<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL does can not connect to the ISP Gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6795#M290</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That looks suspiciously like this configuration (and this problem): &lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/message/8899-re-how-to-configure-external-interface-in-clusterxl?commentID=8899#comment-8899" title="https://community.checkpoint.com/message/8899-re-how-to-configure-external-interface-in-clusterxl?commentID=8899#comment-8899"&gt;https://community.checkpoint.com/message/8899-re-how-to-configure-external-interface-in-clusterxl?commentID=8899#comment…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact,&amp;nbsp;the network diagram looks nearly identical to the linked thread.&lt;/P&gt;&lt;P&gt;It may be a coincidence, of course.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To verify it is NOT a Check Point problem:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; on one of the cluster members (this unloads the firewall policy)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Attempt to ping the ISP gateway from the same cluster member&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you can&lt;STRONG&gt;&lt;EM&gt; not&lt;/EM&gt;&lt;/STRONG&gt; ping the ISP gateway in this situation, then it's&amp;nbsp;unlikely to be a Check Point issue (or it could be a basic networking issue).&lt;/P&gt;&lt;P&gt;If you can ping the ISP gateway in this situation, then:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;fw fetch localhost&lt;/STRONG&gt; to reload the policy to the cluster member&lt;/LI&gt;&lt;LI&gt;Open a second ssh session to the cluster member&lt;/LI&gt;&lt;LI&gt;Attempt to ping the ISP gateway from one session while running&amp;nbsp;&lt;STRONG&gt;tcpdump&lt;/STRONG&gt; on the other.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you can see ping packets leave your gateway and responses not come back, then it's likely an issue with your switch configuration.&lt;/P&gt;&lt;P&gt;If you can see ping packets come back and the ping is not successful, then it might be a Check Point configuration issue and I recommend working with the Check Point TAC:&amp;nbsp;&lt;A class="link-titled" href="https://www.checkpoint.com/support-services/contact-support/" title="https://www.checkpoint.com/support-services/contact-support/"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If none of this makes any sense, I strongly suggest working with your local Check Point partner&amp;nbsp;or SE who can work with you one on one.&lt;/P&gt;&lt;P&gt;If you need a pointer to who to contact, please send me a private message and I will connect you.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Sep 2017 04:35:03 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-09-29T04:35:03Z</dc:date>
    <item>
      <title>ClusterXL does can not connect to the ISP Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6790#M285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My ClusterXL&amp;nbsp; is working Load Sharing Multicast Mode but can not connect to the ISP. There is connected switch between CsusterXL and ISP. ClusterXL can connect to other devices. How to configure the ISP device or ClusterXL. The switch between the ISP and ClustrXL is Cisco catalyst 2960X. Distributed deployment and Security gateway is GAIA R80.10, Management is GAIA R80.10&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 13:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6790#M285</guid>
      <dc:creator>Choijilsuren_Ba</dc:creator>
      <dc:date>2017-09-28T13:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL does can not connect to the ISP Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6791#M286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using Load Sharing Unicast Mode and check if your ClusterXL gateways can then reach your ISP router. If that is the case, switch back to Multicast Mode and troubleshoot the Multicast configuration on your switch between the firwall cluster and the ISP router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 20:18:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6791#M286</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-09-28T20:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL does can not connect to the ISP Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6792#M287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Define "cannot connect to ISP" -- by what method are you determining this?&lt;/P&gt;&lt;P&gt;Have you:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Verified you can ping the default route from both cluster members? (Verifies basic connectivity)&lt;/LI&gt;&lt;LI&gt;Verified you can ping one hop up from the default route (determines you've set up routing correctly)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The more details you can provide&amp;nbsp;about your environment, what you've tried, what you expected, and what results you got, the more helpful the community can be.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 20:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6792#M287</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-28T20:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL does can not connect to the ISP Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6793#M288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ClusterXL is currently working production. Therefore can not moved Load sharing Unicast mode. ClusterXL is can working other cluster interfaces. Other Cluster interfaces is working normally.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Sep 2017 01:33:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6793#M288</guid>
      <dc:creator>Choijilsuren_Ba</dc:creator>
      <dc:date>2017-09-29T01:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL does can not connect to the ISP Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6794#M289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Default route configured both cluster members but&amp;nbsp; can not ping to ISP gateway.&lt;/P&gt;&lt;P&gt;Example topology:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/59188_pastedImage_2.png" style="width: 620px; height: 299px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can ping from VIP:1.1.1.4 to 1.1.1.5 and 2.2.2.2.&amp;nbsp; can not ping from VIP: 1.1.1.4 to 1.1.1.1&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Sep 2017 02:20:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6794#M289</guid>
      <dc:creator>Choijilsuren_Ba</dc:creator>
      <dc:date>2017-09-29T02:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL does can not connect to the ISP Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6795#M290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That looks suspiciously like this configuration (and this problem): &lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/message/8899-re-how-to-configure-external-interface-in-clusterxl?commentID=8899#comment-8899" title="https://community.checkpoint.com/message/8899-re-how-to-configure-external-interface-in-clusterxl?commentID=8899#comment-8899"&gt;https://community.checkpoint.com/message/8899-re-how-to-configure-external-interface-in-clusterxl?commentID=8899#comment…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact,&amp;nbsp;the network diagram looks nearly identical to the linked thread.&lt;/P&gt;&lt;P&gt;It may be a coincidence, of course.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To verify it is NOT a Check Point problem:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; on one of the cluster members (this unloads the firewall policy)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Attempt to ping the ISP gateway from the same cluster member&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you can&lt;STRONG&gt;&lt;EM&gt; not&lt;/EM&gt;&lt;/STRONG&gt; ping the ISP gateway in this situation, then it's&amp;nbsp;unlikely to be a Check Point issue (or it could be a basic networking issue).&lt;/P&gt;&lt;P&gt;If you can ping the ISP gateway in this situation, then:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;fw fetch localhost&lt;/STRONG&gt; to reload the policy to the cluster member&lt;/LI&gt;&lt;LI&gt;Open a second ssh session to the cluster member&lt;/LI&gt;&lt;LI&gt;Attempt to ping the ISP gateway from one session while running&amp;nbsp;&lt;STRONG&gt;tcpdump&lt;/STRONG&gt; on the other.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you can see ping packets leave your gateway and responses not come back, then it's likely an issue with your switch configuration.&lt;/P&gt;&lt;P&gt;If you can see ping packets come back and the ping is not successful, then it might be a Check Point configuration issue and I recommend working with the Check Point TAC:&amp;nbsp;&lt;A class="link-titled" href="https://www.checkpoint.com/support-services/contact-support/" title="https://www.checkpoint.com/support-services/contact-support/"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If none of this makes any sense, I strongly suggest working with your local Check Point partner&amp;nbsp;or SE who can work with you one on one.&lt;/P&gt;&lt;P&gt;If you need a pointer to who to contact, please send me a private message and I will connect you.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Sep 2017 04:35:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-does-can-not-connect-to-the-ISP-Gateway/m-p/6795#M290</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-29T04:35:03Z</dc:date>
    </item>
  </channel>
</rss>

