<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: icmp timeouts with PRB in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233627#M45218</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I appreciate your comments.&lt;/P&gt;&lt;P&gt;I captured packets at three points (Windows vNIC, CP's eth1, FortiGate's internal), only to find ICMP request from 10.31.10.1 (WindowsVM).&lt;/P&gt;&lt;P&gt;Your comment makes me notice I did not capture it at FortiGate's external.&lt;/P&gt;&lt;P&gt;I am going to do it and post the results.&lt;/P&gt;&lt;P&gt;The log of CP tells me that it allows ICMP request, but ICMP reply is nowhere to be found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2024 06:01:50 GMT</pubDate>
    <dc:creator>saitoh</dc:creator>
    <dc:date>2024-11-25T06:01:50Z</dc:date>
    <item>
      <title>icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233376#M45155</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hesitate to ask this because I think this is quite elementary, but I need a bit of explanation.&lt;/P&gt;&lt;P&gt;I am testing how policy based routing works in CP, wanting to make CP route packets to eth0 or eth2, according to what a certain packet is.&lt;/P&gt;&lt;P&gt;The environment as follows.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28517iEDE65345EA973FAE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;FortiGate has allow-all policy, no UTM activated.&lt;/P&gt;&lt;P&gt;GW1, 2 play role of cluster of ClusterXL.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28518iB249547C0E96E66F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here eth1 is in trusted zone, eth0, eth2 untrusted.&lt;/P&gt;&lt;P&gt;Default route is set on eth0, and only HTTPS to FGT's external IP (10.11.124.1) goes to eth2 by policy based routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The test above was successful.&lt;/P&gt;&lt;P&gt;I made changes to routing policy for only ICMP to go through eth2, which failed due to timeouts.&lt;/P&gt;&lt;P&gt;I am not experienced enough to understand what is happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe this is quite basic networking topic, not the one of CP...&lt;/P&gt;&lt;P&gt;I feel sorry to ask this stupid question, but your comments would be highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 10:01:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233376#M45155</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-11-21T10:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233387#M45157</link>
      <description>&lt;P&gt;What is the source &amp;amp; destination IP addresses of your test traffic?&lt;/P&gt;
&lt;P&gt;(Note a limitation is that traffic originated from the gateway itself is not subject to PBR per sk167135).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 08:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233387#M45157</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-11-25T08:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233461#M45177</link>
      <description>&lt;P&gt;Do you have something configured like&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;static-route {...} ping {off | on}?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;gateway can use ping to monitor gateways. Maybe this options influences your test with ping?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/Policy-Based-Routing-Configuring-in-Gaia-Clish.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/Policy-Based-Routing-Configuring-in-Gaia-Clish.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 19:29:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233461#M45177</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-21T19:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233462#M45178</link>
      <description>&lt;P&gt;No issues man, we are here to help. What do you see if you do basic capture? Do the logs show anything?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 19:37:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233462#M45178</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-21T19:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233625#M45216</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for your comment.&lt;/P&gt;&lt;P&gt;I tested ICMP routing from WindowsVM (10.31.10.1) to FortiGate external (10.11.124.1).&lt;/P&gt;&lt;P&gt;I configured PBR policy for CP to pick up ICMP traffic only from WindowsVM to FGT external and send it through eth2.&lt;/P&gt;&lt;P&gt;It goes through without any mishaps when I delete the policy of PBR, so I assume PBR matters in this occasion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 05:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233625#M45216</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-11-25T05:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233627#M45218</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I appreciate your comments.&lt;/P&gt;&lt;P&gt;I captured packets at three points (Windows vNIC, CP's eth1, FortiGate's internal), only to find ICMP request from 10.31.10.1 (WindowsVM).&lt;/P&gt;&lt;P&gt;Your comment makes me notice I did not capture it at FortiGate's external.&lt;/P&gt;&lt;P&gt;I am going to do it and post the results.&lt;/P&gt;&lt;P&gt;The log of CP tells me that it allows ICMP request, but ICMP reply is nowhere to be found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 06:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233627#M45218</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-11-25T06:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233628#M45219</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;&lt;P&gt;I checked out monitored IPs settings in PBR, but no IP is set to be monitored.&lt;/P&gt;&lt;P&gt;When I deleted PBR settings ping goes successful, so some point in PBR setting matters, as you mentioned, I guess.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 06:17:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233628#M45219</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-11-25T06:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233633#M45220</link>
      <description>&lt;P&gt;I took packet at 10.11.124.1, and found FGT actually replies nothing, while it passes that packet from receiving port to destination port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, its debug log associated with routing shows FGT drops reply packet during route decision process.&lt;/P&gt;&lt;P&gt;Its policy is Src;Any, Dst:Any, Service:Any, Always at the top, so there is no mistake in policy hit.&lt;/P&gt;&lt;P&gt;I start to guess I misconfigured FGT's static routing, which was below.&lt;/P&gt;&lt;P&gt;To 10.31.10.0/25,&lt;/P&gt;&lt;P&gt;Gateway port2 (leading to CP's eth0) Distance 10&lt;/P&gt;&lt;P&gt;Gateway port3 (leading to CP's eth2) Distance 11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port3 route is meant to be passive route even though I believe the route does not appear in routing table.&lt;/P&gt;&lt;P&gt;I guess this is not causing trouble because I thought in route decision session existence came in first.&lt;/P&gt;&lt;P&gt;I tried changing it as they have same AD, and things started going right!&lt;/P&gt;&lt;P&gt;Looks like kernel routing table should have active route through port3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am relieved to know I misunderstood FGT, not CP!&lt;/P&gt;&lt;P&gt;Many thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 08:16:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233633#M45220</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-11-25T08:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233634#M45221</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;, and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I solved the issue, which is about misconfig on FortiGate, nothing wrong with CP.&lt;/P&gt;&lt;P&gt;Thanks for your time, and input!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 08:17:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233634#M45221</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-11-25T08:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: icmp timeouts with PRB</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233658#M45223</link>
      <description>&lt;P&gt;Great job!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 12:14:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/icmp-timeouts-with-PRB/m-p/233658#M45223</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-25T12:14:17Z</dc:date>
    </item>
  </channel>
</rss>

