<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GRE in Cluster environment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/159754#M28053</link>
    <description>&lt;P&gt;I believe this is supposed to NAT behind the cluster address, as you can see here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169672&amp;amp;partition=Advanced&amp;amp;product=ClusterXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169672&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&lt;/A&gt;&lt;BR /&gt;In any case, I suspect this is a bug and the TAC will be needed to assist with this.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Oct 2022 18:43:25 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-10-17T18:43:25Z</dc:date>
    <item>
      <title>GRE in Cluster environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/159745#M28048</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;
&lt;P&gt;target: establish GRE Tunnel between a R81.10 Cluster and&amp;nbsp; a Linux Server by following &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169794&amp;amp;partition=Advanced&amp;amp;product=Quantum#Cluster" target="_self"&gt;sk169794&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Issue: in the underlay traffic (local IPs) always the cluster members IP is answering and not the Cluster IP!&lt;BR /&gt;In the screenshot you can see the remote peer 192.168.2.1 tries to reach the CP Cluster IP with 192.168.1.1 but the CP Member IP with 192.168.1.2 is answering. Is this by design? &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 640px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18149i6A25495E04D36BB8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;With this the GRE is not working because we assume the Remote System doesn't know what to do with the cluster members IP. When we set it up like a single GRE it works!&lt;/P&gt;
&lt;P&gt;KR&lt;BR /&gt;David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 15:30:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/159745#M28048</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2022-10-17T15:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: GRE in Cluster environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/159754#M28053</link>
      <description>&lt;P&gt;I believe this is supposed to NAT behind the cluster address, as you can see here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169672&amp;amp;partition=Advanced&amp;amp;product=ClusterXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169672&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&lt;/A&gt;&lt;BR /&gt;In any case, I suspect this is a bug and the TAC will be needed to assist with this.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 18:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/159754#M28053</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-17T18:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: GRE in Cluster environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/175920#M32135</link>
      <description>&lt;P&gt;Just wanted to give an update about the TAC case... TAC is still in research &lt;span class="lia-unicode-emoji" title=":sneezing_face:"&gt;🤧&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 14:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/175920#M32135</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2023-03-23T14:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: GRE in Cluster environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/178473#M32694</link>
      <description>&lt;P&gt;Just wanted to update:&lt;BR /&gt;We needed an own NAT Rule so that the response from the ClusterMembers are changed to the ClusterVIP.&lt;BR /&gt;That was the first we tried but however the NAT rule took a few hours till it matched/become active &lt;span class="lia-unicode-emoji" title=":confounded_face:"&gt;😖&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 11:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GRE-in-Cluster-environment/m-p/178473#M32694</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2023-04-19T11:57:28Z</dc:date>
    </item>
  </channel>
</rss>

