt;/EM&gt;&lt;/STRONG&gt; but with both I had no luck.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 09:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132072#M19526</guid>
      <dc:creator>fabiofabio</dc:creator>
      <dc:date>2021-10-19T09:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132074#M19528</link>
      <description>&lt;P&gt;Make sure you are on the same network as the node, run "fw unloadlocal" and check the connectivity again. If it does not work, there is something wrong with the box.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 09:55:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132074#M19528</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-10-19T09:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132084#M19532</link>
      <description>&lt;P&gt;Note that the interface name order is not the same on both nodes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are the interfaces mapped correctly according to the phisical position and their names/aliases ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean:&lt;/P&gt;&lt;P&gt;does phisical interface X really corresponds to ethX ?&lt;/P&gt;&lt;P&gt;does phisical interface Y really corresponds to ethY ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check cabling, unplug each by each one at a time and confirm that the one that goes down is really the desired one .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What about arp table ?&amp;nbsp; are they the same on the switch side ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you see correct / expected traffic on tcpdump and/or fw monitor ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 10:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132084#M19532</guid>
      <dc:creator>rrbranco</dc:creator>
      <dc:date>2021-10-19T10:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132114#M19539</link>
      <description>&lt;P&gt;I was just about to send the same comment...thats a very good point.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/65384"&gt;@fabiofabio&lt;/a&gt;&amp;nbsp;, can you confirm what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/586"&gt;@rrbranco&lt;/a&gt;&amp;nbsp;mentioned?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 13:27:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132114#M19539</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-19T13:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132120#M19541</link>
      <description>&lt;P&gt;Try this in expert mode:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;printf "%9s%13s%10s%8s%6s\n" "Interface" "Bus Addr" "PCI-ID" "Driver" "Link?";ifconfig -a | egrep "^[^ ]" | awk '{print $1}' | egrep -v "^(lo$|usb|bond[0-9\.]+|Mgmt\.[0-9]|eth[-0-9]+\.)" | xargs -n 1 -I @ sh -c 'printf "%9s" @;printf "%13s" $(ethtool -i @ | grep "bus" | cut -d" " -f2);printf "%10s" $(lspci -n | grep $(ethtool -i @ | grep "bus" | cut -d: -f3-4) | cut -d" " -f3);printf "%8s" $(ethtool -i @ | grep "driver" | cut -d" " -f2);printf "%6s" $(ethtool @ | grep "Link" | cut -d" " -f3);echo ""'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It prints the interface name, the PCIe address, the PCI ID (used to confirm the driver is correct), the driver name, and the link status of each physical interface. Example output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[Expert@LabFW]# printf "%9s%13s%10s%8s%6s\n" "Interface" "Bus Addr" "PCI-ID" "Driver" "Link?";ifconfig -a | egrep "^[^ ]" | awk '{print $1}' | egrep -v "^(lo$|usb|bond[0-9\.]+|Mgmt\.[0-9]|eth[-0-9]+\.)" | xargs -n 1 -I @ sh -c 'printf "%9s" @;printf "%13s" $(ethtool -i @ | grep "bus" | cut -d" " -f2);printf "%10s" $(lspci -n | grep $(ethtool -i @ | grep "bus" | cut -d: -f3-4) | cut -d" " -f3);printf "%8s" $(ethtool -i @ | grep "driver" | cut -d" " -f2);printf "%6s" $(ethtool @ | grep "Link" | cut -d" " -f3);echo ""'
Interface     Bus Addr    PCI-ID  Driver Link?
     eth0 0000:07:00.0 8086:150c  e1000e    no
     eth1 0000:02:00.0 8086:150c  e1000e   yes
     eth2 0000:03:00.0 8086:150c  e1000e    no
     eth3 0000:04:00.0 8086:150c  e1000e    no
[Expert@LabFW]# &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure the interface names and the PCIe addresses match between boxes. If they don't, you can use /etc/udev/rules.d/00-OS-XX.rules to rearrange the names, as described in&amp;nbsp;&lt;SPAN&gt;sk69621.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 14:04:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132120#M19541</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-10-19T14:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: fw with destination host unreachable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132123#M19543</link>
      <description>&lt;P&gt;Perhaps the hardware discovery process was a little bit different on each box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try&amp;nbsp; :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&amp;nbsp; tail -f /var/log/messages* | grep -i eth "&amp;nbsp; and remove cables (one at a time) or shutdown the corresponding port on the switch side (one at a time) .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;verify if the interface that goes down is what you are expecting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it does not matches, see if you can try the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sk69621 -&amp;nbsp;How to change interface naming on Open Servers running Gaia OS&lt;BR /&gt;reorganize the cables to match the naming decided by the OS after the hardware discovery&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 14:13:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-with-destination-host-unreachable/m-p/132123#M19543</guid>
      <dc:creator>rrbranco</dc:creator>
      <dc:date>2021-10-19T14:13:22Z</dc:date>
    </item>
  </channel>
</rss>

