<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the expected traffic in a packet capture for Checkpoint High Avalibility? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58373#M4412</link>
    <description>Just to correct myself, R80.20 and above, the default sync traffic is unicast, not multicast.&lt;BR /&gt;CCP packets should appear on all "clustered" interfaces.</description>
    <pubDate>Tue, 16 Jul 2019 23:44:55 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-07-16T23:44:55Z</dc:date>
    <item>
      <title>What is the expected traffic in a packet capture for Checkpoint High Avalibility?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/57964#M4346</link>
      <description>&lt;P&gt;While working on a issue I noticed this on a wireshark packet capture on my Nexus 9000 switch is connected to a 15400 XL running Gaia 80.33 (whatever the current version is). There are two 15400 XL in one DC1 and 2 in DC2. The 4 are all clustered together for the VSS. The 192.168.xxx.xx is checkpoint's "internal switch" address. My question is should I be seeing these messages sent to the switchport that is connected to the firewall? The port that is connected to the firewall from the Nexus is for multicast traffic. I did a packet capture in our QA environment which is a mirror of our production with the exception of there are only 2 15400 XL and I don't see these messages below. Is this a mis- configuration of the Firewall High Availability being sent to the Nexus connecting port?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2019-07-10 15:34:26.154998 0.0.0.0 -&amp;gt; 192.168.xxx.xx CPHA CPHAv3223: FWHA_MY_STATE&lt;BR /&gt;2019-07-10 15:34:26.155007 0.0.0.0 -&amp;gt; 0.0.0.0 CPHA CPHAv3223: FWHA_IFCONF_REQ&lt;BR /&gt;2019-07-10 15:34:26.155010 0.0.0.0 -&amp;gt; 0.0.0.0 CPHA CPHAv3223: FWHA_IFCONF_REQ&lt;BR /&gt;2019-07-10 15:34:26.155013 0.0.0.0 -&amp;gt; 0.0.0.0 CPHA CPHAv3223: FWHA_IFCONF_REQ&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 20:38:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/57964#M4346</guid>
      <dc:creator>Jamesbondjr007x</dc:creator>
      <dc:date>2019-07-10T20:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: What is the expected traffic in a packet capture for Checkpoint High Avalibility?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58211#M4377</link>
      <description>Check Point's sync traffic is multicast by default.&lt;BR /&gt;While the actual connection sync data goes over the sync network, probes do go out over each connected interface.&lt;BR /&gt;This is to verify cluster members can reach each other on every interface.&lt;BR /&gt;I haven't seen what this traffic looks like in R80.30 to verify what you're seeing is correct.</description>
      <pubDate>Mon, 15 Jul 2019 05:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58211#M4377</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-15T05:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: What is the expected traffic in a packet capture for Checkpoint High Avalibility?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58373#M4412</link>
      <description>Just to correct myself, R80.20 and above, the default sync traffic is unicast, not multicast.&lt;BR /&gt;CCP packets should appear on all "clustered" interfaces.</description>
      <pubDate>Tue, 16 Jul 2019 23:44:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58373#M4412</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-16T23:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: What is the expected traffic in a packet capture for Checkpoint High Avalibility?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58378#M4414</link>
      <description>The default is indeed Unicast for this traffic, unless the gateways were upgraded, then the previous state is just copied and left alone.</description>
      <pubDate>Wed, 17 Jul 2019 05:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58378#M4414</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-07-17T05:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is the expected traffic in a packet capture for Checkpoint High Avalibility?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58422#M4418</link>
      <description>&lt;P&gt;I want to thank you for the responses. My question was is &lt;STRONG&gt;not if its unicast or multicast&lt;/STRONG&gt;. It was if what I pasted in the original posting is what should be occuring on connected interfaces to the firewall. As I stated I do not see that in our QA environment with the same code and chassis.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 19:15:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58422#M4418</guid>
      <dc:creator>Jamesbondjr007x</dc:creator>
      <dc:date>2019-07-17T19:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is the expected traffic in a packet capture for Checkpoint High Avalibility?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58448#M4420</link>
      <description>CCP packets should be appearing on all "Clustered" interfaces, as I said previously.&lt;BR /&gt;If you're not seeing them, it's because the configuration of the Cluster object is different with respect to the interfaces in your QA environment.</description>
      <pubDate>Thu, 18 Jul 2019 08:08:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-expected-traffic-in-a-packet-capture-for-Checkpoint/m-p/58448#M4420</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-18T08:08:34Z</dc:date>
    </item>
  </channel>
</rss>

