<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateways Loose Internet Connection After Policies Intallation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179914#M32917</link>
    <description>&lt;P&gt;That nice to know that but still looks odd to be honest. The traffic originating from gateway does get hide or folded behind VIP and shouldn't matter if those are natted or not provided what is the sequence kept in global properties&amp;nbsp; for "Traffic originating from Gateway" &amp;lt;LAST|First| Before LASt&amp;gt;&lt;/P&gt;&lt;P&gt;And&amp;nbsp; without policy the appliance does not route the connection or no connection can traverse through the appliance for security reason else it will perform just like normal server.&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 02:17:44 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2023-05-04T02:17:44Z</dc:date>
    <item>
      <title>Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179861#M32904</link>
      <description>&lt;P&gt;Hello Mates!&lt;/P&gt;&lt;P&gt;I'm having a strange problem in a client's environment. It's a Cluster in HA R81.10 Take 94.&lt;/P&gt;&lt;P&gt;When I install policies, the gateways lose communication with the internet, there's no ping to the outside, but the machines behind the gateway navigate normally.&lt;/P&gt;&lt;P&gt;When I apply an fwunloadlocal to the gateways, they start responding to ping from the internet again, but the machines stop browsing.&lt;/P&gt;&lt;P&gt;No drops are shown in zdebug, the policies rules seems to be ok too.&lt;/P&gt;&lt;P&gt;fw monitor show like this when I try to ping external address:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwmonitor-gw.png" style="width: 565px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20763i2C3BA51B2A488A74/image-size/large?v=v2&amp;amp;px=999" role="button" title="fwmonitor-gw.png" alt="fwmonitor-gw.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;the IP 172.31.1.3 is the gateway interface. I just see the request, not reply&lt;/P&gt;&lt;P&gt;In the same moment that a machine behind the gateway shown me request/reply normally:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwmonitor-pc-behind.png" style="width: 582px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20764iEE0BDD9A371C481C/image-size/large?v=v2&amp;amp;px=999" role="button" title="fwmonitor-pc-behind.png" alt="fwmonitor-pc-behind.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What could be causing this?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 15:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179861#M32904</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-05-03T15:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179863#M32905</link>
      <description>&lt;P&gt;I had this happen with customers before and 9 times out of 10, either its something with topology (anti spoofing) and/or routing/nat.&lt;/P&gt;
&lt;P&gt;Here is an easy thing to try...in both situations, run ip r g 8.8.8.8 from gateway and compare the output, that should give a clue.&lt;/P&gt;
&lt;P&gt;HTH&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82249"&gt;@Bernardes&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 15:03:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179863#M32905</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-03T15:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179871#M32906</link>
      <description>&lt;P&gt;hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt; !&lt;/P&gt;&lt;P&gt;This was the result before and after fw unloadlocal:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="unload.png" style="width: 462px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20765i54631594EA57AB31/image-size/large?v=v2&amp;amp;px=999" role="button" title="unload.png" alt="unload.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I try to disable anti-spoofing, but it doesn't work.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 15:39:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179871#M32906</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-05-03T15:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179876#M32907</link>
      <description>&lt;P&gt;Any changes in Implied rules? Did you disable anything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 16:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179876#M32907</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-03T16:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179879#M32908</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt; ! The implied rules are default, no changes.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 16:03:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179879#M32908</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-05-03T16:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179880#M32909</link>
      <description>&lt;P&gt;Ok so what does fw stat shows if policy push is successful?&lt;/P&gt;&lt;P&gt;Do you get ping to 8.8.8.8 or 9.9.9.9&lt;/P&gt;&lt;P&gt;Do you get arp of your default gateway (arp -an | grep &amp;lt;DG_IP_Address&amp;gt;)&lt;/P&gt;&lt;P&gt;What is cphaprob -a if says?&lt;/P&gt;&lt;P&gt;cphaprob stat shows any PNOTES?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 16:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179880#M32909</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-03T16:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179881#M32910</link>
      <description>&lt;P&gt;Ok, so thats the same...can you tell if nat takes place when issue occurs? What does zdebug show?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 16:38:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179881#M32910</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-03T16:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179900#M32911</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;look at the output results for these commands:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output-res.png" style="width: 714px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20769iDDDDFB9C281E2937/image-size/large?v=v2&amp;amp;px=999" role="button" title="output-res.png" alt="output-res.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 20:42:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179900#M32911</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-05-03T20:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179902#M32912</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;the NAT occurs on an F5 appliance in front of Check Point. This Security Gateway is not doing NAT in this case.&lt;/P&gt;&lt;P&gt;In zdebug output not is showing nothing fot this traffic, apparently theres no drop&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zdebug.png" style="width: 492px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20770iED20228364CAF3D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="zdebug.png" alt="zdebug.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 20:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179902#M32912</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-05-03T20:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179903#M32913</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82249"&gt;@Bernardes&lt;/a&gt;&amp;nbsp;Since I like to think about anything in life the logical way, lets recap this situation.&lt;/P&gt;
&lt;P&gt;Sooo...IF you do fw unloadlocal and everything works fine, that tells me logically that SOMETHING in the policy is causing the problem. Can you do zdebug BEFORE you unload the policy and see if it gives anything?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 21:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179903#M32913</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-03T21:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179907#M32914</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;This zdebug output above is when the policies were applied, but after the fw unloadlocal the result is the same, aparently there's no drops before or after the policies are applied.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 23:27:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179907#M32914</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-05-03T23:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179908#M32915</link>
      <description>&lt;P&gt;Ok...if you are 100% sure and you have verified routing/natting, then only other thing I could think of is anti-spoofing. Please ensure thats accurate, because if wrong, it can definitely cause issues like this one.&lt;/P&gt;
&lt;P&gt;Take care.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 23:55:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179908#M32915</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-03T23:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179913#M32916</link>
      <description>&lt;P&gt;Hello friends &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for all your help and dedication so far!&lt;/P&gt;
&lt;P&gt;The problem has been solved with a NO NAT rule on the Check Point.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nonat.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20771i76E5E076DDC9DB3A/image-size/large?v=v2&amp;amp;px=999" role="button" title="nonat.png" alt="nonat.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As I mentioned before, this Check Point appliance didn't perform NAT, the NATs were configured on the F5, and it has worked like this since deployment.&lt;/P&gt;
&lt;P&gt;I believe something was changed on the F5, and out of curiosity, I created rules for the members' IPs and the cluster's VIP, and after creating the rules, the appliances navigated normally.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nav.png" style="width: 651px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20772i583E2E3E00F6ECFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="nav.png" alt="nav.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However, I didn't understand why it worked without the policies. Was there something implicit that made it work?&lt;/P&gt;
&lt;P&gt;Do you have any idea of what could have made the appliances' navigation work without the policies installed?&lt;/P&gt;
&lt;P&gt;Thank you all!&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 01:51:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179913#M32916</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2023-05-04T01:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179914#M32917</link>
      <description>&lt;P&gt;That nice to know that but still looks odd to be honest. The traffic originating from gateway does get hide or folded behind VIP and shouldn't matter if those are natted or not provided what is the sequence kept in global properties&amp;nbsp; for "Traffic originating from Gateway" &amp;lt;LAST|First| Before LASt&amp;gt;&lt;/P&gt;&lt;P&gt;And&amp;nbsp; without policy the appliance does not route the connection or no connection can traverse through the appliance for security reason else it will perform just like normal server.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 02:17:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179914#M32917</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-04T02:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways Loose Internet Connection After Policies Intallation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179915#M32918</link>
      <description>&lt;P&gt;I tend to agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;. Good job by the way in doing those rules, since F5 is handling the NAT. But, having said that, by default, CP firewall will not do any nat, as out of the box, nat is not enabled and plus, there is no default nat rule inside the policy that would nat all outgoing traffic, so one either need to be created OR you can check option to nat all internal networks behind the firewall external IP.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 02:35:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateways-Loose-Internet-Connection-After-Policies-Intallation/m-p/179915#M32918</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-04T02:35:31Z</dc:date>
    </item>
  </channel>
</rss>

