<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic to secondary member of ClusterXL is dropped using VxLan in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164023#M29343</link>
    <description>&lt;P&gt;I have the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Site1 ClusterXL&amp;gt; &amp;lt;---------Site2Site IpSec Tunnel ------------&amp;gt; &amp;lt;Site 2 ClusterXL&amp;gt;&lt;/P&gt;&lt;P&gt;Member1-Site1: 10.10.171.2/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member1-Site2: 10.20.171.2/24&lt;/P&gt;&lt;P&gt;Member2-Site2: 10.10.171.3/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member2-Site2: 10.20.171.3/24&lt;/P&gt;&lt;P&gt;VIP: 10.10.171.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VIP: 10.20.171.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site 2 Site Tunnel 1 Encryption Domain: 10.11.171.0/24. Site1 has a Cluster VIP here of 10.11.171.1&lt;/P&gt;&lt;P&gt;Site 2 Site Tunnel 2 Encryption Domain: 10.12.171.0/24. Site2 has a Cluster VIP here of 10.12.171.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Across that IPSEC tunnel I have a Checkpoint Native VxLan interface pointed at back at the opposite cluster:&lt;/P&gt;&lt;P&gt;Member1-Site1: 172.31.0.2/29&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member1-Site1: 172.31.0.5/29&lt;/P&gt;&lt;P&gt;Member1-Site1: 172.31.0.3/29&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member2-Site2: 172.31.0.6/29&lt;/P&gt;&lt;P&gt;VxLan VIP Site1: 172.31.0.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VxLan VIP Site2: 172.31.0.4&lt;/P&gt;&lt;P&gt;Remote addr: 10.12.171.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Remote addr: 10.11.171.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then have a route from Site1: route 10.20.171.0/24 via 172.31.0.4&lt;/P&gt;&lt;P&gt;And a route from Site2 back: route 10.10.171.0/24 via 172.31.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This works perfectly. I can reach all hosts on 10.10.171.0/24 or 10.20.171.0/24 from either side - except for traffic headed to the standby member in the ClusterXL on the destination net.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone shed light on why this might be the case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2022 21:04:12 GMT</pubDate>
    <dc:creator>dphonovation</dc:creator>
    <dc:date>2022-12-02T21:04:12Z</dc:date>
    <item>
      <title>Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164023#M29343</link>
      <description>&lt;P&gt;I have the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Site1 ClusterXL&amp;gt; &amp;lt;---------Site2Site IpSec Tunnel ------------&amp;gt; &amp;lt;Site 2 ClusterXL&amp;gt;&lt;/P&gt;&lt;P&gt;Member1-Site1: 10.10.171.2/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member1-Site2: 10.20.171.2/24&lt;/P&gt;&lt;P&gt;Member2-Site2: 10.10.171.3/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member2-Site2: 10.20.171.3/24&lt;/P&gt;&lt;P&gt;VIP: 10.10.171.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VIP: 10.20.171.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site 2 Site Tunnel 1 Encryption Domain: 10.11.171.0/24. Site1 has a Cluster VIP here of 10.11.171.1&lt;/P&gt;&lt;P&gt;Site 2 Site Tunnel 2 Encryption Domain: 10.12.171.0/24. Site2 has a Cluster VIP here of 10.12.171.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Across that IPSEC tunnel I have a Checkpoint Native VxLan interface pointed at back at the opposite cluster:&lt;/P&gt;&lt;P&gt;Member1-Site1: 172.31.0.2/29&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member1-Site1: 172.31.0.5/29&lt;/P&gt;&lt;P&gt;Member1-Site1: 172.31.0.3/29&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Member2-Site2: 172.31.0.6/29&lt;/P&gt;&lt;P&gt;VxLan VIP Site1: 172.31.0.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VxLan VIP Site2: 172.31.0.4&lt;/P&gt;&lt;P&gt;Remote addr: 10.12.171.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Remote addr: 10.11.171.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then have a route from Site1: route 10.20.171.0/24 via 172.31.0.4&lt;/P&gt;&lt;P&gt;And a route from Site2 back: route 10.10.171.0/24 via 172.31.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This works perfectly. I can reach all hosts on 10.10.171.0/24 or 10.20.171.0/24 from either side - except for traffic headed to the standby member in the ClusterXL on the destination net.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone shed light on why this might be the case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 21:04:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164023#M29343</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-12-02T21:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164024#M29344</link>
      <description>&lt;P&gt;If you do simple zdebug what do you see? Also, if you issue command ip r g x.x.x.x (IP you are trying to reach), does it look same as one that does work?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 18:46:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164024#M29344</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T18:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164026#M29346</link>
      <description>&lt;P&gt;just saw this in zdebug. A clue!:&lt;/P&gt;&lt;P&gt;@;1464977;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=6 10.10.171.4:44698 -&amp;gt; 10.20.171.3:18192 dropped by fwha_ccl_inbound_late_do Reason: Dropping dynamic routing packet forwarded to wrong member.;&lt;BR /&gt;@;1465051;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=6 10.10.171.12:55319 -&amp;gt; 10.20.171.3:8443 dropped by fwha_ccl_inbound_late_do Reason: Dropping dynamic routing packet forwarded to wrong member.;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This doesn't seem to help either (tried on all members)&lt;BR /&gt;fwha_forw_packet_to_not_active&lt;SPAN&gt;&amp;nbsp;to&amp;nbsp;&lt;/SPAN&gt;1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 20:25:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164026#M29346</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-12-02T20:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164030#M29347</link>
      <description>&lt;P&gt;That would appear to be something routing related, for sure. What is output of ip route get for IP you are testing on both members?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 20:54:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164030#M29347</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T20:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164033#M29348</link>
      <description>&lt;P&gt;On Site 1 FW1:&lt;/P&gt;&lt;P&gt;[Expert@cp-fw1-site1:0]# ip r g 10.20.171.3&lt;BR /&gt;10.20.171.3 via 172.31.0.4 dev vxlan7 src 172.31.0.2&lt;BR /&gt;cache&lt;BR /&gt;[Expert@cp-fw1-site1:0]# ip r g 10.20.171.2&lt;BR /&gt;10.20.171.2 via 172.31.0.4 dev vxlan7 src 172.31.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Site 1 FW2:&lt;/P&gt;&lt;P&gt;[Expert@cp-fw2-site1:0]# ip r g 10.20.171.3&lt;BR /&gt;10.20.171.3 via 172.31.0.4 dev vxlan7 src 172.31.0.3&lt;BR /&gt;cache&lt;BR /&gt;[Expert@cp-fw2-site1:0]# ip r g 10.20.171.2&lt;BR /&gt;10.20.171.2 via 172.31.0.4 dev vxlan7 src 172.31.0.3&lt;BR /&gt;cache&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Site 1 FW1:&lt;/P&gt;&lt;P&gt;[Expert@cp-fw1-site2:0]# ip r g 10.10.171.3&lt;BR /&gt;10.10.171.3 via 172.31.0.1 dev vxlan7 src 172.31.0.5&lt;BR /&gt;cache&lt;BR /&gt;[Expert@cp-fw1-site2:0]# ip r g 10.10.171.2&lt;BR /&gt;10.10.171.2 via 172.31.0.1 dev vxlan7 src 172.31.0.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Site 1 FW2:&lt;/P&gt;&lt;P&gt;[Expert@cp-fw2-site2:0]# ip r g 10.10.171.3&lt;BR /&gt;10.10.171.3 via 172.31.0.1 dev vxlan7 src 172.31.0.6&lt;BR /&gt;cache&lt;BR /&gt;[Expert@cp-fw2-site2:0]# ip r g 10.10.171.2&lt;BR /&gt;10.10.171.2 via 172.31.0.1 dev vxlan7 src 172.31.0.6&lt;BR /&gt;cache&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 21:01:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164033#M29348</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-12-02T21:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164041#M29350</link>
      <description>&lt;P&gt;That seems correct. I also found below, but you already said you changed the value. Lets see what others have to say.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also, just wondering, if you compare the traceroute of working and non-working one, where is it failing?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 00:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164041#M29350</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-03T00:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164059#M29355</link>
      <description>&lt;P&gt;Well, the zdebug drop is being shown on the active member of the opposite site.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 14:15:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164059#M29355</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-12-03T14:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164066#M29357</link>
      <description>&lt;P&gt;And this is the traceroutes:&lt;BR /&gt;&lt;BR /&gt;cp-mgmt-site1&amp;gt; traceroute 10.20.171.2&lt;BR /&gt;traceroute to 10.20.171.2 (10.20.171.2), 30 hops max, 40 byte packets&lt;BR /&gt;1 10.10.171.2 (10.10.171.2) 2.053 ms 1.682 ms 2.024 ms&lt;BR /&gt;2 10.20.171.2 (10.20.171.2) 20.622 ms 20.580 ms 20.607 ms&lt;BR /&gt;cp-mgmt-site1&amp;gt; traceroute 10.20.171.3&lt;BR /&gt;traceroute to 10.20.171.3 (10.20.171.3), 30 hops max, 40 byte packets&lt;BR /&gt;1 10.10.171.2 (10.10.171.2) 2.360 ms 1.796 ms 2.323 ms&lt;BR /&gt;2 * * *&lt;BR /&gt;3 * * *&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;while the other side's active member is logging the afroomentioned drops.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's weird is that the security gateways can ping the standby fine; but I think this is due to an auto NAT rule.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 16:53:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164066#M29357</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-12-03T16:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to secondary member of ClusterXL is dropped using VxLan</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164071#M29358</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;There is something about routing to the vxlan interface from the standby. Oddly, the standby member can ping both active/standby on the other side. But it cannot ping the management server (10.10.171.4):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;In this case, FW2 at Site 2 (in standby) is trying to reach a CP MGMT box on the other side via ping.&lt;/P&gt;&lt;P&gt;FW2 at Site 2 is responding with ICMP unreachable from the IP of its member on the Clustered VxLan interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;[Expert@cp-fw2-site2:0]# ifconfig vxlan7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;vxlan7&amp;nbsp;&amp;nbsp;&amp;nbsp;Link encap:Ethernet&amp;nbsp;HWaddr 0E:61:40:26:DB:26&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;inet addr:172.31.0.6&amp;nbsp;Bcast:172.31.0.7&amp;nbsp;Mask:255.255.255.248&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;UP BROADCAST RUNNING MULTICAST&amp;nbsp;MTU:8000&amp;nbsp;Metric:1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;TX packets:2897 errors:0 dropped:0 overruns:0 carrier:0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;collisions:0 txqueuelen:1000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;RX bytes:0 (0.0 b)&amp;nbsp;TX bytes:81240 (79.3 KiB)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;[Expert@cp-fw2-site2:0]# ip r g 10.10.171.4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;10.10.171.4 via 172.31.0.1 dev vxlan7 src 172.31.0.6&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;cache&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;[Expert@cp-fw2-site2:0]# ping -c 1 172.31.0.6&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;PING 172.31.0.6 (172.31.0.6) 56(84) bytes of data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;64 bytes from 172.31.0.6: icmp_seq=1 ttl=64 time=0.079 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;--- 172.31.0.6 ping statistics ---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;1 packets transmitted, 1 received, 0% packet loss, time 0ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;rtt min/avg/max/mdev = 0.079/0.079/0.079/0.000 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;[Expert@cp-fw2-site2:0]# ping 10.10.171.4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;PING 10.10.171.4 (10.10.171.4) 56(84) bytes of data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;From 172.31.0.6 icmp_seq=1 Destination Host Unreachable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Whereas everyone else on-net with fw2-site2 (but using fw1 as its active and owns the default gateway vip) CANNOT ping the standby gateway on the other side; but can the mgmt server&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Dec 2022 14:06:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-to-secondary-member-of-ClusterXL-is-dropped-using-VxLan/m-p/164071#M29358</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-12-04T14:06:55Z</dc:date>
    </item>
  </channel>
</rss>

