<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point R77.30 ClusterXL and Cisco GLBP? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10224#M620</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would assume the forwarding decision is "upstream" then and not something the Check Point can directly influence.&lt;/P&gt;&lt;P&gt;Is the traffic going to the MPLS circuit subject to NAT?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Oct 2018 20:15:33 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-10-25T20:15:33Z</dc:date>
    <item>
      <title>Check Point R77.30 ClusterXL and Cisco GLBP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10221#M617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="border: 0px; color: rgba(0, 0, 0, 0.75); background: 0px 0px; font-size: 14px;"&gt;Is anyone using Check Point R77.30 ClusterXL and Cisco GLBP? Our MPLS provider has configured gateway load balancing protocol between two 50Mbit circuits. We are using the VIP of these routers as our route for the MPLS network. We were told that they are seeing traffic only being utilised outbound on one circuit. I've read this post which describes my scenario pretty much, however there isn't a solution, has anyone else come across this? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="border: 0px; color: rgba(0, 0, 0, 0.75); background: 0px 0px; font-size: 14px;"&gt;Any help appreciated!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="border: 0px; color: rgba(0, 0, 0, 0.75); background: 0px 0px; font-size: 14px;"&gt;(I cross posted this in to "Check Point Experts" on linked in - Apologies)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 11:52:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10221#M617</guid>
      <dc:creator>Dave_Cullen</dc:creator>
      <dc:date>2018-10-25T11:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77.30 ClusterXL and Cisco GLBP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10222#M618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How many routes are configured for this destination on the Check Point devices?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 17:05:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10222#M618</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-25T17:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77.30 ClusterXL and Cisco GLBP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10223#M619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just one route. &amp;nbsp;All global sites have their own /29 transfer network within the /24 super net.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 17:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10223#M619</guid>
      <dc:creator>Dave_Cullen</dc:creator>
      <dc:date>2018-10-25T17:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77.30 ClusterXL and Cisco GLBP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10224#M620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would assume the forwarding decision is "upstream" then and not something the Check Point can directly influence.&lt;/P&gt;&lt;P&gt;Is the traffic going to the MPLS circuit subject to NAT?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 20:15:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10224#M620</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-25T20:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77.30 ClusterXL and Cisco GLBP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10225#M621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience HSRP and VRRP all uses a VIP and all the "magic" is handled upstream yes.&lt;/P&gt;&lt;P&gt;The service provider engineer told me that the MAC address is alternated for the VIP that is provided by the GLBP cluster and this is how the load balancing is performed.&lt;/P&gt;&lt;P&gt;I guess the difference here is that we have active / active.&lt;/P&gt;&lt;P&gt;His last comments were:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your device should be capable to do Load-Sharing and accept two MACs for one IP, please check this.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Some ideas:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="margin-top: 0cm;"&gt;&lt;LI style="color: #1f497d; margin-left: 0cm;"&gt;Please allow asymmetric flows on your Firewall&lt;/LI&gt;&lt;LI style="color: #1f497d; margin-left: 0cm;"&gt;Please register two MAC addresses for The VIP IP X.X.X.1 (MAC: 00:00:00:00:00:01 and &lt;SPAN&gt;&amp;nbsp;00:00:00:00:00:02&lt;/SPAN&gt;) on you Firewall (Example Addresses)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I replied with:&lt;/P&gt;&lt;OL style="margin-top: 0cm;"&gt;&lt;LI style="margin-left: 18.0pt;"&gt;I cannot see that this is possible in Check Point&lt;/LI&gt;&lt;LI style="margin-left: 18.0pt;"&gt;I cannot create two static ARP entries for the same MAC - Gaia simply overtires the original entry when adding the second one&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe someone has specific experience in this scenario and could correct my logic above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so far!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 20:31:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10225#M621</guid>
      <dc:creator>Dave_Cullen</dc:creator>
      <dc:date>2018-10-25T20:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point R77.30 ClusterXL and Cisco GLBP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10226#M622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure how allowing asymmetric flows would necessarily solve this since the problem appears to be the fact we're sending traffic to one of the two MAC addresses.&lt;/P&gt;&lt;P&gt;Even so, asymmetric flows are bad from a firewall perspective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may be able to use ECMP (Equal Cost Multipath) to your advantage here.&lt;/P&gt;&lt;P&gt;Configure a static ARP with some other IP on that subnet as a second route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configure the "real" IP and this other IP as nexthops using ECMP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2018 21:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-R77-30-ClusterXL-and-Cisco-GLBP/m-p/10226#M622</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-25T21:02:27Z</dc:date>
    </item>
  </channel>
</rss>

