<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy push overwrote default route on cluster active gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164613#M29492</link>
    <description>&lt;P&gt;Sure i will share it on Sunday as i am not in front a laptop, its not only bgp but dynamic routing with ispr.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2022 12:36:46 GMT</pubDate>
    <dc:creator>Ilya_Yusupov</dc:creator>
    <dc:date>2022-12-09T12:36:46Z</dc:date>
    <item>
      <title>Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163097#M29087</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I really hope someone can shed some light with this. So, one of our colleagues went into client's environment (they use smart-1 cloud) and 6000 series cluster and simply added couple of IP addresses to block group and once policy was applied, we noticed that active member could not be accessed.&lt;/P&gt;
&lt;P&gt;At this point, thankfully, ssh to backup worked fine, so once we ssh-ed to active from backup, noticed that default route was gone. Now, in my 15 years with CP, I had NEVER seen or heard of problem like this. Keep in mind, failover never happened, however, there was Internet outage, as default route was gone. Default route was added back via clish afterwards and we did push policy couple of times afterwards and it was fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, just to try and figure this out ourselves, we downloaded audit.log from /var/log/audit dir, but it was not useful at all, as it does not have any timestamps, but we searched for words, such as route, default, delete, but no luck. We are 99.99% sure that something else caused this, rather than policy push, but really hard to say what at this point.&lt;/P&gt;
&lt;P&gt;Also checked /var/log/messages files, but no luck there either. There was no one who was even logged into firewalls before this issue happened, so it begs the question HOW this happened.&lt;/P&gt;
&lt;P&gt;We ended up opening TAC case for it, but after doing zoom meeting, gentleman told us would consult further internally and see what else can be done to try and find the reason.&lt;/P&gt;
&lt;P&gt;If anyone else has an idea or any other file(s) we could check, it would be greatly appreciated!&lt;/P&gt;
&lt;P&gt;Thanks as always.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 00:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163097#M29087</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-25T00:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163151#M29102</link>
      <description>&lt;P&gt;As a newcomer at Checkpoint just a shot in the dark: is a CloningGroup defined? We once had strange effects with it (admin, cadmin ...), there were also accesses to cluster members lost (but not the default route &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&amp;nbsp; But Routing is group feature ...&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 09:34:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163151#M29102</guid>
      <dc:creator>DirkB</dc:creator>
      <dc:date>2022-11-25T09:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163171#M29108</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70315"&gt;@DirkB&lt;/a&gt;&amp;nbsp;, thanks for the response, but thats definitely not it, sorry. Lets see what TAC comes back with, as we are totally out of ideas where to even look next, as we checked everything we could humanly think of.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 11:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163171#M29108</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-25T11:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163173#M29109</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You could check /var/log/routed.log. May be more info in it.&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 11:42:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163173#M29109</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2022-11-25T11:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163175#M29110</link>
      <description>&lt;P&gt;Ok, thats good idea, ty, will check that in couple hours and report back.&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 11:46:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163175#M29110</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-25T11:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163180#M29112</link>
      <description>&lt;P&gt;only stupid casually if DHCP (I don't know &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ):Are Kernel Routes activated,&amp;nbsp;&lt;SPAN&gt;Kernel Routes are not activated by default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is Ping activated for the default route? If so, I think the route is deleted from table per design, &lt;STRONG&gt;if ping fails (or failed&amp;nbsp;temporary) to next hop&lt;/STRONG&gt; (and readded, if Ping&amp;nbsp;succeeds) ...&amp;nbsp;but it would be unclear to me how the static entries would be accessed - perhaps with save config (with the policies) ... wich is the timestamp of configs (can you track an order?). Perhaps just a coincidence in time.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 12:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163180#M29112</guid>
      <dc:creator>DirkB</dc:creator>
      <dc:date>2022-11-25T12:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163183#M29113</link>
      <description>&lt;P&gt;I dont personally think that would have anything to do with it, regardless about the ping failing. Let us see what TAC says next, because we absolutely have to give a reason to the customer, this cannot happen again, specially given the fact it caused Internet outage.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 12:26:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163183#M29113</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-25T12:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163184#M29114</link>
      <description>&lt;P&gt;I attached a file with relevant times when it happened and messages from routed_messages and routed.log. Not sure if they matter, but I saw same messages for the last year, so hard to believe its relevant, but who knows : - )&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 12:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/163184#M29114</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-25T12:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164381#M29414</link>
      <description>&lt;P&gt;In case anyone ever has this issue, please be mindful that this happened AFTER we upgraded customer from R80.40 to R81.10 and we found out with help from TAC escalations its caused by ISP redundancy. so appears something in R81.10 is different than in R80.40 for this, what, no clue. I also replicated this in my lab as well I will update once I find out 100% what exactly is causing the behavior, as it happened twice already.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 22:34:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164381#M29414</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-06T22:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164476#M29442</link>
      <description>&lt;P&gt;For anyone who has ISP redundancy, TAC gave below change as issue was replicated, so you would have to do this. What exactly it does, not 100% sure, never got an answer, though it says to disable the script uncomment the line. I definitely will get an answer as to what is EXACT purpose of this.&lt;/P&gt;
&lt;P&gt;Please uncomment this line "exit 1" from file $FWDIR/bin/cpisp_update file on the gateway:&lt;/P&gt;
&lt;P&gt;# To disable the script uncomment the following line.&lt;BR /&gt;# exit 1&lt;/P&gt;
&lt;P&gt;set MISP_MAX_ISPS = 10&lt;BR /&gt;set ISP_STATUS_FILE = "$FWDIR/conf/cpispstatus.conf"&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 03:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164476#M29442</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-08T03:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164479#M29443</link>
      <description>&lt;P&gt;Thats wonderful finding let me replicate that in my scenario and test it out.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 03:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164479#M29443</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-08T03:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164480#M29444</link>
      <description>&lt;P&gt;I hope you never have the same problem, as its really frustrating. But, now that we know what was causing it, its an easy fix. I will definitely make sure to get an explanation if upgrade caused this, as it never happened on R80.40.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 03:19:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164480#M29444</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-08T03:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164496#M29447</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Could you share the version you are using on the Smart-1 and on the firewall ?&lt;/P&gt;&lt;P&gt;I am managing about 180 modules all over the world and the new company standard is to use ISP redundancy every where. Currently running 80.40 and 80.20, upgrade to 81.10 is planned next year...&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 07:58:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164496#M29447</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2022-12-08T07:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164514#M29452</link>
      <description>&lt;P&gt;I hate to say this, but unless CP actually fixed this permanently, you WILL most likely encounter this problem. Mgmt is S1C (smart-1 cloud) and gateways are 6400, all running R81.10. Now, keep in mind, when S1C was on R81.10 (upgrades are managed and scheduled by CP) and gateways on R80.40, this NEVER happened. Once gateways were upgraded to R81.10, thats when issue occurred 1st time maybe a week later and then 2nd time 2 weeks after. This is why Im pressing TAC to provide logic as to whether this is an issue in R81+ and how it can be avoided without having to modify that file.&lt;/P&gt;
&lt;P&gt;Another interesting thing I will also try to confirm is whether this ONLY affects HA isp config or load sharing as well. As soon as I get the info, will update here.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 11:42:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164514#M29452</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-08T11:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164516#M29453</link>
      <description>&lt;P&gt;Also&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54723"&gt;@BikeMan&lt;/a&gt;&amp;nbsp;, to add to my last comment, I also saw something interesting below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Quantum_SecurityGateway_Guide/Topics-FWG/ISP-Redundancy-CLI.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Quantum_SecurityGateway_Guide/Topics-FWG/ISP-Redundancy-CLI.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;See this part:&lt;/P&gt;
&lt;H2&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ispr variable"&gt;ISP Redundancy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Script&lt;/H2&gt;
&lt;P&gt;When the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;starts, or an ISP link state changes, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;$FWDIR/bin/cpisp_update&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;script runs on the&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;This script changes the default route of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Important_Note"&gt;Warning&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- We do&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;recommend that you make any changes to this script.&lt;/P&gt;
&lt;P&gt;***************************************&lt;/P&gt;
&lt;P&gt;Now, here is my own logic. NEITHER of those scenarios applied to the customer. So, obviously, once gateways were upgraded, they had to be rebooted, so according to the document, it would imply that default route would change every time fw is rebooted?? That makes no sense. Also, their primary ISP link never failed either. Anyway, lets see what TAC says.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 11:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164516#M29453</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-08T11:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164610#M29490</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I reviewed the case and i am sorry but the provided solution is wrong here, uncomment that line means you disable ISPR means failover of ISP will not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case customer is running with BGP which its not supported with ISPR, even if it worked for a customer on previous version we can't guarantee that it worked correctly as dynamic routing and ISPR are impacting routing of each other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is some discussion with RnD about the case but not sure there will be a solution.&lt;/P&gt;
&lt;P&gt;Will keep update once we have some conclusions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ilya&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 11:27:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164610#M29490</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2022-12-09T11:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164612#M29491</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14307"&gt;@Ilya_Yusupov&lt;/a&gt;&amp;nbsp;, very grateful for your update. So, just wondering, I could not find any documents or articles stating that ISPR is not supported with BGP. Would you be able to provide that please?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 12:26:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164612#M29491</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-09T12:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164613#M29492</link>
      <description>&lt;P&gt;Sure i will share it on Sunday as i am not in front a laptop, its not only bgp but dynamic routing with ispr.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 12:36:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164613#M29492</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2022-12-09T12:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164620#M29495</link>
      <description>&lt;P&gt;No rush. I will ask via the TAC case.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 12:57:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164620#M29495</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-09T12:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Policy push overwrote default route on cluster active gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164637#M29500</link>
      <description>&lt;P&gt;K, TAC provided the link, but here is what makes no sense to me personally.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170418&amp;amp;partition=Basic&amp;amp;product=Anti-Bot," target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170418&amp;amp;partition=Basic&amp;amp;product=Anti-Bot,&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this part:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PMTR-68991ISP Redundancy is not supported if Dynamic Routing is configured (because the ISP Redundancy feature must create a static default route that overrides the default route created by dynamic routing).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;well, customer's DG IS INDEED derived from ISPR and NOT bgp, so I cant connect the dots here as to why this would even apply to them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 15:11:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-push-overwrote-default-route-on-cluster-active-gateway/m-p/164637#M29500</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-09T15:11:15Z</dc:date>
    </item>
  </channel>
</rss>

