<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VRRP failover issue (SG6900 10Gbps) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143183#M22213</link>
    <description>&lt;P&gt;thank you for the reply.&lt;/P&gt;&lt;P&gt;However, we configured and tested the same internally,&lt;/P&gt;&lt;P&gt;and the interface at the bottom of the firewall was directly connected to each other, but the same problem occurred.&lt;/P&gt;&lt;P&gt;It doesn't appear to be a switch issue in my opinion.&lt;/P&gt;&lt;P&gt;I Think This is an obvious bug.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2022 01:26:58 GMT</pubDate>
    <dc:creator>ChoiYunSoo</dc:creator>
    <dc:date>2022-03-08T01:26:58Z</dc:date>
    <item>
      <title>VRRP failover issue (SG6900 10Gbps)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143112#M22187</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer's equipment was changed from SG23800 to SG6900 equipment.&lt;/P&gt;&lt;P&gt;Versions are R80.20 to R80.40.&lt;/P&gt;&lt;P&gt;And a 10Gbps add-on module is inserted.&lt;/P&gt;&lt;P&gt;- Line card 1 model: CPAC-4-10F-C&lt;BR /&gt;- Line card 1 type: 4 ports 1/10GbE SFP+ Rev 4.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the customer company consists only of an external interface and an internal interface, and it is VRRP.&lt;/P&gt;&lt;P&gt;As for the issue, when Bypass mode is activated in the DDOS device above the Check Point firewall, the firewall will be in the following state.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW_A,&amp;nbsp; &amp;nbsp; &amp;nbsp; External Interface = Master / Internal Interface = Master&lt;/P&gt;&lt;P&gt;FW_B,&amp;nbsp; &amp;nbsp; &amp;nbsp; External Interface = Backup / Internal Interface = Master&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tested the internal interface by directly connecting the firewall to each other, but the results were the same, and we also confirmed that the hello packet was sent normally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, SG23800 configured with R80.40 and tested with the same hotfix, but no symptoms occurred.&lt;/P&gt;&lt;P&gt;Also, when I test the UTP which is onboard on the SG6900, the symptoms do not occur.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect it is a driver firmware issue that appears when an additional module is inserted into the SG6900 or quantum device.&lt;/P&gt;&lt;P&gt;Have you ever experienced or resolved the same symptoms as me?&lt;/P&gt;&lt;P&gt;Currently, I am in the process of opening a case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS. R80.40 has been tested from No Hotfix to the latest ongoing hotfix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="22.png" style="width: 522px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15615i6ED91B662CB3F2BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="22.png" alt="22.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 09:40:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143112#M22187</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2022-03-07T09:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP failover issue (SG6900 10Gbps)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143116#M22188</link>
      <description>&lt;P&gt;Please confirm the following...&lt;/P&gt;
&lt;P&gt;* Which JHF version for R80.40?&lt;/P&gt;
&lt;P&gt;* VLANs or Physical interfaces?&lt;/P&gt;
&lt;P&gt;* Must configure firewall rule to accept VRRP packets sent from VRRP routers to multicast IP address 224.0.0.18.&lt;/P&gt;
&lt;P&gt;* When using VRRP VMAC mode, both spanning tree and IGMP snooping must be disabled to avoid split brain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 11:35:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143116#M22188</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-07T11:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP failover issue (SG6900 10Gbps)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143183#M22213</link>
      <description>&lt;P&gt;thank you for the reply.&lt;/P&gt;&lt;P&gt;However, we configured and tested the same internally,&lt;/P&gt;&lt;P&gt;and the interface at the bottom of the firewall was directly connected to each other, but the same problem occurred.&lt;/P&gt;&lt;P&gt;It doesn't appear to be a switch issue in my opinion.&lt;/P&gt;&lt;P&gt;I Think This is an obvious bug.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 01:26:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143183#M22213</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2022-03-08T01:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP failover issue (SG6900 10Gbps)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143185#M22216</link>
      <description>&lt;P&gt;Please report the case to TAC for assistance, note certain NIC card versions were only "supported" from JHF T139 GA but this doesn't appear to apply in your case.&lt;/P&gt;
&lt;TABLE class="footnote" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;PRJ-26926,&lt;BR /&gt;PMTR-69753&lt;/TD&gt;
&lt;TD&gt;Gaia OS&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;NEW&lt;/STRONG&gt;: Added support for new card 4 ports 1/10GbE SFP+ Rev 4.1.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 08 Mar 2022 02:09:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143185#M22216</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-08T02:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP failover issue (SG6900 10Gbps)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143814#M22370</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;It might help you resolve this issue if you are using "VMAC mode: VRRP".&lt;/P&gt;&lt;P&gt;# ethtool --set-priv-flags ethX disable-source-pruning on&lt;/P&gt;&lt;P&gt;I also had a similar issue.&lt;BR /&gt;In my lab it occured when I used the interface card "CPAC-4-10F-C" and the driver "i40e" and "VMAC mode: VRRP" on the interface card.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 01:11:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-failover-issue-SG6900-10Gbps/m-p/143814#M22370</guid>
      <dc:creator>Takeharu_Mineta</dc:creator>
      <dc:date>2022-03-16T01:11:45Z</dc:date>
    </item>
  </channel>
</rss>

