<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: traffic doesn't go to the right interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157861#M27445</link>
    <description>&lt;P&gt;this looks good, since eth1 is the external interface through which the gre tunnel naturally goes:&lt;/P&gt;&lt;P&gt;ip r g 18.185.14.90&lt;BR /&gt;18.185.14.90 via 194.xxx.xxx.xxx dev eth1 src 194.yyy.yyy.yyy&lt;BR /&gt;cache&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2022 16:30:17 GMT</pubDate>
    <dc:creator>Exonix</dc:creator>
    <dc:date>2022-09-22T16:30:17Z</dc:date>
    <item>
      <title>traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157815#M27436</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;we have GW R81.10 and some PBR. We've just found that from time to time some traffic doesn't go to the right interface - GRE for Zscaler. The strange thing is that sometimes traffic goes where it should. This is a good traffic:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gre1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17861i59B7FD0465715B41/image-size/large?v=v2&amp;amp;px=999" role="button" title="gre1.png" alt="gre1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;this is a bad traffic:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gre2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17862iDE590BC6E43AC973/image-size/large?v=v2&amp;amp;px=999" role="button" title="gre2.png" alt="gre2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as you can see the difference is only the port definition. It is always 443, but different objects.&amp;nbsp;&lt;STRONG&gt;tcp_443_noage&lt;/STRONG&gt; has the following settings (unfortunately, I do not know the purpose of this object, but it is used by some rules for VMWare and veeam):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="443.png" style="width: 595px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17863iCBA9C7AD4905A2D3/image-size/large?v=v2&amp;amp;px=999" role="button" title="443.png" alt="443.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be wrong and how to fix it?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 11:33:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157815#M27436</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-22T11:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157816#M27437</link>
      <description>&lt;P&gt;R81.30 is not a version that exists yet, do you mean R80.30?&lt;/P&gt;
&lt;P&gt;What do your PBR rules look like?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 11:36:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157816#M27437</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-22T11:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157820#M27438</link>
      <description>&lt;P&gt;it is R81.10, I've correted this information.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pbr1.png" style="width: 927px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17866iFBE687CF04016DCD/image-size/large?v=v2&amp;amp;px=999" role="button" title="pbr1.png" alt="pbr1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:23:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157820#M27438</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-22T12:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157842#M27441</link>
      <description>&lt;P&gt;oh, I was not aware you can attach PBR table based on FW rule number. How would that work if you add another rule above and the whole thing shifts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per port definition, it is probably some workaround for backup team with long running backups etc. I would suggest for regular user traffic sticking with standard https object.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe there was major PBR redesign some time ago - at least that's what I understood from release notes. We still have some incorrectly performed routing by PBR too, but on R80.40.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 13:42:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157842#M27441</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-09-22T13:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157843#M27442</link>
      <description>&lt;P&gt;Run ip r g and then IP address as a destination and verify it is indeed correct (from expert mode).&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 13:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157843#M27442</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-22T13:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157860#M27444</link>
      <description>&lt;P&gt;after adding a new rule the number in the PBR is also changed. And yes, this is not only one problem with PBR... We have another case with CP Support where we have workaround (&lt;EM&gt;adding disabled rule before impacted rule&lt;/EM&gt;) but we can't use it in my case.&lt;/P&gt;&lt;P&gt;the non-standart port is not defined in the Rule for Zscaler and appears only in the logs. How FW decides which object to use?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs1.png" style="width: 806px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17867i92542FE0C5BE70C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="logs1.png" alt="logs1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157860#M27444</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-22T16:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157861#M27445</link>
      <description>&lt;P&gt;this looks good, since eth1 is the external interface through which the gre tunnel naturally goes:&lt;/P&gt;&lt;P&gt;ip r g 18.185.14.90&lt;BR /&gt;18.185.14.90 via 194.xxx.xxx.xxx dev eth1 src 194.yyy.yyy.yyy&lt;BR /&gt;cache&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157861#M27445</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-22T16:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157948#M27488</link>
      <description>&lt;P&gt;A “different” service could be necessary if, for instance, you want certain HTTPS traffic to have a different timeout than the default.&lt;BR /&gt;I suspect there may be some issue with PBR, in which case you will probably need TAC assistance.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 18:48:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/157948#M27488</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-23T18:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158023#M27512</link>
      <description>&lt;P&gt;the problem exists for a long time already. in some cases we managed to solve it, but in this case not. We have already opened a Ticket with the Support, but they havent't found a reson and solution yet...&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 10:05:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158023#M27512</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-26T10:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158053#M27521</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The PBR matching depend on your fw rule, so it would be usefull a capture to see how it looks like. Only one object with port TCP/443 should have the option Match for Any enabled, https object has this, so disable the option on one of the objects. On the rule are using specific service objects or any? I have found that using only the FW rule as condition can be quit problematic, in some cases, the reply packets are also routed trought the destination interface instead of sending it back to the internal interface. I would try to add another condition, for example the internal interface or source IP network.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 15:18:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158053#M27521</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-09-26T15:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158193#M27561</link>
      <description>&lt;P&gt;we have two rules:&lt;/P&gt;&lt;P&gt;100 source_A destination_B tcp_443_noage&lt;/P&gt;&lt;P&gt;500 source_C destination_D any&lt;/P&gt;&lt;P&gt;for Rule 500 we configured PBR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;thanks for advice for additional&amp;nbsp;condition!&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 16:09:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158193#M27561</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-27T16:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158214#M27569</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;On rule 500, you are using service ANY. In that case, any service or service-range with option "Match for ANY" can match here. In the case of port TCP/443 you have two objects with this option enable, https and tcp_443_noage. According to&amp;nbsp;&lt;SPAN&gt;sk150553 "it is highly recommended not having any conflicting or overlapping services with Match for 'Any' on."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think the easiest way to fix this is disabling this option in tcp_443_noage. But if you need to keep the option enabled on this object so just use specific service objects on your rule 500, it would be https plus any other port you want. With that the matching traffic should always use https service object.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 17:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158214#M27569</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-09-27T17:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158805#M27736</link>
      <description>&lt;P&gt;One more question. I checked the firewall health and this is what I found.&amp;nbsp;What does it mean "FW Tables Limit"? this test failed on both nodes. Is there any limit for amount\number of the FW\NAT Rules?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FW Kernel Tables.png" style="width: 784px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18018iF1B7E224BD343F21/image-size/large?v=v2&amp;amp;px=999" role="button" title="FW Kernel Tables.png" alt="FW Kernel Tables.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 08:20:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158805#M27736</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-10-05T08:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158852#M27753</link>
      <description>&lt;P&gt;What generated this table you provided?&lt;/P&gt;
&lt;P&gt;In general, there isn't a limit on the number of rules you can have.&lt;BR /&gt;That said, there can be issues on the management when you're managing a policy with several thousand rules or more.&lt;BR /&gt;Due to the mechanisms we provide such as groups, multiple sources/destination/service per access rule, Access Roles, and others, you shouldn't actually need that many rules.&lt;BR /&gt;Most policies I've seen that are thousands of rules can often be reduced substantially through an optimization exercise.&lt;/P&gt;
&lt;P&gt;What does have limits are some of the kernel tables that we use to keep track of the various traffic going through the gateway.&lt;BR /&gt;The "peak" refers to the "high water mark" for the number of entries in the specified table.&lt;BR /&gt;Whether this points to an actual problem or not remains to be seen.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 18:48:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/158852#M27753</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-05T18:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: traffic doesn't go to the right interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/159457#M27912</link>
      <description>&lt;P&gt;that was&amp;nbsp;HealthCheckPoint:&amp;nbsp;&lt;STRONG&gt;hcp -r all --include-wts yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an Update: one branch just got the same problem, but not GRE interface related. I've created a rule before the existing rule and only for affected traffic and port 443 - it did help!!! How is it possible?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="443.2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18118iF4504174EF78CADF/image-size/large?v=v2&amp;amp;px=999" role="button" title="443.2.png" alt="443.2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 15:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-doesn-t-go-to-the-right-interface/m-p/159457#M27912</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-10-13T15:18:04Z</dc:date>
    </item>
  </channel>
</rss>

