<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot ping next hop from vsx gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239640#M46499</link>
    <description>&lt;P&gt;Have you installed policy for the VS since adding the interface?&lt;/P&gt;
&lt;P&gt;Is there any NAT configured on this VS that might be a conflict?&lt;/P&gt;
&lt;P&gt;Is eth5 properly set (ticked) as a trunk?&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jan 2025 15:43:38 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-01-26T15:43:38Z</dc:date>
    <item>
      <title>Cannot ping next hop from vsx gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239636#M46497</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am setting up VSX in our enviorment.&lt;/P&gt;&lt;P&gt;We have prod vsx that has below configuration:&lt;/P&gt;&lt;P&gt;eth5.30: 10.1.30.1/24&lt;/P&gt;&lt;P&gt;eth5 is connected to l2 switch and there is router in 10.1.30.0/24 segment.&lt;/P&gt;&lt;P&gt;10.1.30.2/24 is configured as sub-int in router.&lt;/P&gt;&lt;P&gt;When I ping 10.1.30.2 from prod vsx. I don't get any response.&lt;/P&gt;&lt;P&gt;I run tcpdump and get below output:&lt;/P&gt;&lt;P&gt;request who-has 192.168.30.2 tell 192.168.30.1 length 28&lt;/P&gt;&lt;P&gt;In logs I see vsx is changing source&amp;nbsp; from 192.168.30.1 to internal ip address -192.168.196.17&lt;/P&gt;&lt;P&gt;May I know why?&lt;/P&gt;&lt;P&gt;How can I make next hop rechable?&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 13:29:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239636#M46497</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-01-26T13:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping next hop from vsx gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239640#M46499</link>
      <description>&lt;P&gt;Have you installed policy for the VS since adding the interface?&lt;/P&gt;
&lt;P&gt;Is there any NAT configured on this VS that might be a conflict?&lt;/P&gt;
&lt;P&gt;Is eth5 properly set (ticked) as a trunk?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 15:43:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239640#M46499</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-26T15:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping next hop from vsx gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239645#M46502</link>
      <description>&lt;P&gt;Have you installed policy for the VS since adding the interface? Yes&lt;/P&gt;&lt;P&gt;Is there any NAT configured on this VS that might be a conflict? No NAT&lt;/P&gt;&lt;P&gt;Is eth5 properly set (ticked) as a trunk? - Yes&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 17:01:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239645#M46502</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-01-26T17:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping next hop from vsx gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239646#M46503</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;below output looks okay?&lt;/P&gt;&lt;P&gt;[Expert@VSX-GW-1:0]# ifconfig&lt;BR /&gt;eth0 Link encap:Ethernet HWaddr 50:00:00:02:00:00&lt;BR /&gt;inet addr:10.199.199.15 Bcast:10.199.199.255 Mask:255.255.255.0&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:70412 errors:7025 dropped:0 overruns:0 frame:7025&lt;BR /&gt;TX packets:64859 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:52914863 (50.4 MiB) TX bytes:25974772 (24.7 MiB)&lt;/P&gt;&lt;P&gt;eth1 Link encap:Ethernet HWaddr 50:00:00:02:00:01&lt;BR /&gt;inet addr:11.1.1.1 Bcast:11.1.1.255 Mask:255.255.255.0&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:191589 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:246849 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:32897764 (31.3 MiB) TX bytes:38205534 (36.4 MiB)&lt;/P&gt;&lt;P&gt;eth4 Link encap:Ethernet HWaddr 50:00:00:02:00:04&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:248242 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:0 (0.0 b) TX bytes:16560624 (15.7 MiB)&lt;/P&gt;&lt;P&gt;eth5 Link encap:Ethernet HWaddr 50:00:00:02:00:05&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:40871 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:114939 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:3411203 (3.2 MiB) TX bytes:7962524 (7.5 MiB)&lt;/P&gt;&lt;P&gt;lo Link encap:Local Loopback Media:unknown(auto)&lt;BR /&gt;inet addr:127.0.0.1 Mask:255.0.0.0&lt;BR /&gt;UP LOOPBACK RUNNING ALLMULTI MULTICAST MTU:65536 Metric:1&lt;BR /&gt;RX packets:30530 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:30530 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:6288400 (5.9 MiB) TX bytes:6288400 (5.9 MiB)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is from vsx 0. Shoud this show eth5?&amp;nbsp;&lt;/P&gt;&lt;P&gt;eth5 interface should be on my prod vsx.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 18:52:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239646#M46503</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-01-26T18:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping next hop from vsx gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239647#M46504</link>
      <description>&lt;P&gt;Did you configure VLAN 30 within eth5 on VS0 or some other VS ? You need to access VS where this VLAN is configured using expert command "vsenv &amp;lt;VSID&amp;gt;" or using clish command "set virtual-system&amp;nbsp;&amp;lt;VSID&amp;gt;". Once you are inside the correct VS, you should be able to reach&amp;nbsp;&lt;SPAN&gt;10.1.30.2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PS: If you dont get ping response from&amp;nbsp;10.1.30.2, it can indicate the router is not allowed to answer for pings. Check if MAC of&amp;nbsp;10.1.30.2 is known using expert command from proper VS: 'arp - an | grep&amp;nbsp;"10.1.30.2"'&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 18:57:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239647#M46504</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2025-01-26T18:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping next hop from vsx gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239648#M46505</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;: I configured vlan 30 in prod VSX. I checked arp and I am getting incomplete arp. Eth5 is configured with l2 sw and has below configurartion.&lt;/P&gt;&lt;P&gt;hostname SW3&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;logging buffered 100000&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;ipv6 multicast rpf use-bgp&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;switchport mode access&lt;BR /&gt;duplex auto&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;switchport mode access&lt;BR /&gt;duplex auto&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;switchport mode access&lt;BR /&gt;duplex auto&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;duplex auto&lt;BR /&gt;!&lt;BR /&gt;interface Vlan30&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip http server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;logging synchronous&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vlan 30 is set as access port on all 3 ports. two from VSX gateway and 1 from router.&lt;/P&gt;&lt;P&gt;I can see mac-address table is also learnt:&lt;/P&gt;&lt;P&gt;SW3#show mac address-table&lt;BR /&gt;Mac Address Table&lt;BR /&gt;-------------------------------------------&lt;/P&gt;&lt;P&gt;Vlan Mac Address Type Ports&lt;BR /&gt;---- ----------- -------- -----&lt;BR /&gt;30 5000.0002.0005 DYNAMIC Et0/0&lt;BR /&gt;30 5000.0005.0005 DYNAMIC Et0/1&lt;BR /&gt;30 aabb.cc00.7000 DYNAMIC Et0/2&lt;BR /&gt;Total Mac Addresses for this criterion: 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eth5.30 mac-address is -&amp;nbsp;50:00:00:02:00:05&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know why arp is coming incomplete.&lt;/P&gt;&lt;P&gt;I debug arp on switch side and get below log:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IP ARP req filtered src 10.1.30.1 5000.0002.0005, dst 10.1.30.2 0000.0000.0000 wrong cable, interface Vlan30&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 19:38:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239648#M46505</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-01-26T19:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping next hop from vsx gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239649#M46506</link>
      <description>&lt;P&gt;Switchport is not configured as a trunk per above output?&lt;/P&gt;
&lt;P&gt;Also per above ensure the ping is originated from the correct VS context.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 01:44:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-ping-next-hop-from-vsx-gateway/m-p/239649#M46506</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-27T01:44:51Z</dc:date>
    </item>
  </channel>
</rss>

