<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with traffic from standby member to radius in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158914#M27770</link>
    <description>&lt;P&gt;What network/interface is the Radius server located on/via relative to the firewall?&lt;/P&gt;
&lt;P&gt;When configuring the above kernel parameters did you also adjust your NAT policy to compensate?&lt;/P&gt;
&lt;P&gt;For the Radius configuration what "NAS IP Address" value is set and what is ISE configured to allow?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 14:43:59 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-10-06T14:43:59Z</dc:date>
    <item>
      <title>Problem with traffic from standby member to radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158889#M27765</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having some issues with radius authentication from standby member in a cluster that&lt;/P&gt;&lt;P&gt;consists of two open server nodes (vmware virtual machines) running R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both nodes have radius server authentication configured but it is only possible to login to the active node.&lt;/P&gt;&lt;P&gt;If we switch roles from active to standby the other node that becomes active works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have traced traffic and traffic goes from Standby node over via Active node to Radius server.&lt;/P&gt;&lt;P&gt;Radius server is responding back to cluster IP and is visible on Active node but then no return traffic is visible on the standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following steps have been made in attempts to correct the issue:&lt;/P&gt;&lt;P&gt;In VMWARE, disable Forged Mac Address on Sync portgroup&lt;/P&gt;&lt;P&gt;We have tried to toggle these Kernel parameters:&lt;/P&gt;&lt;P&gt;fwha_cluster_hide_active_only&lt;/P&gt;&lt;P&gt;fwha_silent_standby_mode&lt;/P&gt;&lt;P&gt;fwha_forw_packet_to_not_active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But no difference at all, no reboot was made just toggle the flags on the fly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions on how to further check this issue are welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Rickard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 11:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158889#M27765</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2022-10-06T11:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with traffic from standby member to radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158890#M27766</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we're also using Radius (Cisco ISE) to authenticate/authorize access on the appliance.&lt;BR /&gt;as I know we don't have any issue, as we have the appliances registered in ISE by LAN IP and Management IP address .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also I see you have them as virtual machines, our virtual ones are single appliances, so no HA there and no Radius problem also .&lt;BR /&gt;&lt;BR /&gt;when you try to perform an Radius authentication on the secondary box, can you also have an SSH session (in expert mode maybe) and do a TCPDUMP on LAN/Management towards Radius IP and see what you get there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would say it's normal to see traffic in the ACTIVE box, as you would route through that one towards RADIUS Server - not sure on your set-up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ty,&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 11:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158890#M27766</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-10-06T11:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with traffic from standby member to radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158895#M27768</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes as far as i understand the traffic flow is as expected.&lt;/P&gt;&lt;P&gt;But the problem is that return traffic does not seem to reach the standby.&lt;/P&gt;&lt;P&gt;If we listen for traffic at Radius we see traffic from Active node with cluster IP as source and return.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 12:25:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158895#M27768</guid>
      <dc:creator>nooni</dc:creator>
      <dc:date>2022-10-06T12:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with traffic from standby member to radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158912#M27769</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;If we listen for traffic at Radius we see traffic from Active node with cluster IP as source and return.&lt;/SPAN&gt;" - sorry but you have smth WRONG there.&amp;nbsp;&lt;BR /&gt;if I ask RADIUS AUTH from standby, then the RADIUS server should see the packet coming from the standby appliance (IP address).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;several details are missing, as you should not route standby traffic over ACTIVE GW, unless you have some weird routing/set-up and some NAT in place - that would explain you seeing Active Node IP on an Secondary Node return.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so can you sketch smth in paint - how are things connected and what communicates with what ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ty,&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 14:17:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158912#M27769</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-10-06T14:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with traffic from standby member to radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158914#M27770</link>
      <description>&lt;P&gt;What network/interface is the Radius server located on/via relative to the firewall?&lt;/P&gt;
&lt;P&gt;When configuring the above kernel parameters did you also adjust your NAT policy to compensate?&lt;/P&gt;
&lt;P&gt;For the Radius configuration what "NAS IP Address" value is set and what is ISE configured to allow?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 14:43:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158914#M27770</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-06T14:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with traffic from standby member to radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158926#M27773</link>
      <description>&lt;P&gt;What JHF are you on?&lt;BR /&gt;I'd ensure you're on at least the latest GA JHF.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/R80.40_Downloads.htm?tocpath=_____3" target="_blank"&gt;https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/R80.40_Downloads.htm?tocpath=_____3&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 16:21:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Problem-with-traffic-from-standby-member-to-radius/m-p/158926#M27773</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-06T16:21:03Z</dc:date>
    </item>
  </channel>
</rss>

