<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unknown MAC address used by Standby node in Cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167152#M30195</link>
    <description>&lt;P&gt;I agree with you 100%. Please keep us posted what TAC says.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2023 16:11:49 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-01-09T16:11:49Z</dc:date>
    <item>
      <title>Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166994#M30128</link>
      <description>&lt;P&gt;Is this expected behaviour design that Checkpoint Standby node in cluster will access internet, IPS update, contacting internal servers etc., happens through Sync interface?&lt;/P&gt;&lt;P&gt;Pinged Google DNS 8.8.8.8 from Standby node and captured traffic on Standby firewall using tcpdump and observed traffic echo request packets on sync interface but there is no reply. Further observed there is difference in Source MAC address which leads to VMWare ESX host drops packet.&lt;/P&gt;&lt;P&gt;I have changed Forged transmits option to Accept from Reject in ESX portgroup fixed the issue. However, I would like to know from Checkpoint experts about below Unknown MAC addresses.&lt;/P&gt;&lt;P&gt;Below packet capture from Standby node sync interface&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;02:56:2e:00:00:01 (Unknow MAC)&lt;/STRONG&gt; &amp;gt; 00:0c:29:XX:XX:XX (Active Node Sync interface MAC), ethertype IPv4 (0x0800), length 98: X.X.X.X (Standby Node internet interface IP) &amp;gt; 8.8.8.8: ICMP echo request, id 16914, seq 115, length 64&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;00:01:00:00:fd:01 (Unknown MAC)&lt;/STRONG&gt; &amp;gt; 00:0c:29:YY:YY:YY (Standby Node Sync interface MAC), ethertype IPv4 (0x0800), length 98: 8.8.8.8 &amp;gt; X.X.X.X (Standby Node internet interface IP): ICMP echo reply, id 16914, seq 28, length 64&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 13:11:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166994#M30128</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-07T13:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166997#M30129</link>
      <description>&lt;P&gt;Standby members traffic via Sync is expected (R80.40) and higher, refer: sk167453&lt;/P&gt;
&lt;P&gt;Note sk169154 (section 3.4) provides a mechanism to alter the behaviour if needed.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 14:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166997#M30129</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-07T14:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166998#M30130</link>
      <description>&lt;P&gt;Thanks for that information. However, I would like to know Unknown MAC address belongs to Checkpoint or not? How can we ensure that?&lt;/P&gt;&lt;P&gt;There is no aymmetric connection issue here.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 13:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166998#M30130</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-07T13:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166999#M30131</link>
      <description>&lt;P&gt;Chris is correct it is indeed expected behavior. As far as unknown MAC, can you verify if that MAC is indeed showing either in cphaprob -a if or ifconfig -a command?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 14:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166999#M30131</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-07T14:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167009#M30135</link>
      <description>&lt;P&gt;There is no such MAC address obderved by running suggested commands&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 08:00:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167009#M30135</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-08T08:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167022#M30138</link>
      <description>&lt;P&gt;Do you see the same mac-address when both cluster members are on the same ESX host?&lt;/P&gt;
&lt;P&gt;Possibly correction layer mac-address TAC should be able to help confirm.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 09:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167022#M30138</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-08T09:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167024#M30139</link>
      <description>&lt;P&gt;I dont think so this is specific to ESX host. I am getting same in Checkpoint appliance standby node as well.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 09:30:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167024#M30139</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-08T09:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167027#M30141</link>
      <description>&lt;P&gt;But your cluster works fine otherwise? No failover issue?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 13:01:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167027#M30141</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-08T13:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167046#M30145</link>
      <description>&lt;P&gt;Cluster works absolutely fine. Only issue with Standby node unable to communicate outside world, that too fixed after allowed Forged transmits in ESX but we want to understand from Checkpoint why this behaviour and where these MAC address were getting generated?&lt;/P&gt;&lt;P&gt;Why it not forward packets with actual standby sync interface MAC address as Source MAC?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 04:31:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167046#M30145</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T04:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167047#M30146</link>
      <description>&lt;P&gt;I dont have any more ideas, sorry mate. Maybe open a TAC case and see what they say. Personally, I had never seen that before.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 04:34:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167047#M30146</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-09T04:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167049#M30147</link>
      <description>&lt;P&gt;No issues &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;. Have already TAC case opened but no useful update from them. I have figured out all these things by myself. Let me see, what they will answer for this Unknown MAC.&lt;/P&gt;&lt;P&gt;Thanks for your response &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 04:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167049#M30147</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T04:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167066#M30155</link>
      <description>&lt;TABLE class="table"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;MAC-Segment:&lt;/TH&gt;
&lt;TD&gt;00:01:00:00:00:00 - 00:01:00:FF:FF:FF (MA-L)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TH&gt;Hersteller:&lt;/TH&gt;
&lt;TD&gt;EQUIP'TRANS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TH&gt;Adresse:&lt;/TH&gt;
&lt;TD&gt;31 rue Paul Cezanne&lt;BR /&gt;LA ROCHETTE 77000&lt;BR /&gt;FR&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 09 Jan 2023 10:20:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167066#M30155</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-09T10:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167069#M30158</link>
      <description>&lt;P&gt;Those are MAC addresses used to forward traffic from a Standby member. Check why the standup member is actually receiving traffic that needs to be forwarded.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 10:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167069#M30158</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T10:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167070#M30159</link>
      <description>&lt;P&gt;One MAC is from&amp;nbsp;&lt;SPAN&gt;EQUIP'TRANS (see above) -&amp;nbsp;02:56:2e:00:00:01 is not tied to a vendor. All CP appliances interface HW MACs are in the form:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;00:1C:7F:xx:yy:zz&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 10:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167070#M30159</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-09T10:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167072#M30160</link>
      <description>&lt;P&gt;Not getting your point.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp; Standby member uses same kind of MAC address to forward traffic to other hosts irrpespective of type of deployment (Deploy in Physical server such as HP or deploy as VM in esx host or Checkpoint appliance).&lt;/P&gt;&lt;P&gt;So, Checkpoint has to answer.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 11:00:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167072#M30160</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T11:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167080#M30163</link>
      <description>&lt;P&gt;Check Point is two words.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What I see from your original post, you see traffic being forwarded from the standby member to the active member. This is normal for some limited scenarios, where a few connections may still be handled by a standby member after failover. These connections should be then forwarded to the active member and sent out.&lt;BR /&gt;&lt;BR /&gt;To do that, a standby member is forwarding packets using an artificial MAC address. This is part of ClusterXL tech. The last octet of that artificial MAC address is a function of your cluster ID.&lt;BR /&gt;&lt;BR /&gt;Depending on the version of your FWs (which you failed to mention) this forwarding can be done via sync or via production interfaces of your cluster.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you see a lot of forwarded traffic, you should investigate why production traffic hits the standby and not the active member, and fix the issue.&lt;BR /&gt;&lt;BR /&gt;In your case, who is pinning 8.8.8.8 through standby member?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 11:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167080#M30163</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T11:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167101#M30177</link>
      <description>&lt;P&gt;Cluster running in Gaia R81.10 version. I only ran ping 8.8.8.8 to test internet connectivity from standby firewall. Production traffic always hits active firewall not stanbdy. There is no issue with production application traffic.&lt;/P&gt;&lt;P&gt;Here, the issue that we are talking about connection initiated by standby member. Probably, I will wait for assigned engineer from Check Point to address my queries through remote session.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 12:23:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167101#M30177</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T12:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167102#M30178</link>
      <description>&lt;P&gt;Keep us posted, very interesting issue indeed.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 12:30:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167102#M30178</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-09T12:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167123#M30189</link>
      <description>&lt;P&gt;This is by design, see about forwarded traffic once mode.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 14:00:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167123#M30189</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T14:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167125#M30191</link>
      <description>&lt;P&gt;It is only interesting if one does not know how ClusterXl works,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 14:01:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167125#M30191</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T14:01:08Z</dc:date>
    </item>
  </channel>
</rss>

