<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Standby member no internet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228817#M44056</link>
    <description>&lt;P&gt;K, fair enough...keep us posted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2024 02:57:21 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-10-03T02:57:21Z</dc:date>
    <item>
      <title>Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228335#M43927</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;So it's been discussed a lot but my story is a little bit different.&amp;nbsp; I have a client with a bunch of Active/Standby ClusterXL&amp;nbsp; clusters in which the Standby member cannot access he internet at all.&lt;/P&gt;&lt;P&gt;Long story short: I almost ran out of search keywords in this forum and on google regarding the issue. First of all, sk43807 was followed line-by-line with no luck. then fwha_forw_packet_to_not_active 1/0 - no change at all and this is why!&amp;nbsp; - please see the diagram. There is more than 1 interface but you get the picture.&lt;/P&gt;&lt;P&gt;Both members are running only on private IP addresses.&amp;nbsp; All traffic is NAT hidden behind a public IP address and the CORE router knows to route the /32 of that public IP address to the VIP address of the cluster.&amp;nbsp; When the ACTIVE node (doesn't matter, fw1 or fw2) sends any packets it's NAT-ed behind that public IP address and sent on it's way. The return traffic is forwarded by the router to the VIP which and everything works (as VIP is bounded to the Active member).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the Standby member tries to access everything I can see (and I'm very sorry but I cannot put real captures here due to IP address privacy)&amp;nbsp; that packets that originates from Standby&amp;nbsp; are forwarded to the Active member over the SYNC interface. The Active member then matches the traffic to it's rulebase, applies NAT and packets go out to CORE and then to internet. The return traffic is funny. It arrives on the Active member and there vanishes. It's not dropped (fw ctl zdebug +drop) , it simple vanishes and is not forwarded to the Standby member (which is a function by design I presume).&lt;/P&gt;&lt;P&gt;So eventually I've lost all my hops in making this work.&lt;/P&gt;&lt;P&gt;Any help or guidance will really be apreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wish all the best,&lt;/P&gt;</description>
      <pubDate>Sat, 28 Sep 2024 17:04:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228335#M43927</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-09-28T17:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228356#M43928</link>
      <description>&lt;P&gt;Forwarding outbound traffic through the sync interface is correct in this case. Return packet disappearing without forwarding back is not. Check if you have any associated drops. Also, if stuck, please open a support request.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 10:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228356#M43928</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-09-29T10:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228358#M43929</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96591"&gt;@melcu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run am #fw ctl zdebug + drop on the standby member. Maybe will appear something meaningful.&lt;/P&gt;
&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 11:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228358#M43929</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-29T11:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228370#M43930</link>
      <description>&lt;P&gt;If I were you, apart from what the guys already asked, I would make sure routes are exactly the same on both members. Also, to confirm, navigate to cluster object in smart console, open network, then topology and click get interfaces WITHOUT topology, just to verify there are no errors.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 13:38:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228370#M43930</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T13:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228371#M43931</link>
      <description>&lt;P&gt;I've created a lab with the exact IP schema from the above diagram.&amp;nbsp; Pinging google DNS&amp;nbsp; I can see this on the Active member, but nothing on the standby member. See the attached.&lt;/P&gt;&lt;P&gt;Later edit: Also&amp;nbsp; interfaces and routes are identical.&lt;/P&gt;&lt;P&gt;[Expert@gw01:0]# ip ro ls&lt;BR /&gt;10.134.0.0/24 dev eth1&amp;nbsp; proto kernel&amp;nbsp; scope link&amp;nbsp; src 10.134.0.11&lt;BR /&gt;10.144.70.0/24 dev eth0&amp;nbsp; proto kernel&amp;nbsp; scope link&amp;nbsp; src 10.144.70.21&lt;BR /&gt;10.144.0.0/16 via 10.144.70.1 dev eth0&amp;nbsp; proto routed&lt;BR /&gt;default via 10.134.0.1 dev eth1&amp;nbsp; proto routed&lt;/P&gt;&lt;P&gt;[Expert@gw02:0]# ip ro ls&lt;BR /&gt;10.134.0.0/24 dev eth1&amp;nbsp; proto kernel&amp;nbsp; scope link&amp;nbsp; src 10.134.0.12&lt;BR /&gt;10.144.70.0/24 dev eth0&amp;nbsp; proto kernel&amp;nbsp; scope link&amp;nbsp; src 10.144.70.22&lt;BR /&gt;10.144.0.0/16 via 10.144.70.1 dev eth0&amp;nbsp; proto routed&lt;BR /&gt;default via 10.134.0.1 dev eth1&amp;nbsp; proto routed&lt;/P&gt;&lt;P&gt;Getting interfaces with or without topology goes well. At least in my lab as I don't have any access in their environment. Here I can do whatever I want as it's a lab .. no impact &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 13:42:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228371#M43931</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-09-29T13:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228372#M43932</link>
      <description>&lt;P&gt;Can you send output of below command from expert mode of both members please?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;ip r g 8.8.8.8&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 13:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228372#M43932</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T13:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228373#M43933</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96591"&gt;@melcu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the context this is what I see in my lab cluster and fw2 is standby currently.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]#&lt;BR /&gt;[Expert@CP-FW-01:0]# ip r g 8.8.8.8&lt;BR /&gt;8.8.8.8 via 172.16.10.1 dev eth0 src 172.16.10.248&lt;BR /&gt;cache&lt;BR /&gt;[Expert@CP-FW-01:0]# ssh admin@172.16.10.247&lt;BR /&gt;admin@172.16.10.247's password:&lt;BR /&gt;Last login: Fri Sep 27 08:35:02 2024 from 100.65.16.2&lt;BR /&gt;[Expert@CP-FW-02:0]# ip r g 8.8.8.8&lt;BR /&gt;8.8.8.8 via 172.16.10.1 dev eth0 src 172.16.10.247&lt;BR /&gt;cache&lt;BR /&gt;[Expert@CP-FW-02:0]# ^C&lt;BR /&gt;[Expert@CP-FW-02:0]# cphaprob roles&lt;/P&gt;
&lt;P&gt;ID Role&lt;/P&gt;
&lt;P&gt;1 Master&lt;BR /&gt;2 (local) Non-Master&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]# ping 8.8.8.8&lt;BR /&gt;PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.&lt;BR /&gt;64 bytes from 8.8.8.8: icmp_seq=1 ttl=113 time=9.13 ms&lt;BR /&gt;64 bytes from 8.8.8.8: icmp_seq=2 ttl=113 time=6.36 ms&lt;BR /&gt;64 bytes from 8.8.8.8: icmp_seq=3 ttl=113 time=6.00 ms&lt;BR /&gt;^C&lt;BR /&gt;--- 8.8.8.8 ping statistics ---&lt;BR /&gt;3 packets transmitted, 3 received, 0% packet loss, time 2000ms&lt;BR /&gt;rtt min/avg/max/mdev = 6.008/7.169/9.133/1.399 ms&lt;BR /&gt;[Expert@CP-FW-02:0]#&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 13:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228373#M43933</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T13:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228374#M43934</link>
      <description>&lt;P&gt;[Expert@gw01:0]# ip ro get 8.8.8.8&lt;BR /&gt;8.8.8.8 via 10.134.0.1 dev eth1&amp;nbsp; src 10.134.0.11&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cache&amp;nbsp; ipid 0x40ef mtu 1500 advmss 1460 hoplimit 64&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[Expert@gw02:0]# ip ro get 8.8.8.8&lt;BR /&gt;8.8.8.8 via 10.134.0.1 dev eth1&amp;nbsp; src 10.134.0.12&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cache&amp;nbsp; mtu 1500 advmss 1460 hoplimit 64&lt;/P&gt;&lt;P&gt;fw1&amp;nbsp; is MASTER&lt;/P&gt;&lt;P&gt;fw2 is NON-MASTER (as it's the standby unit)&amp;nbsp; If I flip them internet works in FW2 but not on FW1 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 13:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228374#M43934</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-09-29T13:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228376#M43935</link>
      <description>&lt;P&gt;I have a gut feeling I know what could be wrong. So its 100% NOT the specific member if an issue happens regardless which is master.&lt;/P&gt;
&lt;P&gt;Can you check how below is set? No need to send a screenshot, just verify.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27900iFE700046B733E197/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 14:00:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228376#M43935</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T14:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228377#M43936</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96591"&gt;@melcu&lt;/a&gt;&amp;nbsp;I know this may sound silly (trivial), but can you confirm 100% that you do indeed have a proper rule in smart console allowing the traffic?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 14:04:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228377#M43936</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T14:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228378#M43937</link>
      <description>&lt;P&gt;In LAB is wire. Specific rule for VIP and members to access internet&amp;nbsp; and the unsafe&amp;nbsp; from ANY to members and CLU&amp;nbsp; (but public IP is protected by an IPS profile - just in case).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 14:08:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228378#M43937</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-09-29T14:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228379#M43938</link>
      <description>&lt;P&gt;To clear ANY doubts, run ping in one ssh window, then below in another and send what you get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;[Expert@CP-FW-02:0]# fw up_execute dst=8.8.8.8 ipp=0&lt;/STRONG&gt;&lt;BR /&gt;Rulebase execution ended successfully.&lt;BR /&gt;Overall status:&lt;BR /&gt;----------------&lt;BR /&gt;Active clob mask: 2&lt;BR /&gt;Required clob mask: 0&lt;BR /&gt;Match status: POSSIBLE&lt;BR /&gt;Match action: Accept&lt;/P&gt;
&lt;P&gt;Per Layer:&lt;BR /&gt;------------&lt;BR /&gt;Layer name: network&lt;BR /&gt;Layer id: 0&lt;BR /&gt;Match status: POSSIBLE&lt;BR /&gt;Match action: Accept&lt;BR /&gt;Possible rules: 3 4 6 7 8 9 16777215&lt;/P&gt;
&lt;P&gt;Layer name: appc+urlf&lt;BR /&gt;Layer id: 6&lt;BR /&gt;Match status: MATCH&lt;BR /&gt;Match action: Accept&lt;BR /&gt;Matched rule: 5&lt;BR /&gt;Possible rules: 5 16777215&lt;/P&gt;
&lt;P&gt;Layer name: content-awareness-layer&lt;BR /&gt;Layer id: 3&lt;BR /&gt;Match status: MATCH&lt;BR /&gt;Match action: Accept&lt;BR /&gt;Matched rule: 1&lt;BR /&gt;Matched rules: 1&lt;/P&gt;
&lt;P&gt;Layer name: final-allow-layer&lt;BR /&gt;Layer id: 7&lt;BR /&gt;Match status: MATCH&lt;BR /&gt;Match action: Accept&lt;BR /&gt;Matched rule: 1&lt;BR /&gt;Matched rules: 1&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-02:0]#&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 14:16:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228379#M43938</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T14:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228380#M43939</link>
      <description />
      <pubDate>Sun, 29 Sep 2024 14:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228380#M43939</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-09-29T14:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228381#M43940</link>
      <description>&lt;P&gt;K, so if its accepted, rules are fine. Not sure then, maybe some kernel parameter...lets see if anyone else may have an idea. Anyway, I have to go now, get ready for some biking event.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you find the resolution soon.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 14:21:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228381#M43940</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T14:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228382#M43941</link>
      <description>&lt;P&gt;Told ya! It's driving me crazy!&lt;/P&gt;&lt;P&gt;Even looking in the logs it shows that traffic is accepted by fw01, is NATted by the public IP and goes out. Even in the Fortigate I see traffic coming from the NAT IP (when initiated by the standby member) but when it returns it gets dropped or something by fw01.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perimetral firewall (Fortigate- but irrelevant):&lt;/P&gt;&lt;P&gt;FGT-FW01 (vdom-) # diagnose sniffer packet any 'host 8.8.8.8 and host 91.208.215.149'&lt;BR /&gt;interfaces=[any]&lt;BR /&gt;filters=[host 8.8.8.8 and host 91.208.215.149]&lt;BR /&gt;11.250797 91.208.215.149 -&amp;gt; 8.8.8.8: icmp: echo request&lt;BR /&gt;11.250813 91.208.215.149 -&amp;gt; 8.8.8.8: icmp: echo request&lt;BR /&gt;11.250814 91.208.215.149 -&amp;gt; 8.8.8.8: icmp: echo request&lt;BR /&gt;11.280356 8.8.8.8 -&amp;gt; 91.208.215.149: icmp: echo reply&lt;BR /&gt;11.280358 8.8.8.8 -&amp;gt; 91.208.215.149: icmp: echo reply&lt;BR /&gt;11.280368 8.8.8.8 -&amp;gt; 91.208.215.149: icmp: echo reply&lt;BR /&gt;11.280369 8.8.8.8 -&amp;gt; 91.208.215.149: icmp: echo reply&lt;/P&gt;&lt;P&gt;So it sees the traffic originating from standby node and NATTed behind 91.208.215.149&lt;/P&gt;&lt;P&gt;The return traffic reaches the VIP (on the active node)&lt;/P&gt;&lt;P&gt;[Expert@gw01:0]# tcpdump -vvv -ni eth1 host 8.8.8.8&lt;BR /&gt;tcpdump: listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes&lt;BR /&gt;17:27:25.095506 IP (tos 0x0, ttl&amp;nbsp; 59, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.095623 IP (tos 0x0, ttl&amp;nbsp; 58, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.095908 IP (tos 0x0, ttl&amp;nbsp; 57, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.095948 IP (tos 0x0, ttl&amp;nbsp; 56, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.096033 IP (tos 0x0, ttl&amp;nbsp; 55, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.096062 IP (tos 0x0, ttl&amp;nbsp; 54, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.096142 IP (tos 0x0, ttl&amp;nbsp; 53, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.096177 IP (tos 0x0, ttl&amp;nbsp; 52, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;BR /&gt;17:27:25.096261 IP (tos 0x0, ttl&amp;nbsp; 51, id 0, offset 0, flags [none], proto: ICMP (1), length: 84) 8.8.8.8 &amp;gt; 91.208.215.149: ICMP echo reply, id 10267, seq 8, length 64&lt;/P&gt;&lt;P&gt;But on the standby member .. mumu &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; sees only the outgoing packets but nothing back.&lt;/P&gt;&lt;P&gt;[Expert@gw02:0]# tcpdump -vni any host 8.8.8.8&lt;BR /&gt;tcpdump: listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes&lt;BR /&gt;17:30:39.739541 IP (tos 0x0, ttl&amp;nbsp; 64, id 0, offset 0, flags [DF], proto: ICMP (1), length: 84) 91.208.215.149 &amp;gt; 8.8.8.8: ICMP echo request, id 10325, seq 176, length 64&lt;BR /&gt;17:30:40.739875 IP (tos 0x0, ttl&amp;nbsp; 64, id 0, offset 0, flags [DF], proto: ICMP (1), length: 84) 91.208.215.149 &amp;gt; 8.8.8.8: ICMP echo request, id 10325, seq 177, length 64&lt;BR /&gt;17:30:41.740411 IP (tos 0x0, ttl&amp;nbsp; 64, id 0, offset 0, flags [DF], proto: ICMP (1), length: 84) 91.208.215.149 &amp;gt; 8.8.8.8: ICMP echo request, id 10325, seq 178, length 64&lt;BR /&gt;17:30:42.739779 IP (tos 0x0, ttl&amp;nbsp; 64, id 0, offset 0, flags [DF], proto: ICMP (1), length: 84) 91.208.215.149 &amp;gt; 8.8.8.8: ICMP echo request, id 10325, seq 179, length 64&lt;/P&gt;&lt;P&gt;First I thought that the packet will return to a different interface and that's why I've used "-i any".&amp;nbsp; It doesn't come back from FW01.&lt;/P&gt;&lt;P&gt;Pretty sure this is Kernel issue.&amp;nbsp; Btw, even turning fwaccell off&amp;nbsp; doesn't solve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 14:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228382#M43941</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-09-29T14:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228386#M43942</link>
      <description>&lt;P&gt;Just came back from my race...I thought about this while running and now that I checked your topology, I am certain your issue is the fact you have external if configured as sync. Can you create SEPARATE sync interface and test?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 16:56:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228386#M43942</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T16:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228387#M43943</link>
      <description>&lt;P&gt;Hmm SYNC was not on this interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before:&lt;BR /&gt;eth0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sync(secured), unicast&lt;BR /&gt;eth1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; non sync(non secured), unicast&lt;BR /&gt;&lt;BR /&gt;Virtual cluster interfaces: 2&lt;BR /&gt;eth0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.144.70.20&lt;BR /&gt;eth1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.134.0.10&lt;/P&gt;&lt;P&gt;After:&lt;BR /&gt;eth0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; non sync(non secured), unicast&lt;BR /&gt;eth1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sync(secured), unicast&lt;BR /&gt;&lt;BR /&gt;Virtual cluster interfaces: 2&lt;BR /&gt;&lt;BR /&gt;eth0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.144.70.20&lt;BR /&gt;eth1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.134.0.10&lt;/P&gt;&lt;P&gt;Behavior is the same..&lt;/P&gt;&lt;P&gt;Just tested. ClusterXL_admin down on FW1&amp;nbsp; and FW2 instantly reaches internet.&lt;/P&gt;&lt;P&gt;SO definitely something in the Kern.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 17:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228387#M43943</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-09-29T17:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228392#M43944</link>
      <description>&lt;P&gt;But then how come your topology shows it is?? Can you send topology screenshot again? And also commands below from BOTH members?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;If you got time, lets do remote, since it a lab&lt;/P&gt;
&lt;P&gt;Let me know&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob -a if&lt;/P&gt;
&lt;P&gt;CCP mode: Manual (Unicast)&lt;BR /&gt;Required interfaces: 4&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interface Name: Status:&lt;/P&gt;
&lt;P&gt;eth0 (LM) UP&lt;BR /&gt;eth1 (LM) UP&lt;BR /&gt;eth2 (LM) UP&lt;BR /&gt;eth3 (S) UP&lt;/P&gt;
&lt;P&gt;S - sync, HA/LS - bond type, LM - link monitor, P - probing&lt;/P&gt;
&lt;P&gt;Virtual cluster interfaces: 3&lt;/P&gt;
&lt;P&gt;eth0 172.16.10.246&lt;BR /&gt;eth1 192.168.10.246&lt;BR /&gt;eth2 172.31.10.246&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob -i list&lt;/P&gt;
&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# cphaprob syncstat&lt;/P&gt;
&lt;P&gt;Delta Sync Statistics&lt;/P&gt;
&lt;P&gt;Sync status: OK&lt;/P&gt;
&lt;P&gt;Drops:&lt;BR /&gt;Lost updates................................. 0&lt;BR /&gt;Lost bulk update events...................... 0&lt;BR /&gt;Oversized updates not sent................... 0&lt;/P&gt;
&lt;P&gt;Sync at risk:&lt;BR /&gt;Sent reject notifications.................... 0&lt;BR /&gt;Received reject notifications................ 0&lt;/P&gt;
&lt;P&gt;Sent messages:&lt;BR /&gt;Total generated sync messages................ 1458146&lt;BR /&gt;Sent retransmission requests................. 0&lt;BR /&gt;Sent retransmission updates.................. 0&lt;BR /&gt;Peak fragments per update.................... 1&lt;/P&gt;
&lt;P&gt;Received messages:&lt;BR /&gt;Total received updates....................... 3962798&lt;BR /&gt;Received retransmission requests............. 0&lt;/P&gt;
&lt;P&gt;Sync Interface:&lt;BR /&gt;Name......................................... eth3&lt;BR /&gt;Link speed................................... 1000Mb/s&lt;BR /&gt;Rate......................................... 25340 [Bps]&lt;BR /&gt;Peak rate.................................... 802520[Bps]&lt;BR /&gt;Link usage................................... 0%&lt;BR /&gt;Total........................................ 27707 [MB]&lt;/P&gt;
&lt;P&gt;Queue sizes (num of updates):&lt;BR /&gt;Sending queue size........................... 512&lt;BR /&gt;Receiving queue size......................... 256&lt;BR /&gt;Fragments queue size......................... 50&lt;/P&gt;
&lt;P&gt;Timers:&lt;BR /&gt;Delta Sync interval (ms)..................... 100&lt;/P&gt;
&lt;P&gt;Reset on Sun Sep 22 12:15:49 2024 (triggered by fullsync).&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]#&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 18:47:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228392#M43944</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T18:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228400#M43945</link>
      <description>&lt;P&gt;Forgot to mention, IF topology shows something different, go to smart console cluster object, network and then edit topology, click "get interfaces WITHOUT topology", make sure it saves without errors, publish, install policy, test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 21:06:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228400#M43945</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-29T21:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Standby member no internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228475#M43946</link>
      <description>&lt;P&gt;So an upstream router is basically providing the NAT here only for the public VIP?&lt;BR /&gt;I'm with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;, we probably need to see fw ctl zdebug + drop output from the active member while trying to initiate communication from the secondary.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 13:59:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Standby-member-no-internet/m-p/228475#M43946</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-30T13:59:27Z</dc:date>
    </item>
  </channel>
</rss>

