<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem: CP gateways &amp;quot;lose&amp;quot; interfaces -  fw getifs is empty - but ip address shows th in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-CP-gateways-quot-lose-quot-interfaces-fw-getifs-is-empty/m-p/204340#M38534</link>
    <description>&lt;P&gt;Doesn’t matter what the OS configuration says if the firewall kernel module can’t see the interfaces.&lt;BR /&gt;Interface mapping issues is usually an issue that you see on Open Servers only.&lt;/P&gt;
&lt;P&gt;I do know that we did a kernel update in R81.20 which also included updates to the various NIC drivers.&lt;BR /&gt;If I had to guess, it has something to do with that.&lt;BR /&gt;We should have handled this through the upgrade process, though…&lt;/P&gt;</description>
    <pubDate>Sat, 27 Jan 2024 21:43:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-01-27T21:43:49Z</dc:date>
    <item>
      <title>Problem: CP gateways "lose" interfaces -  fw getifs is empty - but ip address shows the interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-CP-gateways-quot-lose-quot-interfaces-fw-getifs-is-empty/m-p/204232#M38523</link>
      <description>&lt;P&gt;I had a strange behavior on a gateway (appliance 3x00) that run on Gaia R81.10 JHF take 109.&lt;BR /&gt;&lt;BR /&gt;after several month running without problems, during normal operation some night before the gateway was not reachable by network anymore.&lt;BR /&gt;HW seems to be okay.&lt;BR /&gt;Connection by serial port was possible.&lt;BR /&gt;every outgoing ping from the gateway returns "operation not permitted."&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; did not solve the problem.&lt;BR /&gt;&lt;STRONG&gt;fwaccel off&lt;/STRONG&gt; did not solve the problem.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;reboot&lt;/STRONG&gt; didn't solve the problems. During boot the I can see that the gateway is unable to fetch the policy from gateway anymore, but without cp service the routing is working and the ports are reachable.&lt;/P&gt;&lt;P&gt;After &lt;STRONG&gt;cpstop&lt;/STRONG&gt; all outgoing and incoming connections - beside NAT/VPN - worked based on routing.&lt;/P&gt;&lt;P&gt;After &lt;STRONG&gt;cpstart&lt;/STRONG&gt; sames problem as before.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;fw getifs&lt;/STRONG&gt; did not show any interfaces anymore!&lt;/U&gt;&lt;/P&gt;&lt;P&gt;But ip address/ip route&amp;nbsp; showed the correct configuration, &lt;STRONG&gt;show config&lt;/STRONG&gt; in clish, too.&lt;BR /&gt;&lt;BR /&gt;After that we did a factory restore the R77.30 and upgrade to R81.10, reset SIC, reconnect to Mgmt and do a policy install with the old policy - no problems, every thing worked again.&lt;BR /&gt;&lt;BR /&gt;Then we did a upgrade to JHF 109 an we had the same problems as before.&lt;BR /&gt;A uninstall of the JHF did &lt;U&gt;not&lt;/U&gt; solve the problems!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;fw getifs&lt;/STRONG&gt; still did not show any interface anymore!&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I had a similar problem a year before at a different customer on all nodes of 2 gateway clusters (5x00 and 3x00) with R81.10 JHF take79 after reboot of these clusters.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We did a fresh install of these gateways, which solved the problems.&lt;/P&gt;&lt;P&gt;I already opened a case at CP.&lt;/P&gt;&lt;P&gt;They told me, based on the analyze of the snapshot files, there was a mismatch between OS interface mapping and CP interface mapping...that should not happened...&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;but the root cause is still unknown!&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Inside the Smart Center objects the interfaces are correct...&lt;BR /&gt;&lt;BR /&gt;So my question is, did anyone had similar problems before?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 10:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-CP-gateways-quot-lose-quot-interfaces-fw-getifs-is-empty/m-p/204232#M38523</guid>
      <dc:creator>DH</dc:creator>
      <dc:date>2024-01-26T10:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem: CP gateways "lose" interfaces -  fw getifs is empty - but ip address shows th</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-CP-gateways-quot-lose-quot-interfaces-fw-getifs-is-empty/m-p/204340#M38534</link>
      <description>&lt;P&gt;Doesn’t matter what the OS configuration says if the firewall kernel module can’t see the interfaces.&lt;BR /&gt;Interface mapping issues is usually an issue that you see on Open Servers only.&lt;/P&gt;
&lt;P&gt;I do know that we did a kernel update in R81.20 which also included updates to the various NIC drivers.&lt;BR /&gt;If I had to guess, it has something to do with that.&lt;BR /&gt;We should have handled this through the upgrade process, though…&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 21:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-CP-gateways-quot-lose-quot-interfaces-fw-getifs-is-empty/m-p/204340#M38534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-27T21:43:49Z</dc:date>
    </item>
  </channel>
</rss>

