<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Outgoing packets from cluster member NAT issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Outgoing-packets-from-cluster-member-NAT-issue/m-p/145105#M22661</link>
    <description>&lt;P&gt;Thanks for your help but unfortunately this doesn't helped me to resolve my issue.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2022 04:24:41 GMT</pubDate>
    <dc:creator>Nandhakumar</dc:creator>
    <dc:date>2022-03-31T04:24:41Z</dc:date>
    <item>
      <title>Outgoing packets from cluster member NAT issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Outgoing-packets-from-cluster-member-NAT-issue/m-p/145039#M22646</link>
      <description>&lt;P&gt;Having weird issue in Checkpoint Cluster member.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured cluster member but when i try to do telnet one of our internal server from Active node its getting succeed but same not getting succeed from Standby node.&lt;/P&gt;&lt;P&gt;When i analyzed logs, it seems active node physical interface ip is hidden behind respective interface cluster VIP IP as source.&lt;/P&gt;&lt;P&gt;In standby node, NAT not happening and it uses physical interface IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now my question, how can we make config so that standby node also nat its physical ip with cluster vip for outgoing interface. i created manual NAT rule but there is no luck.&lt;/P&gt;&lt;P&gt;Same works when i make standby node to active by failover traffic. At the same active will become standby, so in this case it will fail in this node.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 10:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Outgoing-packets-from-cluster-member-NAT-issue/m-p/145039#M22646</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2022-03-30T10:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Outgoing packets from cluster member NAT issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Outgoing-packets-from-cluster-member-NAT-issue/m-p/145064#M22651</link>
      <description>&lt;P&gt;I suggest to set your standby member as a &lt;STRONG&gt;"Silent Standby"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Set these Kernel parameters:&lt;/P&gt;&lt;P&gt;fwha_silent_standby_mode=1&lt;BR /&gt;fwha_cluster_hide_active_only=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set the same parameters in both members.&lt;/P&gt;&lt;P&gt;You can set them on the fly:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;fw ctl set int fwha_silent_standby_mode 1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;fw ctl set int&amp;nbsp; fwha_cluster_hide_active_only 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;More info:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169154&amp;amp;partition=Advanced&amp;amp;product=ClusterXL#Standby%20member%20connections" target="_self"&gt;SK169154&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To make it permanent see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk26202&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_self"&gt;sk26202&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your management is below R80.40 you will need rules for the standby to initiate connections, as these will be evaluated in policy on the active.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 13:36:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Outgoing-packets-from-cluster-member-NAT-issue/m-p/145064#M22651</guid>
      <dc:creator>Juan_</dc:creator>
      <dc:date>2022-03-30T13:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Outgoing packets from cluster member NAT issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Outgoing-packets-from-cluster-member-NAT-issue/m-p/145105#M22661</link>
      <description>&lt;P&gt;Thanks for your help but unfortunately this doesn't helped me to resolve my issue.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 04:24:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Outgoing-packets-from-cluster-member-NAT-issue/m-p/145105#M22661</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2022-03-31T04:24:41Z</dc:date>
    </item>
  </channel>
</rss>

