<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ESP packets use ISP router MAC instead of ISP HSRP MAC in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ESP-packets-use-ISP-router-MAC-instead-of-ISP-HSRP-MAC/m-p/244909#M47673</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I have several sites with an R81.10 cluster (active/standby), two switches and two ISP routers.&lt;/P&gt;&lt;P&gt;These routers are configured with HSRP.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ISP connection.JPG" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30036iE3ED508FF3CF97F8/image-size/small?v=v2&amp;amp;px=200" role="button" title="ISP connection.JPG" alt="ISP connection.JPG" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the ISP router sends packets, the source MAC is always the router MAC.&lt;/P&gt;&lt;P&gt;When the firewall is sending traffic to the internet, the HSRP MAC of the ISP router is used as a destination.&lt;/P&gt;&lt;P&gt;Exception: when the firewall is sending ESP packets with protocol "UDP (17)" (looks like the actual VPN data packets for Site2Site and Client2Site connections), then the MAC of the actual router is used as a&amp;nbsp;destination.&lt;/P&gt;&lt;P&gt;Is this an expected behaviour or can it be influenced?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue with this is: In case of a router failure, the traffic will be send to a dead MAC.&lt;/P&gt;&lt;P&gt;And as we also have a site with ISP load-sharing, the traffic might be sent directly to the secondary router. If then the switch in the path is restarted, the VPN tunnels also suffer.&lt;/P&gt;&lt;P&gt;Thanks in advance for some insights!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Through the support portal I now found this&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/vpn-r80-20-vsx/m-p/15269#M2805" target="_blank"&gt;vpn r80.20 vsx - Check Point CheckMates&lt;/A&gt;, looks quite similar. Will look at it tomorrow, it didn´t come up in the Community website search.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2025 20:20:52 GMT</pubDate>
    <dc:creator>Robin_H</dc:creator>
    <dc:date>2025-03-26T20:20:52Z</dc:date>
    <item>
      <title>ESP packets use ISP router MAC instead of ISP HSRP MAC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ESP-packets-use-ISP-router-MAC-instead-of-ISP-HSRP-MAC/m-p/244909#M47673</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I have several sites with an R81.10 cluster (active/standby), two switches and two ISP routers.&lt;/P&gt;&lt;P&gt;These routers are configured with HSRP.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ISP connection.JPG" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30036iE3ED508FF3CF97F8/image-size/small?v=v2&amp;amp;px=200" role="button" title="ISP connection.JPG" alt="ISP connection.JPG" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the ISP router sends packets, the source MAC is always the router MAC.&lt;/P&gt;&lt;P&gt;When the firewall is sending traffic to the internet, the HSRP MAC of the ISP router is used as a destination.&lt;/P&gt;&lt;P&gt;Exception: when the firewall is sending ESP packets with protocol "UDP (17)" (looks like the actual VPN data packets for Site2Site and Client2Site connections), then the MAC of the actual router is used as a&amp;nbsp;destination.&lt;/P&gt;&lt;P&gt;Is this an expected behaviour or can it be influenced?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue with this is: In case of a router failure, the traffic will be send to a dead MAC.&lt;/P&gt;&lt;P&gt;And as we also have a site with ISP load-sharing, the traffic might be sent directly to the secondary router. If then the switch in the path is restarted, the VPN tunnels also suffer.&lt;/P&gt;&lt;P&gt;Thanks in advance for some insights!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Through the support portal I now found this&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/vpn-r80-20-vsx/m-p/15269#M2805" target="_blank"&gt;vpn r80.20 vsx - Check Point CheckMates&lt;/A&gt;, looks quite similar. Will look at it tomorrow, it didn´t come up in the Community website search.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 20:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ESP-packets-use-ISP-router-MAC-instead-of-ISP-HSRP-MAC/m-p/244909#M47673</guid>
      <dc:creator>Robin_H</dc:creator>
      <dc:date>2025-03-26T20:20:52Z</dc:date>
    </item>
  </channel>
</rss>

