<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static ECMP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29436#M2353</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Changed from default setting of 8 down to&amp;nbsp;2 and still shows the same in 'netstat -r | grep default'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Jun 2018 11:56:54 GMT</pubDate>
    <dc:creator>Raj_Khatri</dc:creator>
    <dc:date>2018-06-11T11:56:54Z</dc:date>
    <item>
      <title>Static ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29434#M2351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are trying to do ECMP with static routing and&amp;nbsp;have configured 2 default routes. The "show route" command shows two default next hops, however, "netstat -r" shows only one default next hop.&amp;nbsp; We currently use 2 next hops and&amp;nbsp;the ping feature to determine next hop status which seems to work well.&amp;nbsp; Does anyone know if this is achievable&amp;nbsp;to load balance using statics for default route?&amp;nbsp; I know this can be done using eBGP...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sample CLI output -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show route&lt;BR /&gt;S 0.0.0.0/0 via 1.1.1.1, eth3-01, cost 0, age 767583&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;via 1.1.1.2, eth3-01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#netstat -r&lt;BR /&gt;Kernel IP routing table&lt;BR /&gt;Destination Gateway Genmask Flags MSS Window irtt Iface&lt;BR /&gt;default 1.1.1.1 0.0.0.0 UGD 0 0 0 eth3-01&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 13:37:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29434#M2351</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2018-06-08T13:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Static ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29435#M2352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, this is supported, but you need to configure the maximum number of path splits in Gaia.&lt;/P&gt;&lt;H3 class="" style="color: #333333; background-color: inherit; font-weight: bold; text-decoration: none; font-size: 24px; margin: 0.5cm 0px 0em; padding: 20px 0pt 1px;"&gt;Configuring Equal Cost Path Splitting - Gaia Portal&lt;/H3&gt;&lt;OL class="" style="color: #333333; margin-top: 6pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;In the tree view, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Advanced Routing &amp;gt; Routing Options&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Equal Cost Multipath&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;section, select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Maximum Paths&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Apply&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 16:14:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29435#M2352</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-08T16:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Static ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29436#M2353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Changed from default setting of 8 down to&amp;nbsp;2 and still shows the same in 'netstat -r | grep default'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 11:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29436#M2353</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2018-06-11T11:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Static ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29437#M2354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's possible what you're seeing is expected.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/57909"&gt;Sundeep Mudgal&lt;/A&gt;‌, any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:21:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29437#M2354</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-11T15:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Static ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29438#M2355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;netstat might have a bug. Please try "ip r' command in expert mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:44:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29438#M2355</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2018-06-11T15:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Static ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29439#M2356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sundeep, I do see both static default routes when running "ip r"&amp;nbsp;&amp;nbsp; So it does seem like a bug with "netstat -r" output.&amp;nbsp; We have an open case with TAC who is also checking with R&amp;amp;D.&amp;nbsp; Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw&amp;gt; show route static&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; via x.x.x.230, eth3-01, cost 0, age 514897&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; via x.x.x.231, eth3-01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@fw:0]# netstat -r | grep default&lt;BR /&gt;default&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.230&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UGD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 eth3-01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@fw-:0]# ip r&lt;BR /&gt;default&amp;nbsp; proto routed&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop via x.x.x.230&amp;nbsp; dev eth3-01 weight 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop via x.x.x.231&amp;nbsp; dev eth3-01 weight 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2018 13:23:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-ECMP/m-p/29439#M2356</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2018-06-12T13:23:13Z</dc:date>
    </item>
  </channel>
</rss>

