<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205407#M38743</link>
    <description>&lt;P&gt;Yes, agree 100%, did not realize it was the same subnet. Thats odd then, as there would be no routing involved. What is .87 IP? Just a wireless client?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2024 01:01:00 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-08T01:01:00Z</dc:date>
    <item>
      <title>How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205112#M38671</link>
      <description>&lt;P&gt;Hi Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently we find an interesting thing, the environment is as below:&lt;/P&gt;&lt;P&gt;2x Gaia Security Gateways (R81.20 take 26 ) in a ClusterXL Active/Standby mode, the VIP is 10.217.81.1, the active member is 10.217.81.2 .&lt;/P&gt;&lt;P&gt;The interface acted as a gateway of wifi users, the DHCP is on the Wifi access switches. As the DHCP will change the ARP entry and according to&amp;nbsp;sk175603&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk175603" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk175603&lt;/A&gt;&amp;nbsp; , the parameter was set to 1&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;( fw ctl set int cphwd_refresh_nh 1 -a )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Let's see the below captures,&amp;nbsp; we can see that from Frame No.533 to 536, the client 33:35:0c keeps asking gateway's MAC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24376i6CDA3B4448B08034/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture1.png" alt="Capture1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24377iC15CDC1F2C806EE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.png" alt="Capture2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;At Frame No.537, the gateway d2:c3:20 replied to the client.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;My question is, &lt;STRONG&gt;why the Gaia gateway didn't learn the ARP entry for the client 10.217.81.87 from Frame No.536?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And from Frame No.539, the gateway 10.217.81.1 keeps asking for the client's MAC, which should tell to 10.217.81.2 ? This behavior really looks like an ARP Spoofing... and if downstream switch turned on Anti ARP Spoofing feature, these broadcasts might be taken as spoofing.. (e.g. A asks for B's MAc address and tell to Z ?....If A asks CDEFGHIJKLM's MACs and all send to Z , then Z will receive huge replies from&amp;nbsp;CDEFGHIJKLM..)&lt;/P&gt;&lt;P&gt;Actually this is our issue : the client didn't receive these ARP request broadcast packets, and the gateway doesn't have the ARP entry for the client 10.217.81.87. So if a Frame reached Gaia gateway, but it doesn't have the destination MAC address, then the Frame will be dropped?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas about the ARP learning process of Gaia Gateway, I know it is Linux OS based, and might totally different with Cisco Switches...I think Cisco Switch should be able to learn the ARP entry from the ARP requests which sent to gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 05:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205112#M38671</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-06T05:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205116#M38673</link>
      <description>&lt;P&gt;Hi GeorgeF,&lt;/P&gt;&lt;P&gt;It seems you should open a TAC case. Before you open it, install the latest Jumbo take. This will save an iteration round between the TAC and you.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Akos&lt;/P&gt;&lt;P&gt;I have searched for the ARP string among the resolved issues. Maybe one of them can help, but they don't fit to this issue according to the description&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 06:49:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205116#M38673</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-02-06T06:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205141#M38677</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;so let's put things in order,&amp;nbsp;&lt;BR /&gt;i assume this packet capture was taken on the GW, please let me know if it's not the case.&lt;BR /&gt;&lt;BR /&gt;1. it's possible that passive arp learning is not enabled on GAIA.&lt;BR /&gt;2. when working with cluster HA, the same MAC address of the active GW is used for both the physical IP and the VIP.&lt;BR /&gt;2.a - when the member is reaching out to get arp, it uses it's own physical IP as src IP, and it's MAC address.&lt;BR /&gt;2.b - i don't see why there should be mac spoofing, as this is how cluster is operates, as the mac shared between physical and vip ip addresses. and packets can be sent sometimes from vip and sometimes from physical IP with the same MAC.&lt;BR /&gt;&lt;BR /&gt;from what you describe, it sounds like the issue is that BC arp request sent from the GW is not reaching the host (did you verify that with wireshark on the host?), and because of that the GW is not able to learn the arp of this host. so this what needs to be investigated, my guess would be on switch level.&lt;BR /&gt;&lt;BR /&gt;"&lt;SPAN&gt;So if a Frame reached Gaia gateway, but it doesn't have the destination MAC address, then the Frame will be dropped?" - actually if you will look at the ethernet layer in this packet you will see that it has dst broadcast address, which the switch should send via all it's ports on the broadcast domain, and in case you took this packet capture on the GW, than the packet has reached the GW and didn't drop, and as you can see the GW even respond to that back to the HOST (is that reaching the HOST, is the host have the arp of the .1?)&lt;BR /&gt;in the ARP layer the dst MAC is empty because the host asking for the request still don't know the mac of it's dst.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 11:53:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205141#M38677</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-02-06T11:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205394#M38736</link>
      <description>&lt;P&gt;Hi,&lt;SPAN&gt;AmirArama&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for your detailed reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so let's put things in order,&amp;nbsp;&lt;BR /&gt;i assume this packet capture was taken on the GW, please let me know if it's not the case.&lt;/P&gt;&lt;P&gt;---&amp;nbsp; &amp;nbsp;Actually, it is captured on the WLC ( which connected to GW directly and in the same VLAN) , we have captured on the GW as well, and got the same result&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. it's possible that passive arp learning is not enabled on GAIA.&lt;/P&gt;&lt;P&gt;--- Could you please let me know to check and turn on the &lt;STRONG&gt;passive arp learning ? Then I might test if any help .&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. when working with cluster HA, the same MAC address of the active GW is used for both the physical IP and the VIP.&lt;BR /&gt;2.a - when the member is reaching out to get arp, it uses it's own physical IP as src IP, and it's MAC address.&lt;BR /&gt;2.b - i don't see why there should be mac spoofing, as this is how cluster is operates, as the mac shared between physical and vip ip addresses. and packets can be sent sometimes from vip and sometimes from physical IP with the same MAC.&lt;/P&gt;&lt;P&gt;---&amp;nbsp; Yes, I checked the broadcast frame, it did sent with the active member's IP as source , but the same MAC with the VIP.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;from what you describe, it sounds like the issue is that BC arp request sent from the GW is not reaching the host (did you verify that with wireshark on the host?), and because of that the GW is not able to learn the arp of this host. so this what needs to be investigated, my guess would be on switch level.&lt;/P&gt;&lt;P&gt;--- Yes, the BC arp request did reach WLC, but didn't reach the host, the below is the capture from HOST.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;I noticed that there is only one broadcast ARP Announcement packet since the HOST got the DHCP IP, so I just doubt why the GW didn't learn the HOST MAC from it ( not sure if it reached the GW, because only one packet sent, and hard to capture it )&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HOST packet capture.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24414i36C8B0975B2A3C39/image-size/large?v=v2&amp;amp;px=999" role="button" title="HOST packet capture.png" alt="HOST packet capture.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;"&lt;SPAN&gt;So if a Frame reached Gaia gateway, but it doesn't have the destination MAC address, then the Frame will be dropped?" - actually if you will look at the ethernet layer in this packet you will see that it has dst broadcast address, which the switch should send via all it's ports on the broadcast domain, and in case you took this packet capture on the GW, than the packet has reached the GW and didn't drop, and as you can see the GW even respond to that back to the HOST (is that reaching the HOST, is the host have the arp of the .1?)&lt;BR /&gt;in the ARP layer the dst MAC is empty because the host asking for the request still don't know the mac of it's dst.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-- that is what I suspect. Because I did see that the DNS traffic and Web Authentication traffic from the HOST have already reached the DNS server and Web Authentication Server, but no return/reply traffic reached the HOST, so DNS and Web Authentication failed. I just suspect if the GW dropped the traffic, as the return/reply packets whose destination is the HOST's MAC will be dropped because of no ARP entry for them on the GW.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can I check if those return/reply packets dropped or not by the GW?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again and much appreciate for your patient reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;George&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 23:09:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205394#M38736</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-07T23:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205395#M38737</link>
      <description>&lt;P&gt;Hey George,&lt;/P&gt;
&lt;P&gt;Just throwing this out there...for proxy arp, once added, needs policy install. As far as regular arp, if its saying who-has, it definitely tells us that its not able to "discover" the device or host in question. Why? Thats another question. Have you tried doing zdebug to see if firewall is indeed dropping it?&lt;/P&gt;
&lt;P&gt;Say if IP is 10.10.10.10, you can run fw ctl zdebug + drop | grep 10.10.10.10&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 23:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205395#M38737</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-07T23:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205399#M38739</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much for your reply.&lt;/P&gt;&lt;P&gt;I am thinking is it possible to let the GW send ARP request to the WLC directly, as the DHCP is on the WLC, so it should know all the IP-MAC entries for all hosts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is, GW send a &lt;STRONG&gt;unicast&lt;/STRONG&gt; to WLC:&amp;nbsp; "who has 10.217.81.87, please tell 10.217.81.2" , it would be another solution for the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 00:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205399#M38739</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-08T00:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205402#M38740</link>
      <description>&lt;P&gt;Good point about jumbo hotfix, I agree &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 00:53:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205402#M38740</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T00:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205403#M38741</link>
      <description>&lt;P&gt;Right, but the issue is that if that request does not know how to get there, it wont work. I suspect it could be routing issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 00:55:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205403#M38741</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T00:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205404#M38742</link>
      <description>&lt;P&gt;That shouldn't be a routing issue, as they are in the same VLAN and the some broadcast domain, as my understanding,&amp;nbsp; all ARP related are layer 2&amp;nbsp; issue&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 00:58:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205404#M38742</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-08T00:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205407#M38743</link>
      <description>&lt;P&gt;Yes, agree 100%, did not realize it was the same subnet. Thats odd then, as there would be no routing involved. What is .87 IP? Just a wireless client?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 01:01:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205407#M38743</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T01:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205411#M38745</link>
      <description>&lt;P&gt;.87 is a wireless HOST 's IP assigned by the DHCP server(DHCP service is on the WLC (wireless controller))&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 01:21:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205411#M38745</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-08T01:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205412#M38746</link>
      <description>&lt;P&gt;Here is my suggestion...IF this issue happens ONLY with that machine, why just not reboot it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 01:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205412#M38746</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T01:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205421#M38749</link>
      <description>&lt;P&gt;Some machines have this issue, some don't have, and already rebooted many times.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not very sure whether the WLC dropped the broadcast packets or not, but if the GW can learn about the ARP entry from the ARP request then it will solve the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 05:17:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205421#M38749</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-08T05:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205495#M38779</link>
      <description>&lt;P&gt;Yes, to see the routing behavior you can run 'fw monitor'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So for example if your client IP is 10.10.10.10 and web server is 6.6.6.6 run this:&lt;BR /&gt;fw monitor -F "10.10.10.10,0,6.6.6.6,0,0" -F "6.6.6.6,0,10.10.10.10,0,0"&lt;/P&gt;
&lt;P&gt;What i expect you to see is that 10.10.10.10&amp;gt;6.6.6.6 (assuming not dropped by policy and such) will be with i,I,o,O(maybe not O if you going through hide NAT), and on the return direction you would see only i,I, without any o, because the GW doesn't have a nexthop for this packet as it's missing it's mac address.&lt;/P&gt;
&lt;P&gt;well, you can add static arp entry in the OS to be 100% this is the issue.&lt;BR /&gt;&lt;BR /&gt;If i were you, i would configure mirror port on the port connected to this PC, and get the output on another PC with wireshark. and see if the switch actually passing the arp broadcast to this PC from the GW to this port. if it doesn't, you need to figure out why, check the port configuration and stuff. and if it does, that means packet is dropped on the socket of the NIC or something like that, and that's another question. (but unlikely).&lt;BR /&gt;&lt;BR /&gt;I'm not familiar with any official way to change the arp behavior in GAIA so it learns arp passively. but maybe there is..&lt;BR /&gt;but anyhow, it would be a workaround, and you still have some issue on your L2 network.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 16:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205495#M38779</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-02-08T16:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205497#M38780</link>
      <description>&lt;P&gt;So if thats the case, I would try reboot WLC as next step, if you have not already. Otherwise, please run the fw monitor command&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86692"&gt;@AmirArama&lt;/a&gt;&amp;nbsp;indicated.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 16:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205497#M38780</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T16:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205842#M38856</link>
      <description>&lt;P&gt;Thanks very much Amir, yes, when I add the static ARP entry, the issue was resolved, which means it is the ARP related issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally we upgraded the Wireless Controller firmware version,and solved the issue.&lt;/P&gt;&lt;P&gt;Not the firewall's fault but it is a good chance to learn more about the L2 mechanism on GAIA platform.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 04:39:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205842#M38856</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-13T04:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205865#M38863</link>
      <description>&lt;P&gt;Great&lt;/P&gt;
&lt;P&gt;i'm glad to hear everything sorted out, and was as thought.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 09:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205865#M38863</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-02-13T09:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205897#M38867</link>
      <description>&lt;P&gt;Great job!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 11:10:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205897#M38867</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-13T11:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205988#M38892</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;Let's I summarize this post (Correct me in-case some points miss, or I am wrong):&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Experiencing ARP-related issues in a network with two Gaia Security Gateways in ClusterXL Active/Standby mode.&lt;/LI&gt;&lt;LI&gt;The issue involves the gateway not learning ARP entries for clients, leading to potential drops of frames.&lt;/LI&gt;&lt;LI&gt;Suggests investigating passive ARP learning on GAIA, considering the use of the same MAC address for both physical IP and VIP in cluster HA, and checking if broadcast ARP requests from the gateway reach the host.&lt;/LI&gt;&lt;LI&gt;Recommends checking for dropped packets using fw ctl zdebug and suggests rebooting the Wireless Controller (WLC).&lt;/LI&gt;&lt;LI&gt;Provides additional details, confirming the packet capture was taken on the WLC, not the GW directly. Express concern about the GW not learning ARP entries from broadcast packets and suspect that the GW might be dropping return/reply packets.&lt;/LI&gt;&lt;LI&gt;Proposes the idea of the GW sending ARP requests directly to the WLC, considering the DHCP service is on the WLC.&lt;/LI&gt;&lt;LI&gt;Also Suggests rebooting the WLC and using fw monitor to analyze routing behavior.&lt;/LI&gt;&lt;LI&gt;Recommends using fw monitor to observe routing behavior and suggests configuring a mirror port to check if the switch passes ARP broadcasts to the PC.&lt;/LI&gt;&lt;LI&gt;Also Propose adding a static ARP entry as a workaround.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The ARP-related issue was successfully resolved by adding a static ARP entry and upgrading the firmware of the Wireless Controller.&lt;/P&gt;&lt;P&gt;Hence The problem was not attributed to the firewall.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 18:39:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205988#M38892</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2024-02-13T18:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: How the Gaia Gateway cluster learn the ARP entry and update ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205989#M38893</link>
      <description>&lt;P&gt;I think thats very good summary, seems right to me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 18:47:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-the-Gaia-Gateway-cluster-learn-the-ARP-entry-and-update-ARP/m-p/205989#M38893</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-13T18:47:49Z</dc:date>
    </item>
  </channel>
</rss>

