<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem accessing standby cluster member from non-local network in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26807#M4909</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kaspars,&lt;/P&gt;&lt;P&gt;The situation is as you described, i.e. accessing from the "other" side.&lt;/P&gt;&lt;P&gt;However, ssh and https traffic to the management interface of the standby member logged as "accepted".&lt;/P&gt;&lt;P&gt;That being said, I'll try adding the route and see if it does the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Jan 2018 17:42:55 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2018-01-31T17:42:55Z</dc:date>
    <item>
      <title>Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26803#M4905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Log shows accepted traffic on SSH and 443, cluster members connected to number of Cisco switches with VLANs in L2 mode.&lt;/P&gt;&lt;P&gt;No problem accessing both members from connected network.&lt;/P&gt;&lt;P&gt;vMAC in the cluster object IS ENABLED.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 16:40:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26803#M4905</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-31T16:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26804#M4906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;How about &lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;&lt;STRONG&gt;&lt;CODE&gt;fwha_forw_packet_to_not_active&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;? Helps with similar situations with ping also.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13px;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695"&gt;Cluster debug shows "FW-1: fwha_forw_ssl_handler: Rejecting ssl packets to a non-active member"&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Try with just entering&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 13px;"&gt;# fw ctl set int fwha_forw_packet_to_not_active 1&lt;/SPAN&gt;&lt;SPAN style="color: #3d3d3d; font-weight: 400;"&gt;, &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #3d3d3d; font-weight: 400;"&gt;and if works, enable on permanent basis in&amp;nbsp;&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 13px;"&gt;&lt;STRONG&gt;fwkern.conf&lt;/STRONG&gt;&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-weight: 400; font-size: 15px;"&gt;I hope there is still &lt;SPAN style="font-size: 13px;"&gt;&lt;STRONG&gt;fwkern.conf&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;on R80.10&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 16:57:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26804#M4906</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-01-31T16:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26805#M4907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You probably trying to connect to IP that's on the "other" side of the firewall and not locally connected IP. If you have only one route to the firewall VIP then traffic will get dropped as spoofed between firewalls. You can create manual static route for IP on the other side to point to standby memebr's locally connected IP interface address&lt;/P&gt;&lt;P&gt;Hope it makes sense &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;In other words if you have inside&amp;nbsp; member-act 1.1.1.1 and member-stb 1.1.1.2 with VIP 1.1.1.3. And outside has IPs 2.2.2.1 and .2 and .3 then to connect to 2.2.2.2 via inside interface you will need to add static /32 on the router: 2.2.2.2 next-hop 1.1.1.2&lt;/P&gt;&lt;P&gt;Or I misunderstood maybe the problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:19:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26805#M4907</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-31T17:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26806#M4908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll give it a shot shortly and let you know if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:31:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26806#M4908</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-31T17:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26807#M4909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kaspars,&lt;/P&gt;&lt;P&gt;The situation is as you described, i.e. accessing from the "other" side.&lt;/P&gt;&lt;P&gt;However, ssh and https traffic to the management interface of the standby member logged as "accepted".&lt;/P&gt;&lt;P&gt;That being said, I'll try adding the route and see if it does the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:42:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26807#M4909</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-31T17:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26808#M4910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what happens if you don't have the specific /32 to the standby. Packet arrives on active FW. It gets accepted and needs to be forwarded to standby box. It will do so based on topology, that is outside interface. But when this packet arrives to standby on outside interface with source IP from inside network, it will get dropped as spoofed. Unless spoofing is off &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:54:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26808#M4910</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-31T17:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26809#M4911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah, but I've run the infamous&amp;nbsp;&lt;EM style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;fw ctl zdebug drop&amp;nbsp;&lt;/EM&gt;on the standby member (not yet in production), and have not seen the drops there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 18:01:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26809#M4911</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-31T18:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26810#M4912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kaspars and Alexei, thank you guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ended-up using /32 routes as per Kaspars suggestion since I've recalled being in similar situation before and this being a less intrusive solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will keep Alexei's solution in my toolbox.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, I still am baffled as to why zdebug drop did not yield anything on standby member when it was failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vladimir&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 18:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26810#M4912</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-01-31T18:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26811#M4913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will try tomorrow in one of clusters. Interesting. I just recall seeing spoofing drops in logs. Let you know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 18:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26811#M4913</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-31T18:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26812#M4914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go, fw monitor shows packet being accepted on incoming interface on active cluster member. But no outgoing packet there&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62706_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw ctl zdebug shows on active member&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62707_pastedImage_2.png" style="width: 620px; height: 31px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that this is without enabling&amp;nbsp;&lt;STRONG&gt;fwha_forw_packet_to_not_active&lt;/STRONG&gt;. After I enable it it started working immediately. Without static routes. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;But I have seen your case not that long ago and that's why I remembered about /32 option..&lt;/P&gt;&lt;P&gt;Sorry won't have much time to dig into my past notes what happened there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 06:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26812#M4914</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-02-01T06:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26813#M4915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you again for looking into it: I have not seen the drops because I was looking for them on the standby member, thinking that if I see "accepts" in the log, the primary was not dropping them.&lt;/P&gt;&lt;P&gt;Apparently it drops them on egress.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of two solutions available, which one do you like better?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26813#M4915</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-02-01T14:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26814#M4916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hehe, I think I found exactly your situation &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;Connection from one side of the ClusterXL destined to the physical IP address of a non-Active cluster member on the other side of the ClusterXL fails -&amp;nbsp;&lt;/STRONG&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42733" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42733"&gt;sk42733&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just wanted to mention that this fix with&amp;nbsp;&lt;STRONG&gt;fwha_forw_packet_to_not_active&lt;/STRONG&gt; is also connected to many other possible issues:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105539" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105539"&gt;Simultaneously pinging the cluster members and the VIP address...&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97587" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97587"&gt;"Contract entitlement check failed" error on policy installation failure&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695"&gt;Cluster debug shows "FW-1: fwha_forw_ssl_handler: Rejecting ssl packets to a non-active member"&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118801" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118801"&gt;"ERR_CONNECTION_REFUSED" error is displayed in web browser when connecting to Gaia Portal&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112724" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112724"&gt;Updates For Anti-Virus/Anti-Bot/Application Control/URLF blades are not working on standby ClusterXL member&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, it might be even a "best practice" &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&amp;nbsp;But I have only experience with versions before R80, don't know how it is there.&amp;nbsp;Also these "strange" routes might be a bit confusing for a new administrator for example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26814#M4916</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-02-01T14:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26815#M4917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree that given how many issues this setting resolves, it may make better sense to have it on by default and have an option of commenting it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wander what is the reason for it not to be and what possible side effects of it being set are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vladimir Yakovlev &lt;/P&gt;&lt;P&gt;973.558.2738&lt;/P&gt;&lt;P&gt;vlad@eversecgroup.com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 15:03:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26815#M4917</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-02-01T15:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26816#M4918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the process of deploying new cluster of 15400s and ended-up using this suggestion.&lt;/P&gt;&lt;P&gt;Just wanted to tip my hat to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26816#M4918</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-06-18T13:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26817#M4919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had similar problem, solved after setting "fw ctl get int&amp;nbsp;fwha_forw_packet_to_not_active" value to 1. sk42733 was helpful&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 14:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26817#M4919</guid>
      <dc:creator>Huseyin_Rencber</dc:creator>
      <dc:date>2018-06-18T14:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26818#M4920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/cool.png" /&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/check.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 14:56:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26818#M4920</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-06-18T14:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26819#M4921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;got similar story where&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;standby device in A/S HA is accessible by IP but GAIA Portal (http2 daemon) isn't working at all&lt;/P&gt;&lt;P&gt;I've regenerated self-signed certs&lt;/P&gt;&lt;P&gt;Still no go&lt;/P&gt;&lt;P&gt;httpd won't start&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ssh to the standby device but one thing isn't accessible - https/http either on 443 or any other port simply HTTP daemon won't start on that device (there were no chances to that cluster since nearly 1y in terms of the PKI/FQDN etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas folks? alreago got a SR with TAC &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;just from yesterday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jerry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 08:31:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26819#M4921</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-11-06T08:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26820#M4922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would say it's a separate issue as you can SSH to standby cluster member. So L3 routing is working end to end. There are multiple SKs regarding dead httpd, really depends on SW version you are running and actual errors you see. You might want to try this&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk84561" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk84561"&gt;How to debug the Gaia Portal&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 11:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26820#M4922</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-11-06T11:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26821#M4923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did debug even with Ottawa TAC man - still no joy &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers Kaspars, I do appreciate what you've wrote just now but all this is already known, we know it isn't routing or access lists issue but httpd dead as you called it.&lt;/P&gt;&lt;P&gt;now clue what's the problem but that HA runs pretty much latest "takes" ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 11:22:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26821#M4923</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-11-06T11:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing standby cluster member from non-local network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26822#M4924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just meant to say that this thread probably is irrelevant to your case so best would be to start new one&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 11:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-accessing-standby-cluster-member-from-non-local-network/m-p/26822#M4924</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-11-06T11:24:13Z</dc:date>
    </item>
  </channel>
</rss>

