<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: gateways failing until policies are pushed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200371#M37592</link>
    <description>&lt;P&gt;Same issue.&amp;nbsp; Also I tried to renew the cert and got an error message.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2023 19:15:16 GMT</pubDate>
    <dc:creator>kehagen</dc:creator>
    <dc:date>2023-12-12T19:15:16Z</dc:date>
    <item>
      <title>gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200084#M37514</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have r77 gateways 4400.&amp;nbsp; Two of them are in a cluster.&amp;nbsp; We lost connectivity to the inside last night. I pushed the policies and then I could get connectivity.&amp;nbsp; Then same thing happened this morning.&amp;nbsp; I looked at the switch and a mac address is flapping on the inside with the mac of the firewall cluster.&amp;nbsp; I can get to the inside, but it seems to be a recurring problem and not sure what is causing it.&amp;nbsp; Any ideas where to look?&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 19:42:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200084#M37514</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-08T19:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200086#M37515</link>
      <description>&lt;P&gt;Hey Kenny,&lt;/P&gt;
&lt;P&gt;Sounds like could be routing issue. Maybe do zdebug when this happens if you have console, since it sounds like ssh fails when issue is there. PLEASE upgrade, no one in TAC will even bother with this, its long time unsupported version.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 20:04:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200086#M37515</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-08T20:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200087#M37516</link>
      <description>&lt;P&gt;Thanks Andy. &amp;nbsp;I will try that. &amp;nbsp;Yes we’re trying to upgrade asap. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 22:35:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200087#M37516</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-08T22:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200088#M37517</link>
      <description>&lt;P&gt;Yes sir, you should! Now I will go about my weekend birthday celebration...one year older, man, nothing to celebrate &lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 22:59:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200088#M37517</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-08T22:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200089#M37518</link>
      <description>&lt;P&gt;Happy birthday! and thanks for your suggestion. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ken&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 23:22:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200089#M37518</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-08T23:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200091#M37520</link>
      <description>&lt;P&gt;Thank you! Have a nice weekend.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 23:27:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200091#M37520</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-08T23:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200114#M37530</link>
      <description>&lt;P&gt;Sounds like an ARP issue to me, as a policy installation will force a gratuitous ARP for all firewall and NAT addresses if the cluster object is not set to use VMAC (which is the default behavior).&amp;nbsp; Next time you have an outage, check the ARP caches of the surrounding routers, are they losing the IP to MAC mapping for the firewall and/or NAT addresses?&amp;nbsp; Command &lt;STRONG&gt;fw ctl arp&lt;/STRONG&gt; might be helpful to diagnose.&amp;nbsp; If it is found to be an ARP issue, you can try setting VMAC on the cluster, reinstall policy twice and see if it helps.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2023 17:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200114#M37530</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-12-09T17:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200198#M37562</link>
      <description>&lt;P&gt;Thank you Timothy I will try that today. I go onsite to troubleshoot today.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 14:58:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200198#M37562</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-11T14:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200200#M37564</link>
      <description>&lt;P&gt;Hey Kenny,&lt;/P&gt;
&lt;P&gt;Let us know how it goes. I see what Tim is saying, if arp is not there, it will never work, sort of goes without saying. Mind you, that coommand would show you if there are ny proxy arp entries.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 15:10:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200200#M37564</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-11T15:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200201#M37565</link>
      <description>&lt;P&gt;You can also run just arp, as I did below in my lab. So in my case, 172.16.10.1 is our lab Fortigate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-STANDALONE-backup:0]# arp&lt;BR /&gt;Address HWtype HWaddress Flags Mask Iface&lt;BR /&gt;172.16.10.233 ether 50:06:00:07:00:00 C eth0&lt;BR /&gt;172.16.10.126 ether 00:0c:29:27:56:d6 C eth0&lt;BR /&gt;172.16.10.1 ether e8:1c:ba:4e:89:87 C eth0&lt;BR /&gt;[Expert@CP-STANDALONE-backup:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 15:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200201#M37565</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-11T15:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200228#M37566</link>
      <description>&lt;P&gt;the arps look ok on the inside.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the firewalls i get:&lt;/P&gt;&lt;P&gt;[Expert@gto-fw-1:0]# fw ctl arp&lt;BR /&gt;No proxy ARP entries&lt;BR /&gt;[Expert@gto-fw-1:0]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the vmac and it is already applied.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 19:49:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200228#M37566</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-11T19:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200229#M37567</link>
      <description>&lt;P&gt;When doing arp on the problem gateways, I only get 2 arps, one for management and one for the cluster interface.&amp;nbsp; When comparing to a known good gateway, there are many more arps for all the devices behind the firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 20:04:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200229#M37567</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-11T20:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200231#M37568</link>
      <description>&lt;P&gt;Can you just run arp?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 20:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200231#M37568</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-11T20:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200242#M37569</link>
      <description>&lt;P&gt;yes, i did run arp, i only see 2 arps.&amp;nbsp; mgmt and cluster.&amp;nbsp; for some reason it is not getting all the other arps from the devices inside.&amp;nbsp; could it be a certificate or license problem?&amp;nbsp; the cert is good until 12/26/23, so that is next thing to do after i fix this.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 23:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200242#M37569</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-11T23:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200251#M37570</link>
      <description>&lt;P&gt;Apologies mate, missed your first response, my bad. Long day troubleshooting Cisco/Fortigate vpn issue lol. Anyway, so here is my suggestion...can you verify that routes are similar? Just type route from expert mode and compare.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 23:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200251#M37570</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-11T23:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200366#M37590</link>
      <description>&lt;P&gt;yes the routes are the same.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 17:44:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200366#M37590</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-12T17:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200368#M37591</link>
      <description>&lt;P&gt;Got it. Any luck so far or still same issue?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 18:16:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200368#M37591</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-12T18:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: gateways failing until policies are pushed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200371#M37592</link>
      <description>&lt;P&gt;Same issue.&amp;nbsp; Also I tried to renew the cert and got an error message.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 19:15:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/gateways-failing-until-policies-are-pushed/m-p/200371#M37592</guid>
      <dc:creator>kehagen</dc:creator>
      <dc:date>2023-12-12T19:15:16Z</dc:date>
    </item>
  </channel>
</rss>

