<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: route flipping on R80.40 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/93241#M7232</link>
    <description>&lt;P&gt;No disabling SecureXL did not help.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 07:32:56 GMT</pubDate>
    <dc:creator>Steffen_Appel</dc:creator>
    <dc:date>2020-08-04T07:32:56Z</dc:date>
    <item>
      <title>route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86200#M6648</link>
      <description>&lt;P&gt;We have upgraded from R80.10 to R80.40 (HF48) and have a route flipping issue:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;# ip route get a.b.c.d&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;a.b.c.d via&amp;nbsp;&amp;lt;correct next hop ip&amp;gt; dev eth5 src &amp;lt;correct source&amp;gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;# ip route get a.b.c.d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;a.b.c.d via &amp;lt;correct next hop ip&amp;gt; dev eth2 src &amp;lt;correct source&amp;gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;For whatever reason the interface in the routing table is changed from eth5 to eth2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;In fw monitor you can see it as well, the first packet goes to eth5 correctly, the second one after a route flip goes to eth2, which is wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow  is-read-only"&gt;&lt;SPAN class="uiOutputTextArea"&gt;[vs_0][fw_2] &lt;STRONG&gt;eth5&lt;/STRONG&gt;:O[44]: ****** -&amp;gt; ***** (UDP) len=200 id=61683 UDP: 2464 -&amp;gt; 49910 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow  is-read-only"&gt;&lt;SPAN class="uiOutputTextArea"&gt;[vs_0][fw_2] &lt;STRONG&gt;eth2&lt;/STRONG&gt;:O[44]: ****** -&amp;gt; ****** (UDP) len=200 id=49885 UDP: 2464 -&amp;gt; 49910&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow  is-read-only"&gt;&lt;SPAN class="uiOutputTextArea"&gt;Did anyone have similiar problems?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;TAC case is opened.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 08:19:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86200#M6648</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-05-25T08:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86214#M6651</link>
      <description>&lt;P&gt;Is your firewall statically or dynamically routed?&amp;nbsp; What does the actual routing table (&lt;STRONG&gt;netstat -rn&lt;/STRONG&gt;) show for the destination network?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 12:27:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86214#M6651</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-25T12:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86215#M6652</link>
      <description>&lt;P&gt;It is completly static routed.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 12:31:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86215#M6652</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-05-25T12:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86308#M6663</link>
      <description>Hi, &lt;BR /&gt;&lt;BR /&gt;Do you happen to have this route duplicate on both interfaces?&lt;BR /&gt;Sound weird issue networking wise, I would say checking Gaia configuration in clish (show configuration), in config/active and in  kernel (ip route, ifconfig)&lt;BR /&gt;&lt;BR /&gt;also - any chance there is physical interface flapping going on?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Yair</description>
      <pubDate>Tue, 26 May 2020 09:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86308#M6663</guid>
      <dc:creator>Yair_Shahar</dc:creator>
      <dc:date>2020-05-26T09:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86324#M6664</link>
      <description>No interface flapping.&lt;BR /&gt;The problem occurs on both cluster nodes.&lt;BR /&gt;&lt;BR /&gt;Only one static route to the destination host:&lt;BR /&gt;set static-route a.b.c.d/32 nexthop gateway address ****** on&lt;BR /&gt;&lt;BR /&gt;And in active:&lt;BR /&gt;routed:instance:default:static:network:a.b.c.d t&lt;BR /&gt;routed:instance:default:static:network:a.b.c.d:masklen:32 t&lt;BR /&gt;routed:instance:default:static:network:a.b.c.d:masklen:32:gateway t&lt;BR /&gt;routed:instance:default:static:network:a.b.c.d:masklen:32:gateway:address:****** t&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 26 May 2020 10:51:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86324#M6664</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-05-26T10:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86332#M6665</link>
      <description>&lt;P&gt;We have only seen it for UDP and ICMP never for TCP.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 12:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86332#M6665</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-05-26T12:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86339#M6667</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;We have only ssen it for UDP and ICMP never for TCP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This statement makes no sense unless you are using Policy Based Routing (PBR), are you?&amp;nbsp; Routing is performed by the Linux IP Driver and is not generally influenced by anything in Check Point's code that would be distinguishing service or protocol, unless a feature such as ISP Redundancy is in use.&lt;/P&gt;
&lt;P&gt;Regular IP routing only looks at destination IP address and could care less about service or protocol.&amp;nbsp; Please provide the output of &lt;STRONG&gt;netstat -renv&lt;/STRONG&gt; from expert mode for the route in question, once when it is showing eth2 and the other when it is showing eth5.&amp;nbsp; We need to see the live routing table and associated flags/use.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 13:45:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86339#M6667</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-26T13:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86342#M6668</link>
      <description>&lt;P&gt;No pbr is used:&lt;/P&gt;&lt;P&gt;show pbr&lt;BR /&gt;PBR Summary&lt;/P&gt;&lt;P&gt;PBR has 0 tables&lt;BR /&gt;PBR has 0 rules&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;netstat shows:&lt;/P&gt;&lt;P&gt;a.b.c.d ******&amp;nbsp; 255.255.255.255 UGH 0 0 0 eth5 in the correct case&lt;/P&gt;&lt;P&gt;since the node is not in production right now of course I cannot provide the incorrect one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just for the info, there are about 130 static routes on the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 13:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86342#M6668</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-05-26T13:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86355#M6669</link>
      <description>&lt;P&gt;Without being able to see the unredacted value of the route next hop address and the full unredacted eth2 and eth5 interface configuration it is difficult to surmise what is wrong.&amp;nbsp; Feel free to PM this information to me without redacting the IP addresses.&amp;nbsp; If you aren't comfortable with doing that you'll need to work through TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 14:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86355#M6669</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-26T14:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86441#M6673</link>
      <description>&lt;P&gt;Did you receive the PN?&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 07:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86441#M6673</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-05-27T07:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86474#M6675</link>
      <description>&lt;P&gt;No I don't see your PM.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 12:58:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86474#M6675</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-27T12:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86480#M6677</link>
      <description>&lt;P&gt;PM sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 13:30:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86480#M6677</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-05-27T13:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86883#M6689</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10477"&gt;@Steffen_Appel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you have ISPR configured on the system?&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 15:48:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86883#M6689</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2020-05-31T15:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86996#M6706</link>
      <description>&lt;P&gt;No ISP redundancy configured no.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 05:52:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/86996#M6706</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-06-02T05:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/87000#M6707</link>
      <description>&lt;P&gt;Strange, did you open TAC case? if so can you share the number so i can follow it?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 06:12:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/87000#M6707</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2020-06-02T06:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/87014#M6709</link>
      <description>&lt;P&gt;Yes TAC case is open, will PM you the number.&lt;/P&gt;&lt;P&gt;Had a two day debugging season on the WE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 07:16:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/87014#M6709</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-06-02T07:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/90137#M6892</link>
      <description>R&amp;amp;D is still investigating.</description>
      <pubDate>Tue, 30 Jun 2020 05:17:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/90137#M6892</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-06-30T05:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/92706#M7153</link>
      <description>&lt;P&gt;Still no solution, but additional customers with the same problem.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 07:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/92706#M7153</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2020-07-29T07:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/93054#M7194</link>
      <description>&lt;P&gt;by chance does&amp;nbsp;&lt;/P&gt;&lt;P&gt;show route all&lt;/P&gt;&lt;P&gt;from clish show anything strange?&lt;/P&gt;&lt;P&gt;I would enable trace (set trace kernel all on, set trace static all on, etc) and then check /var/log/routed.log to see if you can get some hints on what is going on as routed is the only process that should be making routing changes so it would be the place to debug.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 21:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/93054#M7194</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-07-31T21:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: route flipping on R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/93056#M7195</link>
      <description>&lt;P&gt;Actually I've received some inside information about this case, and it appears to be a problem with the Linux route cache (&lt;STRONG&gt;ip route show cache&lt;/STRONG&gt;) which is somehow getting cached route entries that are associated with the wrong interface.&amp;nbsp; The main routing table (&lt;STRONG&gt;ip route show&lt;/STRONG&gt; or &lt;STRONG&gt;netstat -rn&lt;/STRONG&gt;) always shows the problematic route associated with the correct interface.&amp;nbsp; So this would appear to be a Gaia/Linux bug, and I find it interesting that the IP route cache functionality was abandoned in the 3.6 version of the Linux kernel, but unfortunately there is no apparent way to disable it permanently.&amp;nbsp; A temporary workaround is to flush the route cache with the &lt;STRONG&gt;ip route flush cache&lt;/STRONG&gt; command but the problem just comes back later.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 23:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-flipping-on-R80-40/m-p/93056#M7195</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-31T23:09:29Z</dc:date>
    </item>
  </channel>
</rss>

