<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secondary gateway cannot ping its default gateway. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195892#M36535</link>
    <description>&lt;DIV&gt;Situation as follows: 2 x 3200 appliances on R80.30 jhfa take 237 (yes, I know). They were relocated over the weekend, external IPs changed, all good. Both appliances are up, active member is fine and passing traffic, ClusterXL reports all is well. The secondary appliance cannot ping its own default gateway, interface is up and topology is correct, no ARP entries at all, default route won't become active. Management cannot reach the box to put policy on (fw unloadlocal doesn't help). The link to the ISP is working, we've put a laptop on the same cable the FW was plugged into and given it the same IP and it works no problem.&lt;/DIV&gt;</description>
    <pubDate>Mon, 23 Oct 2023 10:19:03 GMT</pubDate>
    <dc:creator>khodgson_bts</dc:creator>
    <dc:date>2023-10-23T10:19:03Z</dc:date>
    <item>
      <title>Secondary gateway cannot ping its default gateway.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195892#M36535</link>
      <description>&lt;DIV&gt;Situation as follows: 2 x 3200 appliances on R80.30 jhfa take 237 (yes, I know). They were relocated over the weekend, external IPs changed, all good. Both appliances are up, active member is fine and passing traffic, ClusterXL reports all is well. The secondary appliance cannot ping its own default gateway, interface is up and topology is correct, no ARP entries at all, default route won't become active. Management cannot reach the box to put policy on (fw unloadlocal doesn't help). The link to the ISP is working, we've put a laptop on the same cable the FW was plugged into and given it the same IP and it works no problem.&lt;/DIV&gt;</description>
      <pubDate>Mon, 23 Oct 2023 10:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195892#M36535</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2023-10-23T10:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary gateway cannot ping its default gateway.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195893#M36536</link>
      <description>&lt;P&gt;Can it ping if it becomes active?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 10:21:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195893#M36536</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-23T10:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary gateway cannot ping its default gateway.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195894#M36537</link>
      <description>&lt;P&gt;We've not tried that yet. At the moment the site is live and we cannot have any downtime.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 10:22:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195894#M36537</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2023-10-23T10:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary gateway cannot ping its default gateway.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195897#M36539</link>
      <description>&lt;P&gt;This may be normal, depending on the details of your configuration. With R80.40 and up, traffic from standby goes through sync interface towards the active member, see&amp;nbsp;&lt;SPAN&gt;sk167453.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try running traces to see where packets are "lost".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 10:35:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195897#M36539</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-23T10:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary gateway cannot ping its default gateway.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195898#M36540</link>
      <description>&lt;P&gt;All we are getting is "network unreachable" from traces and pings. Regardless of active/standby status, the device&amp;nbsp;&lt;EM&gt;should&lt;/EM&gt; be able to ping its own default gateway. The route is not even showing as active in the routing table.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 10:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195898#M36540</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2023-10-23T10:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary gateway cannot ping its default gateway.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195900#M36541</link>
      <description>&lt;P&gt;Please look into the SK I already provided, you will see that it is a bit more complicated with ClusterXL&lt;/P&gt;
&lt;P&gt;Assuming you have policy installed on the new appliance, and the cluster is running in Active/Standby, it should be all good.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;However, by traces I mean, try to understand where exactly ICMP is broken. You can do that by running "fw monitor" on both standby and active cluster members. You can also check logs for drops of the relevant traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 11:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195900#M36541</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-23T11:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary gateway cannot ping its default gateway.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195901#M36542</link>
      <description>&lt;P&gt;Oh boy, I just re-read your post, you are running an unsupported R80.30. This changes everything.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please look into a similar thread in the community:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/ClusterXL-standby-cannot-reach-gateway/m-p/25712#M1953" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/ClusterXL-standby-cannot-reach-gateway/m-p/25712#M1953&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 11:11:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-gateway-cannot-ping-its-default-gateway/m-p/195901#M36542</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-10-23T11:11:35Z</dc:date>
    </item>
  </channel>
</rss>

