<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DUAL ISP fail-over is not working found some strange behaviour in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DUAL-ISP-fail-over-is-not-working-found-some-strange-behaviour/m-p/92930#M7178</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Issue - Fail over is not working in dual ISP setup.&lt;/P&gt;&lt;P&gt;Issue Description - We have attached setup in our environment and while trying to do a fail over towards secondary ISP. We observed that old connections are still trying to exit out from primary (Down ISP) and in debug I am getting interface inactive.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I observer that if we reset the connection from user end or connection get clear from connection table, then it will go via secondary ISP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thing is this behaviour looks ok with http/https traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But IPSec and GRE traffic is causing major issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 different routers behind the firewall trying to communicate internet using IPSec and GRE and we have probing mechanism enabled. So when primary ISP goes down this traffic still trying to go out via primary ISP and due to probing, connection table on the firewall will get automatically refresh.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logs after failover done to secondary ISP&amp;nbsp;&lt;/P&gt;&lt;P&gt;++&lt;/P&gt;&lt;P&gt;;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=47 65.**.**.123:0 -&amp;gt; 165.**.**.12:2048 dropped by misp_rt_chain Reason: Interface is inactive;&lt;BR /&gt;;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=47 65.**.**.123:0 -&amp;gt; 165.**.**.12:2048 dropped by misp_rt_chain Reason: Interface is inactive;&lt;BR /&gt;;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=47 65.**.**.123:0 -&amp;gt; 165.**.**.12:2048&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;dropped by misp_rt_chain Reason: Interface is inactive;&lt;/P&gt;&lt;P&gt;++&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DUal ISP.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7435i1D635C593CFE4434/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DUal ISP.png" alt="DUal ISP.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2020 20:55:17 GMT</pubDate>
    <dc:creator>amdhim0004</dc:creator>
    <dc:date>2020-07-30T20:55:17Z</dc:date>
    <item>
      <title>DUAL ISP fail-over is not working found some strange behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DUAL-ISP-fail-over-is-not-working-found-some-strange-behaviour/m-p/92930#M7178</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Issue - Fail over is not working in dual ISP setup.&lt;/P&gt;&lt;P&gt;Issue Description - We have attached setup in our environment and while trying to do a fail over towards secondary ISP. We observed that old connections are still trying to exit out from primary (Down ISP) and in debug I am getting interface inactive.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I observer that if we reset the connection from user end or connection get clear from connection table, then it will go via secondary ISP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thing is this behaviour looks ok with http/https traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But IPSec and GRE traffic is causing major issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 different routers behind the firewall trying to communicate internet using IPSec and GRE and we have probing mechanism enabled. So when primary ISP goes down this traffic still trying to go out via primary ISP and due to probing, connection table on the firewall will get automatically refresh.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logs after failover done to secondary ISP&amp;nbsp;&lt;/P&gt;&lt;P&gt;++&lt;/P&gt;&lt;P&gt;;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=47 65.**.**.123:0 -&amp;gt; 165.**.**.12:2048 dropped by misp_rt_chain Reason: Interface is inactive;&lt;BR /&gt;;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=47 65.**.**.123:0 -&amp;gt; 165.**.**.12:2048 dropped by misp_rt_chain Reason: Interface is inactive;&lt;BR /&gt;;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=47 65.**.**.123:0 -&amp;gt; 165.**.**.12:2048&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;dropped by misp_rt_chain Reason: Interface is inactive;&lt;/P&gt;&lt;P&gt;++&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DUal ISP.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7435i1D635C593CFE4434/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DUal ISP.png" alt="DUal ISP.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 20:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DUAL-ISP-fail-over-is-not-working-found-some-strange-behaviour/m-p/92930#M7178</guid>
      <dc:creator>amdhim0004</dc:creator>
      <dc:date>2020-07-30T20:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: DUAL ISP fail-over is not working found some strange behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DUAL-ISP-fail-over-is-not-working-found-some-strange-behaviour/m-p/197604#M36915</link>
      <description>&lt;P&gt;Hi Amdhim0004&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Myself too getting the same issue, Did you got the solution on this.&lt;/P&gt;&lt;P&gt;Please assist me to solve this.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rajkumar T&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 15:00:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DUAL-ISP-fail-over-is-not-working-found-some-strange-behaviour/m-p/197604#M36915</guid>
      <dc:creator>vijayakumar_M</dc:creator>
      <dc:date>2023-11-09T15:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: DUAL ISP fail-over is not working found some strange behaviour</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DUAL-ISP-fail-over-is-not-working-found-some-strange-behaviour/m-p/197781#M36956</link>
      <description>&lt;P&gt;Need to add one route for Monitoring from Secondary ISP.&lt;/P&gt;&lt;P&gt;Set next hope as Secondary ISP gateway IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Amandeep&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 08:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DUAL-ISP-fail-over-is-not-working-found-some-strange-behaviour/m-p/197781#M36956</guid>
      <dc:creator>amdhim0004</dc:creator>
      <dc:date>2023-11-13T08:33:13Z</dc:date>
    </item>
  </channel>
</rss>

