<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP redundancy: reply to sender MAC instead of gateway MAC in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178631#M32716</link>
    <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Thanks for looking into this. See screenshot below! It's not really an issue with ISP redundancy, replying to the MAC address from which the initial packet was received makes sense to keep the traffic flows symmetrical. It's just that our ISP does not seem to accept traffic sent to the standby router, although the standby router does deliver traffic to our firewall.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20580iFBB1335F79DE6E25/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 14:41:50 GMT</pubDate>
    <dc:creator>ErikV</dc:creator>
    <dc:date>2023-04-20T14:41:50Z</dc:date>
    <item>
      <title>ISP redundancy: reply to sender MAC instead of gateway MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178608#M32713</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm having a connectivity problem since we have connected a new ISP. It seems they have two routers of which one owns the default gateway IP. Nothing strange about that.&lt;/P&gt;&lt;P&gt;But looking at incoming traffic, I see packets arriving for my firewall IP, source IP outside of my directly connected subnet, with different source MAC addresses. Per flow the firewall seems to reply to the source MAC it received the previous packet from, not the ARP entry of the default gateway. I suppose this has something to do with using ISP redundancy, and wanting to have symmetrical flows.&lt;/P&gt;&lt;P&gt;But in this case I suspect it is causing problems. It seems the replies that are sent to other MAC addresses than the MAC of our default gateway (= probably the MAC of the standby router, that still delivers incoming traffic) is dropped at the ISP, since I see multiple SYN-ACKs sent to that MAC and then the session times out. All replies sent to the gateway's MAC address are properly handled.&lt;/P&gt;&lt;P&gt;We are using active-standby ISP redundancy, so in this case there is no need (I think) for this feature, and I would prefer to just reply to the default gateway's MAC instead of the original sender. At least I would like to try to see if this is indeed the cause of our connectivity issues.&lt;/P&gt;&lt;P&gt;Does anyone know more about this behavior, and preferably also know how to switch it off while still using ISP redundancy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 10:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178608#M32713</guid>
      <dc:creator>ErikV</dc:creator>
      <dc:date>2023-04-20T10:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy: reply to sender MAC instead of gateway MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178629#M32715</link>
      <description>&lt;P&gt;Are you able to attach screenshot of the isp redundancy config on the gateway as per below? Please blur out any sensitive info. I work often with customer using ISPR and only issue we had with it was that few months ago, R&amp;amp;D had to give us updated script for it, but other than that, all works fine.&lt;/P&gt;
&lt;P&gt;Example below of what I was looking for...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20579i173B8C5BDF52C537/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 14:14:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178629#M32715</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-20T14:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy: reply to sender MAC instead of gateway MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178631#M32716</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Thanks for looking into this. See screenshot below! It's not really an issue with ISP redundancy, replying to the MAC address from which the initial packet was received makes sense to keep the traffic flows symmetrical. It's just that our ISP does not seem to accept traffic sent to the standby router, although the standby router does deliver traffic to our firewall.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20580iFBB1335F79DE6E25/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 14:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178631#M32716</guid>
      <dc:creator>ErikV</dc:creator>
      <dc:date>2023-04-20T14:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy: reply to sender MAC instead of gateway MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178636#M32717</link>
      <description>&lt;P&gt;Ok, got it...do you see any drops if you do the traffic capture?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 15:05:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178636#M32717</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-20T15:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy: reply to sender MAC instead of gateway MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178656#M32721</link>
      <description>&lt;P&gt;No drops, just retransmits of the SYN-ACK. Going out to the ISP, and no answer...&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 21:21:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178656#M32721</guid>
      <dc:creator>ErikV</dc:creator>
      <dc:date>2023-04-20T21:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy: reply to sender MAC instead of gateway MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178783#M32756</link>
      <description>&lt;P&gt;Not sure ISP Redundancy is involved here (or it's not clear if it is).&lt;BR /&gt;Recommend a TAC case to assist: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 20:43:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-reply-to-sender-MAC-instead-of-gateway-MAC/m-p/178783#M32756</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-21T20:43:14Z</dc:date>
    </item>
  </channel>
</rss>

