<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GAiA Shows &amp;quot;Site cant be reached&amp;quot; - Logs show its allowed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/224717#M43194</link>
    <description>&lt;P&gt;Update guys!&lt;BR /&gt;&lt;BR /&gt;I was able to resolve this one, it just magically works for some reason. The problem right now is URL filtering is not working anymore after transitioning to a 2 tier setup.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Everyone, thank you for the assistance!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 06:40:46 GMT</pubDate>
    <dc:creator>SecurityNed</dc:creator>
    <dc:date>2024-08-28T06:40:46Z</dc:date>
    <item>
      <title>GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222239#M42565</link>
      <description>&lt;P&gt;Hello Checkmates!&lt;BR /&gt;&lt;BR /&gt;I'm in an unusual dilemma right now.&lt;BR /&gt;&lt;BR /&gt;I, for some reason, can't access the GAiA portal on one of my NGFWs. I can after performing a fw unloadlocal command.&lt;BR /&gt;&lt;BR /&gt;The thing is I have checked already the following:&lt;BR /&gt;&lt;BR /&gt;1. defined a unique port in the portal - i have defined it this way, as leaving it blank would automatically route me to the web VPN portal&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27031i1897FFEBBE9A647B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. checked logs for any blocked traffic - there's no blocked traffic as per logs &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (1).png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27032i9559737D968F454B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image (1).png" alt="image (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but still, i cant access the GAiA portal, only after i performed a fw unloadlocal&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (2).png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27033iB88AD6AA247E3833/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image (2).png" alt="image (2).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other thing that I can check to confirm if there's anything thats preventing me to access this portal? A NGFW on the same segment (172.16.16.254) works as intended, only this newly added one is experiencing this issue.&lt;BR /&gt;&lt;BR /&gt;Hoping for your insight on this one Checkmates!&lt;/P&gt;&lt;P&gt;Edit: Here's the policy: I changed already the 4443 to 8844 as there was a policy that used the 4443 port. This is to avoid confusion.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (3).png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27034i43B5043F16E21275/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image (3).png" alt="image (3).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222239#M42565</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-07-30T14:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222250#M42567</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/50346"&gt;@SecurityNed&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried the followings:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;a simple reboot one of the afffected GWs
&lt;UL&gt;
&lt;LI&gt;both member are affected?&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Change the port to an&amp;nbsp; another unique port&lt;/LI&gt;
&lt;LI&gt;What does the&amp;nbsp;show web ssl-port command show for port?&lt;/LI&gt;
&lt;LI&gt;what does the&amp;nbsp; fw ctl zdebug + drop show?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222250#M42567</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-07-30T14:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222253#M42569</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;I've already:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;rebooted the affected GWs (only one is affected, the other one works)&lt;/LI&gt;&lt;LI&gt;While waiting for a response I've changed 8844 to 4334, same behavior&lt;/LI&gt;&lt;LI&gt;I haven't checked this command yet&lt;/LI&gt;&lt;LI&gt;This one as well, as I've only used zdebug for traffic-related stuff&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'll get back to you when I get results for this. Currently due to time restrictions we're performing changes under fw unloadlocal.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:38:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222253#M42569</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-07-30T14:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222256#M42571</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/50346"&gt;@SecurityNed&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct fw cl zdebug..... I wanted to write this, but i am a human &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;One more&amp;nbsp; thing, can we say that, only the standby member is affected always?&lt;/P&gt;
&lt;P&gt;To be 100% percent sure, you are tring to access the MGMT IPS, right?&lt;/P&gt;
&lt;P&gt;And there was an issue, take a look at on this:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk147493" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk147493&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;/P&gt;
&lt;P&gt;Ak&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:45:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222256#M42571</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-07-30T14:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222263#M42576</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Not yet, currently both are standalone NGFWs, and thus we're wanting everything to be ready before we proceed with the cluster activity,&lt;BR /&gt;&lt;BR /&gt;I'm accessing it both via MGMT IP and via the configured IP where it is reachable on the Smart1 Appliance&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 15:03:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222263#M42576</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-07-30T15:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222265#M42578</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/50346"&gt;@SecurityNed&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aha, so it seems Policy issue for me, because #fw unloadlocal solves the problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you don't have a large policy, and this gW are not productives, so maybe yo can clone the working policy, and push it to the not working gw.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course, do the necessary changes before installation. If it solves the problem -&amp;gt; this is a policy issue.&lt;/P&gt;
&lt;P&gt;If I misunderstood that, and they are productive GW-s plese forget the above.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 15:11:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222265#M42578</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-07-30T15:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222272#M42580</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Actually they're running on the same policy table when publishing. So they're using the same policies with the working FW. I might try configuring a separate policy table for the meantime while we configure it to HA.&lt;BR /&gt;&lt;BR /&gt;Will update you once there are unusual stuff after our test.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 15:16:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222272#M42580</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-07-30T15:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222288#M42582</link>
      <description>&lt;P&gt;Can you send this please?&lt;/P&gt;
&lt;P&gt;clish -&amp;gt; show web ssl-port&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 16:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222288#M42582</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-30T16:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222311#M42586</link>
      <description>&lt;P&gt;This SK is the way to go.&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk91380" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk91380&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Please follow it. Explains about fw ctl zdebug and tcpdump&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We need to know why traffic is being blocked. Could be anti-spoofing for example.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe try to filter on IP and not port. So only 10.1.1.1 (example) and not src:10.1.1.1 or dst:10.1.1.1&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 13:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222311#M42586</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-01T13:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222343#M42597</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;you did not specify any SK, or am I blind?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 09:07:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222343#M42597</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-07-31T09:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222466#M42628</link>
      <description>&lt;P&gt;Thanks edited my post&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 13:56:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/222466#M42628</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-01T13:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: GAiA Shows "Site cant be reached" - Logs show its allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/224717#M43194</link>
      <description>&lt;P&gt;Update guys!&lt;BR /&gt;&lt;BR /&gt;I was able to resolve this one, it just magically works for some reason. The problem right now is URL filtering is not working anymore after transitioning to a 2 tier setup.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Everyone, thank you for the assistance!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 06:40:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GAiA-Shows-quot-Site-cant-be-reached-quot-Logs-show-its-allowed/m-p/224717#M43194</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-08-28T06:40:46Z</dc:date>
    </item>
  </channel>
</rss>

