<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with DNS lookup from HA standby member in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-DNS-lookup-from-HA-standby-member/m-p/58947#M4457</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have an issue on our FW-cluster standby member, causing AV/TE-Updates to fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet connection is OK, but I assume that there is an issue with DNS. If I try to resolve e.g. checkpoint.com from our standby member, it times out and is not resolvable. The error messages vary:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;[Expert@chp-2:0]# nslookup checkpoint.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;;; connection timed out; trying next origin&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;;; connection timed out; no servers could be reached&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;[Expert@chp-2:0]# nslookup facebook.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;;; connection timed out; trying next origin&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Server: 10.1.1.14&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Address: 10.1.1.14#53&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;** server can't find facebook.com: NXDOMAIN&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do the same with the active member, it works:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;[Expert@chp-1:0]# nslookup checkpoint.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Server: 10.1.1.14&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Address: 10.1.1.14#53&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Non-authoritative answer:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Name: checkpoint.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Address: 209.87.209.100&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Afterwards, in most cases (80%), the resolution works then from the standby member too for the same host.&lt;/P&gt;&lt;P&gt;But not always - it's a very strange behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do a failover, the standby (now main) FW works properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DNS server are up and running, no issues at all (except this one from the HA standby member).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I can see on another FW (ASA), located between CP and DNS servers, all requests are coming with the cluster IP.&lt;/P&gt;&lt;P&gt;I did a fw monitor and at the same time a capture on the ASA. All packets have corresponding packet captures on ASA, and there I can also see, that the servers answer to every request. But in the FW monitor, I don't see most of the answer-packets. Here's an example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1975i2182F1CCDB190664/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On the left side you can see the FW monitor output. Packets leave with the cluster VIP 10.2.1.1 on different ports.&lt;/P&gt;&lt;P&gt;On the right side you can see the ASA-capture where all these packets appear, and where you can also see the answers from the DNS server 10.1.1.14/15. (marked blue/azure)&lt;/P&gt;&lt;P&gt;But on the left side, these answers dont appear for the first 6 requests. Only the last, yellow one has a properly appearing answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only strange thing that bothers me, is that the packet length of the failing answers seems to be much lower than the last one (26 compared to 96).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas, what could be causing this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2019 09:57:28 GMT</pubDate>
    <dc:creator>xiro</dc:creator>
    <dc:date>2019-07-25T09:57:28Z</dc:date>
    <item>
      <title>Issue with DNS lookup from HA standby member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-DNS-lookup-from-HA-standby-member/m-p/58947#M4457</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have an issue on our FW-cluster standby member, causing AV/TE-Updates to fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet connection is OK, but I assume that there is an issue with DNS. If I try to resolve e.g. checkpoint.com from our standby member, it times out and is not resolvable. The error messages vary:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;[Expert@chp-2:0]# nslookup checkpoint.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;;; connection timed out; trying next origin&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;;; connection timed out; no servers could be reached&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;[Expert@chp-2:0]# nslookup facebook.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;;; connection timed out; trying next origin&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Server: 10.1.1.14&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Address: 10.1.1.14#53&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;** server can't find facebook.com: NXDOMAIN&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do the same with the active member, it works:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;[Expert@chp-1:0]# nslookup checkpoint.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Server: 10.1.1.14&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Address: 10.1.1.14#53&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Non-authoritative answer:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Name: checkpoint.com&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;Address: 209.87.209.100&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Afterwards, in most cases (80%), the resolution works then from the standby member too for the same host.&lt;/P&gt;&lt;P&gt;But not always - it's a very strange behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do a failover, the standby (now main) FW works properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DNS server are up and running, no issues at all (except this one from the HA standby member).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I can see on another FW (ASA), located between CP and DNS servers, all requests are coming with the cluster IP.&lt;/P&gt;&lt;P&gt;I did a fw monitor and at the same time a capture on the ASA. All packets have corresponding packet captures on ASA, and there I can also see, that the servers answer to every request. But in the FW monitor, I don't see most of the answer-packets. Here's an example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1975i2182F1CCDB190664/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On the left side you can see the FW monitor output. Packets leave with the cluster VIP 10.2.1.1 on different ports.&lt;/P&gt;&lt;P&gt;On the right side you can see the ASA-capture where all these packets appear, and where you can also see the answers from the DNS server 10.1.1.14/15. (marked blue/azure)&lt;/P&gt;&lt;P&gt;But on the left side, these answers dont appear for the first 6 requests. Only the last, yellow one has a properly appearing answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only strange thing that bothers me, is that the packet length of the failing answers seems to be much lower than the last one (26 compared to 96).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas, what could be causing this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 09:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-DNS-lookup-from-HA-standby-member/m-p/58947#M4457</guid>
      <dc:creator>xiro</dc:creator>
      <dc:date>2019-07-25T09:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with DNS lookup from HA standby member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-DNS-lookup-from-HA-standby-member/m-p/58969#M4459</link>
      <description>&lt;P&gt;Have a look at this SK:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43807&amp;amp;partition=Advanced&amp;amp;product=ClusterXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43807&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had a similar issue.&amp;nbsp; Though it wasn't with DNS.&amp;nbsp; It was with HTTP.&amp;nbsp; The inactive cluster member was sending traffic out via the cluster IP.&amp;nbsp; but when it came back, the cluster incorrectly sent that return packet to the active host member.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 14:23:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-DNS-lookup-from-HA-standby-member/m-p/58969#M4459</guid>
      <dc:creator>Tommy_Forrest</dc:creator>
      <dc:date>2019-07-25T14:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with DNS lookup from HA standby member</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-DNS-lookup-from-HA-standby-member/m-p/61852#M4735</link>
      <description>&lt;P&gt;Was this problem solved ?&lt;/P&gt;&lt;P&gt;We are facing the same problems after our VSX upgrade to R80.20 (Take 91)&lt;/P&gt;&lt;P&gt;Even a ping from the standby node doesn't work to non SmartCenter/Logserver IPs&lt;/P&gt;&lt;P&gt;setting the&amp;nbsp;fwha_forw_packet_to_not_active parameter doesn't seems to solving the problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 12:43:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-DNS-lookup-from-HA-standby-member/m-p/61852#M4735</guid>
      <dc:creator>JanVandenberghe</dc:creator>
      <dc:date>2019-09-04T12:43:20Z</dc:date>
    </item>
  </channel>
</rss>

