<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217344#M41385</link>
    <description>&lt;P&gt;Unless someone's configured a static ARP entry you shouldn't be having an ARP issue - confirm that with 'ip neigh' or 'arp -a' from expert mode. If ARP is correct, start looking at tcpdumps to see if the traffic is leaving the internal gateway the right way and if it's arriving at the external gateway.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jun 2024 06:46:29 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2024-06-13T06:46:29Z</dc:date>
    <item>
      <title>Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217328#M41382</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hello Checkmates!&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;I currently have a dilemma right now, wherein we're attempting to replace a 5200 NGFW to a 5400 model, with the exact same configuration aside from an interface wherein the existing 5200 is connected to our Smart-1 appliance. (To visualize, the 5200 has 192.168.0.2, while the 5400 has 192.168.0.3, the rest has the same configuration in GAiA, routing and interfaces)&lt;/P&gt;&lt;P&gt;The topology is a two tier topology wherein a 5400 is acting as an external firewall, and we're attempting the existing 5200 appliance which is acting as an internal firewall to a 5400.&lt;/P&gt;&lt;P&gt;When we're attempting to cutover to the 5400, east-west traffic is working as intended, but connectivity from the internal 5400 to the external 5400 is non-existent. Traceroutes is terminated to where the connectivity of both internal and external firewall is.&lt;/P&gt;&lt;P&gt;Do take note that necessary changes were made as well, like routes and policies to accommodate the IP address that's being used by the 5400.&lt;BR /&gt;&lt;BR /&gt;I would like to know if possibly this is due to my ARP tables looking for the MAC address of the previous 5200? Or is it something else possibly. If you guys have similar experiences like this hoping for your input as it had me dumbfounded as to possibly why its not working.&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Hoping for the communities insight on this one.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 01:26:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217328#M41382</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T01:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217330#M41383</link>
      <description>&lt;P&gt;Maybe simple diagram would help us further, but I do agree, ARP sounds like a logical reason to me as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 01:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217330#M41383</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T01:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217331#M41384</link>
      <description>&lt;P&gt;You can also run arp -a from expert mode to verify entries seen.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 02:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217331#M41384</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T02:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217344#M41385</link>
      <description>&lt;P&gt;Unless someone's configured a static ARP entry you shouldn't be having an ARP issue - confirm that with 'ip neigh' or 'arp -a' from expert mode. If ARP is correct, start looking at tcpdumps to see if the traffic is leaving the internal gateway the right way and if it's arriving at the external gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 06:46:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217344#M41385</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-06-13T06:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217365#M41388</link>
      <description>&lt;P&gt;Yes I have the initial arp -a output extracted now and will just wait for the scheduled downtime for the in-line activity. Will get back to this thread in a few hours for the update &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 09:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217365#M41388</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T09:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217366#M41389</link>
      <description>&lt;P&gt;We have arp entries for port forwarding on the external firewall, but it's not related to the connectivity between the internal and external firewall. I will still check the arp tables after the cutover and see if the arp tables are updated, if not, i can just perform a clear arp in clish correct?&lt;BR /&gt;&lt;BR /&gt;I just realized as well that you can change the mac address in GAiA, would it be also plausible to copy the mac address on the 5200 to the 5400's equivalent interface?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 09:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217366#M41389</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T09:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217383#M41390</link>
      <description>&lt;P&gt;From my lab:&lt;/P&gt;
&lt;P&gt;[Expert@CP-STANDALONE:0]#&lt;BR /&gt;[Expert@CP-STANDALONE:0]# ip neigh&lt;BR /&gt;172.16.10.128 dev eth0 lladdr 00:0c:29:2e:c1:7a STALE&lt;BR /&gt;172.16.10.111 dev eth0 lladdr 50:06:00:05:00:00 STALE&lt;BR /&gt;172.16.10.1 dev eth0 lladdr e8:1c:ba:4e:89:87 DELAY&lt;BR /&gt;172.16.10.199 dev eth0 lladdr 50:06:00:0e:00:00 STALE&lt;BR /&gt;172.16.10.126 dev eth0 lladdr 00:0c:29:27:56:d6 STALE&lt;BR /&gt;[Expert@CP-STANDALONE:0]# arp -a&lt;BR /&gt;? (172.16.10.128) at 00:0c:29:2e:c1:7a [ether] on eth0&lt;BR /&gt;? (172.16.10.111) at 50:06:00:05:00:00 [ether] on eth0&lt;BR /&gt;? (172.16.10.1) at e8:1c:ba:4e:89:87 [ether] on eth0&lt;BR /&gt;? (172.16.10.199) at 50:06:00:0e:00:00 [ether] on eth0&lt;BR /&gt;? (172.16.10.126) at 00:0c:29:27:56:d6 [ether] on eth0&lt;BR /&gt;[Expert@CP-STANDALONE:0]# ip -s -s neigh flush all&lt;BR /&gt;172.16.10.128 dev eth0 lladdr 00:0c:29:2e:c1:7a used 51318/51322/51317 probes 0 STALE&lt;BR /&gt;172.16.10.111 dev eth0 lladdr 50:06:00:05:00:00 used 43622/43621/43596 probes 1 STALE&lt;BR /&gt;172.16.10.1 dev eth0 lladdr e8:1c:ba:4e:89:87 ref 1 used 0/0/0 probes 1 DELAY&lt;BR /&gt;172.16.10.199 dev eth0 lladdr 50:06:00:0e:00:00 used 54871/43189/43165 probes 4 STALE&lt;BR /&gt;172.16.10.126 dev eth0 lladdr 00:0c:29:27:56:d6 used 13042/13037/13012 probes 1 STALE&lt;/P&gt;
&lt;P&gt;*** Round 1, deleting 5 entries ***&lt;BR /&gt;*** Flush is complete after 1 round ***&lt;BR /&gt;[Expert@CP-STANDALONE:0]# arp -a&lt;BR /&gt;? (172.16.10.1) at e8:1c:ba:4e:89:87 [ether] on eth0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://linux-audit.com/how-to-clear-the-arp-cache-on-linux/" target="_blank"&gt;https://linux-audit.com/how-to-clear-the-arp-cache-on-linux/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 11:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217383#M41390</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T11:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217400#M41394</link>
      <description>&lt;P&gt;Its weird, as ARP tables are updated correctly, but now it shows ip spoofing as the cause.&lt;BR /&gt;&lt;BR /&gt;0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912320;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notification: sending single drop notification, conn: &amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912321;[cpu_0];[SIM-207388730];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:&amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912321;[cpu_0];[SIM-207388730];pkt_handle_no_match: packet dropped (spoofed address), conn: &amp;lt;20.20.0.4,65535,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912321;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notification: (0,0) received drop, reason: Anti-Spoofing, conn: &amp;lt;20.20.0.4,65535,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912321;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notification: sending packet dropped notification drop mode: 0 debug mode: 1 send as is: 0 track_lvl: -1, conn: &amp;lt;20.20.0.4,65535,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912321;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notification: sending single drop notification, conn: &amp;lt;20.20.0.4,65535,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912322;[cpu_0];[SIM-207388730];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:&amp;lt;20.20.0.4,65535,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912343;[cpu_0];[SIM-207388730];pkt_handle_no_match: packet dropped (spoofed address), conn: &amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912343;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notification: (0,0) received drop, reason: Anti-Spoofing, conn: &amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912343;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notification: sending packet dropped notification drop mode: 0 debug mode: 1 send as is: 0 track_lvl: -1, conn: &amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912343;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notification: sending single drop notification, conn: &amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912344;[cpu_0];[SIM-207388730];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:&amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912403;[cpu_0];[SIM-207388730];pkt_handle_no_match: packet dropped (spoofed address), conn: &amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;BR /&gt;@;994912403;[cpu_0];[SIM-207388730];sim_pkt_send_drop_notificaPKT_IN_DROP vsid=0, conn:&amp;lt;20.20.0.4,23046,20.20.0.3,0,1&amp;gt;;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take note that we haven't experienced it on the previous setup with the 5200. We're currently adding the 20.20.0.0/24 segment to the topology.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 12:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217400#M41394</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T12:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217404#M41396</link>
      <description>&lt;P&gt;In such scenario, you can try make an exception for anti spoofing, or simply set it to detect or disable and install policy, test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26226i4E498D356AC9CBC2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:01:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217404#M41396</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T13:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217411#M41400</link>
      <description>&lt;P&gt;Currently performed this but the spoofing still persists, troubleshooting at the moment &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:11:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217411#M41400</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T13:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217414#M41402</link>
      <description>&lt;P&gt;Are you allowed to do remote?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:15:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217414#M41402</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T13:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217418#M41405</link>
      <description>&lt;P&gt;Unfortunately I cant, I don't have the spoofing issue now, but connection from internal to external firewall's finnicky, as all traffic are getting dropped by the cleanup. I'll update my findings as soon as I can see one.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:31:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217418#M41405</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217419#M41406</link>
      <description>&lt;P&gt;Thats fair. hey, any way you can send basic diagram, just scribble something and point out EXACTLY whats failing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:32:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217419#M41406</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T13:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217434#M41408</link>
      <description>&lt;P&gt;We're really stumped right now. Here's the requested diagram:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image.jpg" style="width: 749px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26230i2E2EB4B188FF2D01/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image.jpg" alt="Image.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're encountering these types of logs when we cutover to our new setup&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-06-13 221441.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26231i6653A75D15F805B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-06-13 221441.png" alt="Screenshot 2024-06-13 221441.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;While when we go back to the working old topology, we have this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-06-13 224536.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26232i0CCC2C38254D6F5F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-06-13 224536.png" alt="Screenshot 2024-06-13 224536.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We're still checking as to where we might have missed a configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 14:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217434#M41408</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T14:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217435#M41409</link>
      <description>&lt;P&gt;Do you have "network defined by routes" set on all your internal interfaces for anti-spoofing topology?&amp;nbsp; If you do and are encountering anti-spoofing issues your routing table on the new gateway is wrong or missing something, full stop.&lt;/P&gt;
&lt;P&gt;Also please post a redacted log card of the anti-spoofing drop, and look closely at the "interface" part of the drop log.&amp;nbsp; Next to the interface name where the anti-spoofing drop occurred, is the arrow pointing down (meaning inbound) or up (meaning outbound)?&amp;nbsp; While anti-spoofing drops normally occur inbound, it is not commonly known that they can also occur outbound (up arrow) which will stymie your troubleshooting if you aren't aware of it.&lt;/P&gt;
&lt;P&gt;For testing purposes you can disable all anti-spoofing enforcement "on the fly" as mentioned in my article below but if your routing is wrong, doing so will not make a difference and things will still not work:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/A-Primer-on-Anti-Spoofing/m-p/61580/highlight/true#M12474" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/A-Primer-on-Anti-Spoofing/m-p/61580/highlight/true#M12474&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 14:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217435#M41409</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-06-13T14:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217441#M41412</link>
      <description>&lt;P&gt;I totally see what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;is saying.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Network defined by routes&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26234i6C4D8FD7EBD21579/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 15:06:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217441#M41412</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T15:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217442#M41413</link>
      <description>&lt;P&gt;One more thing that just came to my mind...since 20.20.20.x is Azure range, MAKE SURE nothing on that end may had changed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 15:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217442#M41413</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T15:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217451#M41417</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We have resolved the spoofing issue by disabling anti-spoofing on the interfaces where the internal and external firewalls connect. Please see screenshots below:&lt;BR /&gt;&lt;BR /&gt;Internal Firewall:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-06-13 231610.png" style="width: 647px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26235iA585DD7BCE3932D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-06-13 231610.png" alt="Screenshot 2024-06-13 231610.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External firewall:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-06-13 232336.png" style="width: 646px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26236iD532C7B33F9B2279/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-06-13 232336.png" alt="Screenshot 2024-06-13 232336.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While here's what happens when we do the cutover:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-06-13 232518.png" style="width: 903px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26237iED581682901E1C9D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-06-13 232518.png" alt="Screenshot 2024-06-13 232518.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It's so unusual as when we cutover to the 5400 (INTERNAL-FW1), it just shows logs originating from public ip addresses, while normal traffic shows as normal (Internal_FWA)&lt;BR /&gt;&lt;BR /&gt;I'm really lost right now. The only difference is that one IP address, the rest, even the routes, is the same&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-06-13 232840.png" style="width: 783px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26238i80A2AD83C94F3724/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-06-13 232840.png" alt="Screenshot 2024-06-13 232840.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We cannot upgrade FWA right now as it's the only working internal firewall, so aside from the ip address, the other difference is the version, but i think that wouldn't be the case.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 15:29:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217451#M41417</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-06-13T15:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217456#M41421</link>
      <description>&lt;P&gt;Not that we dont believe you config is the same, BUT...to be 100% positive, here is what I would personally do. Run below on BOTH firewalls and compare in notepad++ once they are off the firewalls (you can give it any file name and send to any dir, I usually give hostname and current date)&lt;/P&gt;
&lt;P&gt;from expert:&lt;/P&gt;
&lt;P&gt;clish -c "show configuration" &amp;gt; /var/log/old_fw_config_June13_2024.txt&lt;/P&gt;
&lt;P&gt;new fw:&lt;/P&gt;
&lt;P&gt;clish -c "show configuration" &amp;gt; /var/log/new_fw_config_June13_2024.txt&lt;/P&gt;
&lt;P&gt;Compare and see what you get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 16:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217456#M41421</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-13T16:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping 5200 NGFW to 5400 NGFW - Connectivity Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217462#M41422</link>
      <description>&lt;P&gt;Glad to hear that it works, but having anti-spoofing disabled long-term is not where you want to be.&amp;nbsp; Having to do that to get things working would indicate that traffic is not routing the way you think it is, and disabling anti-spoofing is now possibly allowing ICMP redirects to "correct" the situation for you.&amp;nbsp; Relying on this redirect mechanism to keep things running is notoriously unstable so watch out, here are the pages covering this from my last book (no I am not a skilled graphic artist, this is why I work in IT):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="redirect1.png" style="width: 823px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26239i2593A10953324CF2/image-size/large?v=v2&amp;amp;px=999" role="button" title="redirect1.png" alt="redirect1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="redirect2.png" style="width: 813px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26240iAA76B8E3D88C38BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="redirect2.png" alt="redirect2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="redirect3.png" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26241i1F7980CC11D408DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="redirect3.png" alt="redirect3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 16:27:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Swapping-5200-NGFW-to-5400-NGFW-Connectivity-Issue/m-p/217462#M41422</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-06-13T16:27:55Z</dc:date>
    </item>
  </channel>
</rss>

