<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unknown MAC address used by Standby node in Cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167154#M30197</link>
    <description>&lt;P&gt;By the way,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;provided the right info...not sure if he used same site to look it up, but below is what I used.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://macaddress.io/mac-address-lookup/0V5glOjVkq" target="_blank"&gt;https://macaddress.io/mac-address-lookup/0V5glOjVkq&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;SECTION class="small-subheader-block lookup-subheader-block "&gt;
&lt;DIV class="content-in-blocks"&gt;
&lt;H1&gt;02:56:2e:00:00:01 MAC address details&lt;/H1&gt;
&lt;FORM action="https://macaddress.io/mac-address-lookup" autocomplete="off" method="POST"&gt;&lt;INPUT name="mac-address-value" pattern="^([0-9A-Fa-f]{2}[.:-]?){2,7}([0-9A-Fa-f]{2})$" required="required" type="text" placeholder="MAC address or OUI" data-autofocus="true" /&gt;&lt;INPUT class="btn green-btn" type="submit" value="New search" /&gt;&lt;/FORM&gt;&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;DIV class="mac-address-report-block-wrapper"&gt;
&lt;SECTION class="mac-address-report-block"&gt;
&lt;DIV class="content-in-blocks report-content"&gt;
&lt;DIV&gt;
&lt;DIV class="mac-address-report"&gt;
&lt;DIV class="report-column"&gt;
&lt;H4&gt;Vendor details&lt;/H4&gt;
&lt;DIV class="report-row-single-span"&gt;&lt;SPAN&gt;None&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="report-column"&gt;
&lt;H4&gt;Block details&lt;/H4&gt;
&lt;DIV class="report-row-single-span"&gt;&lt;SPAN&gt;The MAC address does not belong to any registered block.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="report-row-single-span"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="report-row-single-span"&gt;
&lt;SECTION class="small-subheader-block lookup-subheader-block "&gt;
&lt;DIV class="content-in-blocks"&gt;
&lt;H1&gt;00:01:00:00:fd:01 MAC address details&lt;/H1&gt;
&lt;FORM action="https://macaddress.io/mac-address-lookup" autocomplete="off" method="POST"&gt;&lt;INPUT name="mac-address-value" pattern="^([0-9A-Fa-f]{2}[.:-]?){2,7}([0-9A-Fa-f]{2})$" required="required" type="text" placeholder="MAC address or OUI" data-autofocus="true" /&gt;&lt;INPUT class="btn green-btn" type="submit" value="New search" /&gt;&lt;/FORM&gt;&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;DIV class="mac-address-report-block-wrapper"&gt;
&lt;SECTION class="mac-address-report-block"&gt;
&lt;DIV class="content-in-blocks report-content"&gt;
&lt;DIV&gt;
&lt;DIV class="mac-address-report"&gt;
&lt;DIV class="report-column"&gt;
&lt;H4&gt;Vendor details&lt;/H4&gt;
&lt;DIV&gt;&lt;SPAN&gt;OUI&lt;/SPAN&gt;&lt;SPAN&gt;00:01:00&amp;nbsp;&lt;I class="icon-question-circle-o" aria-hidden="true" data-tippy="" data-original-title="&amp;lt;h4&amp;gt;What is an Organizationally Unique Identifier (OUI)?&amp;lt;/h4&amp;gt;&amp;lt;p&amp;gt;An OUI is a 24-bit globally unique assigned number. An OUI is assigned with a MA-L identifier block and is referenced by various standards. It can be used to identify an organization or company which requires a globally unique identifier...&amp;lt;/p&amp;gt;&amp;lt;a href=&amp;quot;https://macaddress.io/faq/what-is-an-organizationally-unique-identifier-oui&amp;quot;&amp;gt;Read more &amp;lt;i class=&amp;quot;icon-right-open&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;"&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Is private&lt;/SPAN&gt;&lt;SPAN class="bool-true-value"&gt;False&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Company name&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A class="common-link" href="https://macaddress.io/statistics/company/242" target="_blank"&gt;Equip'Trans&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Company address&lt;/SPAN&gt;&lt;SPAN&gt;31 rue Paul Cezanne LA ROCHETTE 77000 FR&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Country code&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A class="common-link" href="https://macaddress.io/statistics/country/FR" target="_blank"&gt;FR&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="report-column"&gt;
&lt;H4&gt;Block details&lt;/H4&gt;
&lt;DIV&gt;&lt;SPAN&gt;Is registered&lt;/SPAN&gt;&lt;SPAN class="bool-true-value"&gt;True&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Border left&lt;/SPAN&gt;&lt;SPAN&gt;00:01:00:00:00:00&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Border right&lt;/SPAN&gt;&lt;SPAN&gt;00:01:00:FF:FF:FF&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Block size&lt;/SPAN&gt;&lt;SPAN&gt;16,777,216&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Assignment block size&lt;/SPAN&gt;&lt;SPAN&gt;MA-L&amp;nbsp;&lt;I class="icon-question-circle-o" aria-hidden="true" data-tippy="" data-original-title="&amp;lt;h4&amp;gt;What is a MA-L, MA-M, MA-S assignment?&amp;lt;/h4&amp;gt;&amp;lt;p&amp;gt;There are currently 3 different size blocks of MAC Addresses available. All three could be used to generate universally administered MAC‌-48 and MAC‌-64...&amp;lt;/p&amp;gt;&amp;lt;a href=&amp;quot;https://macaddress.io/faq/what-is-a-ma-l-ma-m-ma-s-assignment&amp;quot;&amp;gt;Read more &amp;lt;i class=&amp;quot;icon-right-open&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;"&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="date-span"&gt;&lt;SPAN&gt;Date created&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A class="common-link" href="https://macaddress.io/statistics/date/08-November-2000" target="_blank"&gt;08 November 2000&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="date-span"&gt;&lt;SPAN&gt;Date updated&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A class="common-link" href="https://macaddress.io/statistics/date/26-September-2015" target="_blank"&gt;26 September 2015&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="report-column"&gt;
&lt;H4&gt;MAC address details&lt;/H4&gt;
&lt;DIV&gt;&lt;SPAN&gt;Is valid&lt;/SPAN&gt;&lt;SPAN class="bool-true-value"&gt;True&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Virtual Machine&lt;/SPAN&gt;&lt;SPAN class="vm-span"&gt;Microsoft Virtual PC / Virtual Server&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I class="icon-question-circle-o" aria-hidden="true" data-tippy="" data-original-title="&amp;lt;h4&amp;gt;How to detect a Virtual Machine &amp;lt;span class=&amp;quot;span-no-wrap&amp;quot;&amp;gt;by its MAC address?&amp;lt;/span&amp;gt;&amp;lt;/h4&amp;gt;&amp;lt;p&amp;gt;Our MAC Address API outputs a field called macAddressDetails.virtualMachine. If it detects that a Virtual Machine is using this MAC address, it outputs its vendor name (e.g. 'VMWare'). Otherwise, it outputs 'Not detected'...&amp;lt;/p&amp;gt;&amp;lt;a href=&amp;quot;https://macaddress.io/faq/how-to-detect-a-virtual-machine-by-its-mac-address&amp;quot;&amp;gt;Read more &amp;lt;i class=&amp;quot;icon-right-open&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;"&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Transmission type&lt;/SPAN&gt;&lt;SPAN class="just-no-wrap"&gt;Unicast&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I class="icon-question-circle-o" aria-hidden="true" data-tippy="" data-original-title="&amp;lt;h4&amp;gt;What are unicast and multicast addresses?&amp;lt;/h4&amp;gt;&amp;lt;p&amp;gt;There are also two different types of Ethernet addresses - unicast and multicast.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;If the least significant bit of the most significant octet of an address is set to 0 (zero), the frame is meant to reach only one receiving NIC...&amp;lt;/p&amp;gt;&amp;lt;a href=&amp;quot;https://macaddress.io/faq/what-are-unicast-and-multicast-addresses&amp;quot;&amp;gt;Read more &amp;lt;i class=&amp;quot;icon-right-open&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;"&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Administration type&lt;/SPAN&gt;&lt;SPAN class="just-no-wrap"&gt;UAA&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I class="icon-question-circle-o" aria-hidden="true" data-tippy="" data-original-title="&amp;lt;h4&amp;gt;What are a universal address and a local administered address?&amp;lt;/h4&amp;gt;&amp;lt;p&amp;gt;A MAC address is called a universally administered address (UAA) when it's set by the manufacturer or a locally administered addresses (LAA) when it's assigned by the system administrator...&amp;lt;/p&amp;gt;&amp;lt;a href=&amp;quot;https://macaddress.io/faq/what-are-a-universal-address-and-a-local-administered-address&amp;quot;&amp;gt;Read more &amp;lt;i class=&amp;quot;icon-right-open&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;"&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Applications&amp;nbsp;&lt;I class="icon-question-circle-o" aria-hidden="true" data-tippy="" data-original-title="&amp;lt;h4&amp;gt;How to recognise MAC address application?&amp;lt;/h4&amp;gt;&amp;lt;p&amp;gt;Some MAC addresses and their ranges are reserved for specific use cases by their vendors. Such addresses typically indicate what higher-level protocol is encapsulated in a frame...&amp;lt;/p&amp;gt;&amp;lt;a href=&amp;quot;https://macaddress.io/faq/how-to-recognise-mac-address-application&amp;quot;&amp;gt;Read more &amp;lt;i class=&amp;quot;icon-right-open&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;"&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;SPAN class="just-no-wrap"&gt;Not detected&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Wireshark notes&amp;nbsp;&lt;I class="icon-question-circle-o" aria-hidden="true" data-tippy="" data-original-title="&amp;lt;h4&amp;gt;Wireshark notes&amp;lt;/h4&amp;gt;&amp;lt;p&amp;gt;Our MAC Address API outputs a field called &amp;lt;b&amp;gt;macAddressDetails.wiresharkNotes&amp;lt;/b&amp;gt;. &amp;lt;span class=&amp;quot;span-no-wrap&amp;quot;&amp;gt;For some specific&amp;lt;/span&amp;gt; OUIs or exact MAC addresses, &amp;lt;span class=&amp;quot;span-no-wrap&amp;quot;&amp;gt;Wireshark provides&amp;lt;/span&amp;gt; extra details which may help to recognize the MAC address application or indicate an actual vendor rather than the original assignment...&amp;lt;/p&amp;gt;&amp;lt;a href=&amp;quot;https://macaddress.io/faq/wireshark-notes&amp;quot;&amp;gt;Read more &amp;lt;i class=&amp;quot;icon-right-open&amp;quot;&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;/a&amp;gt;"&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;SPAN&gt;No details&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 09 Jan 2023 16:43:16 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-01-09T16:43:16Z</dc:date>
    <item>
      <title>Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166994#M30128</link>
      <description>&lt;P&gt;Is this expected behaviour design that Checkpoint Standby node in cluster will access internet, IPS update, contacting internal servers etc., happens through Sync interface?&lt;/P&gt;&lt;P&gt;Pinged Google DNS 8.8.8.8 from Standby node and captured traffic on Standby firewall using tcpdump and observed traffic echo request packets on sync interface but there is no reply. Further observed there is difference in Source MAC address which leads to VMWare ESX host drops packet.&lt;/P&gt;&lt;P&gt;I have changed Forged transmits option to Accept from Reject in ESX portgroup fixed the issue. However, I would like to know from Checkpoint experts about below Unknown MAC addresses.&lt;/P&gt;&lt;P&gt;Below packet capture from Standby node sync interface&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;02:56:2e:00:00:01 (Unknow MAC)&lt;/STRONG&gt; &amp;gt; 00:0c:29:XX:XX:XX (Active Node Sync interface MAC), ethertype IPv4 (0x0800), length 98: X.X.X.X (Standby Node internet interface IP) &amp;gt; 8.8.8.8: ICMP echo request, id 16914, seq 115, length 64&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;00:01:00:00:fd:01 (Unknown MAC)&lt;/STRONG&gt; &amp;gt; 00:0c:29:YY:YY:YY (Standby Node Sync interface MAC), ethertype IPv4 (0x0800), length 98: 8.8.8.8 &amp;gt; X.X.X.X (Standby Node internet interface IP): ICMP echo reply, id 16914, seq 28, length 64&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 13:11:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166994#M30128</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-07T13:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166997#M30129</link>
      <description>&lt;P&gt;Standby members traffic via Sync is expected (R80.40) and higher, refer: sk167453&lt;/P&gt;
&lt;P&gt;Note sk169154 (section 3.4) provides a mechanism to alter the behaviour if needed.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 14:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166997#M30129</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-07T14:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166998#M30130</link>
      <description>&lt;P&gt;Thanks for that information. However, I would like to know Unknown MAC address belongs to Checkpoint or not? How can we ensure that?&lt;/P&gt;&lt;P&gt;There is no aymmetric connection issue here.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 13:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166998#M30130</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-07T13:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166999#M30131</link>
      <description>&lt;P&gt;Chris is correct it is indeed expected behavior. As far as unknown MAC, can you verify if that MAC is indeed showing either in cphaprob -a if or ifconfig -a command?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 14:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/166999#M30131</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-07T14:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167009#M30135</link>
      <description>&lt;P&gt;There is no such MAC address obderved by running suggested commands&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 08:00:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167009#M30135</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-08T08:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167022#M30138</link>
      <description>&lt;P&gt;Do you see the same mac-address when both cluster members are on the same ESX host?&lt;/P&gt;
&lt;P&gt;Possibly correction layer mac-address TAC should be able to help confirm.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 09:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167022#M30138</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-08T09:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167024#M30139</link>
      <description>&lt;P&gt;I dont think so this is specific to ESX host. I am getting same in Checkpoint appliance standby node as well.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 09:30:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167024#M30139</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-08T09:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167027#M30141</link>
      <description>&lt;P&gt;But your cluster works fine otherwise? No failover issue?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 13:01:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167027#M30141</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-08T13:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167046#M30145</link>
      <description>&lt;P&gt;Cluster works absolutely fine. Only issue with Standby node unable to communicate outside world, that too fixed after allowed Forged transmits in ESX but we want to understand from Checkpoint why this behaviour and where these MAC address were getting generated?&lt;/P&gt;&lt;P&gt;Why it not forward packets with actual standby sync interface MAC address as Source MAC?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 04:31:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167046#M30145</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T04:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167047#M30146</link>
      <description>&lt;P&gt;I dont have any more ideas, sorry mate. Maybe open a TAC case and see what they say. Personally, I had never seen that before.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 04:34:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167047#M30146</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-09T04:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167049#M30147</link>
      <description>&lt;P&gt;No issues &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;. Have already TAC case opened but no useful update from them. I have figured out all these things by myself. Let me see, what they will answer for this Unknown MAC.&lt;/P&gt;&lt;P&gt;Thanks for your response &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 04:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167049#M30147</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T04:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167066#M30155</link>
      <description>&lt;TABLE class="table"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;MAC-Segment:&lt;/TH&gt;
&lt;TD&gt;00:01:00:00:00:00 - 00:01:00:FF:FF:FF (MA-L)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TH&gt;Hersteller:&lt;/TH&gt;
&lt;TD&gt;EQUIP'TRANS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TH&gt;Adresse:&lt;/TH&gt;
&lt;TD&gt;31 rue Paul Cezanne&lt;BR /&gt;LA ROCHETTE 77000&lt;BR /&gt;FR&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 09 Jan 2023 10:20:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167066#M30155</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-09T10:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167069#M30158</link>
      <description>&lt;P&gt;Those are MAC addresses used to forward traffic from a Standby member. Check why the standup member is actually receiving traffic that needs to be forwarded.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 10:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167069#M30158</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T10:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167070#M30159</link>
      <description>&lt;P&gt;One MAC is from&amp;nbsp;&lt;SPAN&gt;EQUIP'TRANS (see above) -&amp;nbsp;02:56:2e:00:00:01 is not tied to a vendor. All CP appliances interface HW MACs are in the form:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;00:1C:7F:xx:yy:zz&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 10:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167070#M30159</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-09T10:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167072#M30160</link>
      <description>&lt;P&gt;Not getting your point.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp; Standby member uses same kind of MAC address to forward traffic to other hosts irrpespective of type of deployment (Deploy in Physical server such as HP or deploy as VM in esx host or Checkpoint appliance).&lt;/P&gt;&lt;P&gt;So, Checkpoint has to answer.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 11:00:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167072#M30160</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T11:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167080#M30163</link>
      <description>&lt;P&gt;Check Point is two words.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What I see from your original post, you see traffic being forwarded from the standby member to the active member. This is normal for some limited scenarios, where a few connections may still be handled by a standby member after failover. These connections should be then forwarded to the active member and sent out.&lt;BR /&gt;&lt;BR /&gt;To do that, a standby member is forwarding packets using an artificial MAC address. This is part of ClusterXL tech. The last octet of that artificial MAC address is a function of your cluster ID.&lt;BR /&gt;&lt;BR /&gt;Depending on the version of your FWs (which you failed to mention) this forwarding can be done via sync or via production interfaces of your cluster.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you see a lot of forwarded traffic, you should investigate why production traffic hits the standby and not the active member, and fix the issue.&lt;BR /&gt;&lt;BR /&gt;In your case, who is pinning 8.8.8.8 through standby member?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 11:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167080#M30163</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T11:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167101#M30177</link>
      <description>&lt;P&gt;Cluster running in Gaia R81.10 version. I only ran ping 8.8.8.8 to test internet connectivity from standby firewall. Production traffic always hits active firewall not stanbdy. There is no issue with production application traffic.&lt;/P&gt;&lt;P&gt;Here, the issue that we are talking about connection initiated by standby member. Probably, I will wait for assigned engineer from Check Point to address my queries through remote session.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 12:23:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167101#M30177</guid>
      <dc:creator>Nandhakumar</dc:creator>
      <dc:date>2023-01-09T12:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167102#M30178</link>
      <description>&lt;P&gt;Keep us posted, very interesting issue indeed.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 12:30:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167102#M30178</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-09T12:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167123#M30189</link>
      <description>&lt;P&gt;This is by design, see about forwarded traffic once mode.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 14:00:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167123#M30189</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T14:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown MAC address used by Standby node in Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167125#M30191</link>
      <description>&lt;P&gt;It is only interesting if one does not know how ClusterXl works,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 14:01:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unknown-MAC-address-used-by-Standby-node-in-Cluster/m-p/167125#M30191</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-09T14:01:08Z</dc:date>
    </item>
  </channel>
</rss>

