<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mgmt traffice cannot cross bridge interface (double-inspection) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/169485#M30685</link>
    <description>&lt;P&gt;We have done all the changes as advised by this&amp;nbsp;&lt;SPAN&gt;SK105899. I suspect this kernel parameter 'fwx_bridge_reroute_enabled=1' could be the cause, but I stand to be guided. Maybe you can also expound more on what this parameter does. What would be gateway behavior&amp;nbsp;if we remove this parameter? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately topology change is not possible in the short-term, hence why we are looking for a solution on Checkpoint itself.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 28 Jan 2023 07:48:22 GMT</pubDate>
    <dc:creator>chinchira</dc:creator>
    <dc:date>2023-01-28T07:48:22Z</dc:date>
    <item>
      <title>Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/116238#M16385</link>
      <description>&lt;P&gt;Hello&amp;nbsp;anyone,&lt;/P&gt;&lt;P&gt;I hope that the Mgmt interface update signature traffic can traverse the bridge interface of the same Security Gateway, I refer to SK105899, and add the following kernel data,&lt;/P&gt;&lt;P&gt;[Expert@R81:0]# cat $PPKDIR/boot/modules/simkern.conf&lt;BR /&gt;# Deprecated location.&lt;BR /&gt;# Any change should be made at /opt/CPppak-R81/conf/simkern.conf&lt;BR /&gt;sim_anti_spoofing_enabled=0&lt;BR /&gt;[Expert@R81:0]# cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;fw_local_interface_anti_spoofing=0&lt;BR /&gt;fw_antispoofing_enabled=0&lt;BR /&gt;fwx_bridge_reroute_enabled=1&lt;/P&gt;&lt;P&gt;At this point, I still cannot update, and I get the following message (fw ctl zdebug + drop)&lt;/P&gt;&lt;P&gt;@;3558;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 172.16.13.192:43355 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;BR /&gt;@;3565;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 172.16.13.192:43355 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;BR /&gt;@;3578;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 172.16.13.192:43355 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;BR /&gt;@;3604;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 172.16.13.192:43355 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;BR /&gt;@;3680;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 172.16.13.192:26677 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;BR /&gt;@;3686;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 172.16.13.192:26677 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;BR /&gt;@;3699;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 172.16.13.192:26677 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;BR /&gt;@;3725;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 172.16.13.192:26677 -&amp;gt; 96.7.254.216:443 dropped by fw_reroute_bridge_fold Reason: Bridge reroute, cksum is wrong;&lt;/P&gt;&lt;P&gt;I am currently running R81 GA version, and the problem also occurs in R80.40&lt;BR /&gt;Can anyone assist me in solving this problem?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 04:30:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/116238#M16385</guid>
      <dc:creator>Alvin</dc:creator>
      <dc:date>2021-04-19T04:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/116347#M16414</link>
      <description>&lt;P&gt;Recommend a TAC case here.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 18:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/116347#M16414</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-19T18:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/169404#M30660</link>
      <description>&lt;P&gt;I am having a similar problem where am getting the same drop message. Please share how this was resolved.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 11:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/169404#M30660</guid>
      <dc:creator>chinchira</dc:creator>
      <dc:date>2023-01-27T11:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/169433#M30670</link>
      <description>&lt;P&gt;Did you already try the solution from&amp;nbsp;&lt;SPAN&gt;SK105899?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Double-inspection is otherwise not supported by SXL (sk172204) and you should review the topology/routing.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 15:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/169433#M30670</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-27T15:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/169485#M30685</link>
      <description>&lt;P&gt;We have done all the changes as advised by this&amp;nbsp;&lt;SPAN&gt;SK105899. I suspect this kernel parameter 'fwx_bridge_reroute_enabled=1' could be the cause, but I stand to be guided. Maybe you can also expound more on what this parameter does. What would be gateway behavior&amp;nbsp;if we remove this parameter? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately topology change is not possible in the short-term, hence why we are looking for a solution on Checkpoint itself.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 07:48:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/169485#M30685</guid>
      <dc:creator>chinchira</dc:creator>
      <dc:date>2023-01-28T07:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178593#M32710</link>
      <description>&lt;P&gt;Hi Chinchira,&lt;/P&gt;&lt;P&gt;I got the same error message. Do you have solution for this?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 08:50:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178593#M32710</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2023-04-20T08:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178594#M32711</link>
      <description>&lt;P&gt;I would recommend a TAC case here.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:00:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178594#M32711</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-04-20T09:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178603#M32712</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I hope this issue will be solved quickly. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178603#M32712</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2023-04-20T09:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt traffice cannot cross bridge interface (double-inspection)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178967#M32791</link>
      <description>&lt;P&gt;It seems the issue have been solved:&lt;/P&gt;&lt;P&gt;We use only 2 out of the 4 kernerparameters (why should we use not relevant key-pairs??)&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105899" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk105899&lt;/A&gt;&lt;/P&gt;&lt;P&gt;fw_local_interface_anti_spoofing=0&lt;/P&gt;&lt;P&gt;fw_antispoofing_enabled=0&lt;/P&gt;&lt;P&gt;fwx_bridge_reroute_enabled=1&lt;/P&gt;&lt;P&gt;fwx_perform_gateway_hide=0&lt;/P&gt;&lt;P&gt;Conclusion: all of the four key-pairs are needed&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 16:51:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mgmt-traffice-cannot-cross-bridge-interface-double-inspection/m-p/178967#M32791</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2023-04-24T16:51:03Z</dc:date>
    </item>
  </channel>
</rss>

