<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster Load sharing issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227903#M43822</link>
    <description>&lt;P&gt;Most L3 routers (not L2 switches) will refuse to cache a multicast MAC address received in an ARP reply so you will probably need to hardcode this on all L3 devices surrounding the gateway.&lt;/P&gt;
&lt;P&gt;For your L2 switches, not all switches will handle multicast MAC addresses correctly, and will not consistently forward traffic bound for a multicast MAC to all the proper ports.&amp;nbsp; Once again, hardcoding the multicast MACs at the switch level may be required.&amp;nbsp; To summarize:&lt;/P&gt;
&lt;P&gt;MULTICAST MACs = HARDCODING PAIN &amp;amp; SUFFERING&lt;/P&gt;
&lt;P&gt;When taking your tcpdumps, make sure to include the -e option so you can see the Layer 2 MAC addresses.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2024 13:32:56 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2024-09-25T13:32:56Z</dc:date>
    <item>
      <title>Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227378#M43726</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am using R81.20 with JHF-take 65 for my FW1 and FW2. I made cluster.&amp;nbsp;&lt;/P&gt;&lt;P&gt;While enabling the Load balance , I am not able to reach global dns 8.8.8.8 from both Gateway.&lt;/P&gt;&lt;P&gt;on HA we are able to reach global dns.&lt;/P&gt;&lt;P&gt;Attached some snap for reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VIKAS_SINGH_0-1726838526507.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27724i0EC766B9FDA09E0F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VIKAS_SINGH_0-1726838526507.png" alt="VIKAS_SINGH_0-1726838526507.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cphaprob stat output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VIKAS_SINGH_1-1726838526522.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27725i5D46EC305A6C5955/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VIKAS_SINGH_1-1726838526522.png" alt="VIKAS_SINGH_1-1726838526522.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ping global dns&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VIKAS_SINGH_2-1726838526526.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27723i2F203F05A89AF2CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VIKAS_SINGH_2-1726838526526.png" alt="VIKAS_SINGH_2-1726838526526.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 13:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227378#M43726</guid>
      <dc:creator>VIKASH_GIRI</dc:creator>
      <dc:date>2024-09-20T13:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227417#M43741</link>
      <description>&lt;P&gt;What do you see with a tcpdump when trying this?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 19:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227417#M43741</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-20T19:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227438#M43756</link>
      <description>&lt;P&gt;We definitely need more info. As Phoneboy advised, run tcpdump, fw monitor, try ip r g 8.8.8.8. Can you also send us output of route command from expert mode?&lt;/P&gt;
&lt;P&gt;What does traceroute show? Network unreachable is super generic error that can mean multiple things. Could be interface issue, default gateway problem, route.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 00:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227438#M43756</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-21T00:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227442#M43758</link>
      <description>&lt;P&gt;What switches do you have and how is the multicast/IGMP/arp config?&lt;/P&gt;
&lt;P&gt;See also sk44898&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 01:17:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227442#M43758</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-22T01:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227444#M43760</link>
      <description>&lt;P&gt;Valid point Chris.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 04:17:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227444#M43760</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-21T04:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227445#M43761</link>
      <description>&lt;P&gt;i hvnt taken tcpdump , will post on Monday .&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 07:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227445#M43761</guid>
      <dc:creator>VIKASH_GIRI</dc:creator>
      <dc:date>2024-09-21T07:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227446#M43762</link>
      <description>&lt;P&gt;we are using Aruba core switches 8360V2 and we have configure MLAG. all VLAN configured on Core switches .&lt;/P&gt;&lt;P&gt;Gateway side we hv done the Bond configuration on both GW.&lt;/P&gt;&lt;P&gt;I hv attached my setup diagram below , also i forget to mention that i am using Ipsec blade and mobile blade&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 07:49:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227446#M43762</guid>
      <dc:creator>VIKASH_GIRI</dc:creator>
      <dc:date>2024-09-21T07:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227449#M43765</link>
      <description>&lt;P&gt;I have bunch of colleagues who deal with Aruba constantly (I personally dont as much), but I always hear them talk about igmp snooping. Maybe something you can verify if its enabled. Obviously, if you have multicast traffic on your network, that needs to be enabled, otherwise, probably not.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 10:58:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227449#M43765</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-21T10:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227526#M43772</link>
      <description>&lt;P&gt;I'm not sure the bonds are so relevant here but you can check to ensure the hashing mode aligns.&lt;/P&gt;
&lt;P&gt;Per the sk article I referenced above Load-sharing cluster mode isn't compatible with all vendors switches, you may need to implement some changes.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 09:59:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227526#M43772</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-23T09:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227661#M43790</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9385"&gt;@VIKASH_GIRI&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Were you able to get any traction on this issue?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 04:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227661#M43790</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-24T04:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227846#M43811</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;Its running setup so not able to do any troubleshooting , i will get time on weekend only . will keep you posted.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 07:49:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227846#M43811</guid>
      <dc:creator>VIKASH_GIRI</dc:creator>
      <dc:date>2024-09-25T07:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227847#M43812</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hv one query ,i hv gone through some documents from checkpoint that Load sharing will not work when Ipsec and Mobile blade enable...is it true? or ?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 07:57:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227847#M43812</guid>
      <dc:creator>VIKASH_GIRI</dc:creator>
      <dc:date>2024-09-25T07:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227864#M43814</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Please see&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="css-vy7rm"&gt;sk101539 for more information, some limitations are version specific.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also worth mentioning to keep an eye out for&amp;nbsp; ElasticXL with R82 in terms of load-sharing capabilities.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 09:18:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227864#M43814</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-25T09:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Load sharing issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227903#M43822</link>
      <description>&lt;P&gt;Most L3 routers (not L2 switches) will refuse to cache a multicast MAC address received in an ARP reply so you will probably need to hardcode this on all L3 devices surrounding the gateway.&lt;/P&gt;
&lt;P&gt;For your L2 switches, not all switches will handle multicast MAC addresses correctly, and will not consistently forward traffic bound for a multicast MAC to all the proper ports.&amp;nbsp; Once again, hardcoding the multicast MACs at the switch level may be required.&amp;nbsp; To summarize:&lt;/P&gt;
&lt;P&gt;MULTICAST MACs = HARDCODING PAIN &amp;amp; SUFFERING&lt;/P&gt;
&lt;P&gt;When taking your tcpdumps, make sure to include the -e option so you can see the Layer 2 MAC addresses.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 13:32:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Load-sharing-issue/m-p/227903#M43822</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-09-25T13:32:56Z</dc:date>
    </item>
  </channel>
</rss>

