<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point firewall entries in Cisco ARP table in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-firewall-entries-in-Cisco-ARP-table/m-p/104384#M8247</link>
    <description>&lt;P&gt;ClusterXL uses the same MAC unless you tell it to use a vMAC, VRRP however by default uses a vMAC, which type is defined by the command you add your VIP addresses with.&lt;/P&gt;
&lt;P&gt;These are the options to set the vMAC per VIP:&lt;/P&gt;
&lt;TABLE class="tableintopic" border="1" width="606" cellspacing="0" cellpadding="2"&gt;
&lt;TBODY&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="156"&gt;
&lt;P class="tablebodytext"&gt;&lt;CODE class="monospace"&gt;vmac-mode&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="450"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;VRRP&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Sets the VMAC to the format outlined in the VRRP protocol specification RFC 3768. It is automatically set to the same value on all Security Gateways in a Virtual Router. This is the default.&lt;/P&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Interfac&lt;/STRONG&gt;e - Sets the VMAC to the local interface MAC address. If you define this mode for the master and the backup, the VMAC is different for each. VRRP IP addresses are related to different VMACs because they are dependent on the physical interface MAC address of the current master.&lt;/P&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Static&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Manually set the VMAC address. Enter the VMAC address after the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="monospace"&gt;static-mac&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;keyword.&lt;/P&gt;
&lt;P class="listcontinue"&gt;&lt;STRONG class="bold"&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- If you configure different VMACs on the master and backup, you must make sure that you select the correct proxy ARP setting for NAT.&lt;/P&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Extended&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Gaia dynamically calculates and adds three bytes to the interface MAC address to generate more random address. If you select this mode, Gaia constructs the same MAC address for master and backups in the Virtual Router.&lt;/P&gt;
&lt;P class="listcontinue"&gt;&lt;STRONG class="bold"&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- If you set the VMAC mode to Interface or Static, syslog error messages show when you restart the computer or during failover. This is caused by duplicate IP addresses for the master and backup. This is expected behavior because the master and backups temporarily use the same virtual IP address until they get master and backup status.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;So it looks like your VRRP VIP for this interface has been set with the option vmac-mode interface.&lt;/P&gt;
&lt;P&gt;in clish do:&lt;/P&gt;
&lt;P&gt;show configuration mcvr&lt;/P&gt;
&lt;P&gt;This will show you all VIP commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 06 Dec 2020 06:57:48 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2020-12-06T06:57:48Z</dc:date>
    <item>
      <title>Check Point firewall entries in Cisco ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-firewall-entries-in-Cisco-ARP-table/m-p/104382#M8245</link>
      <description>&lt;P&gt;Hi everyone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is probably a simple one so apologies in advance. I have a Check Point 5800 HA cluster in a Data Centre and following some work on a Cisco Nexus, looked at the ARP table and saw the following for my firewalls:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet 19.23.13.140 0 001c.7f81.0908 ARPA GigabitEthernet0/0/0 (CP VRRP)&lt;BR /&gt;Internet 19.23.13.141 0 001c.7f81.13a8 ARPA GigabitEthernet0/0/0 (CP 1 interface)&lt;BR /&gt;Internet 19.23.13.142 0 001c.7f81.0908 ARPA GigabitEthernet0/0/0 (CP 2 interface)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone tell me why CP2 MAC address is the same as CP VRRP? I was thinking that CP2 is acting as the master but would appreciate if this could be confirmed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 03:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-firewall-entries-in-Cisco-ARP-table/m-p/104382#M8245</guid>
      <dc:creator>ziggurat</dc:creator>
      <dc:date>2020-12-06T03:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point firewall entries in Cisco ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-firewall-entries-in-Cisco-ARP-table/m-p/104383#M8246</link>
      <description>&lt;P&gt;Depending on the configuration that seems…plausible.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 05:00:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-firewall-entries-in-Cisco-ARP-table/m-p/104383#M8246</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-06T05:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point firewall entries in Cisco ARP table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-firewall-entries-in-Cisco-ARP-table/m-p/104384#M8247</link>
      <description>&lt;P&gt;ClusterXL uses the same MAC unless you tell it to use a vMAC, VRRP however by default uses a vMAC, which type is defined by the command you add your VIP addresses with.&lt;/P&gt;
&lt;P&gt;These are the options to set the vMAC per VIP:&lt;/P&gt;
&lt;TABLE class="tableintopic" border="1" width="606" cellspacing="0" cellpadding="2"&gt;
&lt;TBODY&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="156"&gt;
&lt;P class="tablebodytext"&gt;&lt;CODE class="monospace"&gt;vmac-mode&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="450"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;VRRP&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Sets the VMAC to the format outlined in the VRRP protocol specification RFC 3768. It is automatically set to the same value on all Security Gateways in a Virtual Router. This is the default.&lt;/P&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Interfac&lt;/STRONG&gt;e - Sets the VMAC to the local interface MAC address. If you define this mode for the master and the backup, the VMAC is different for each. VRRP IP addresses are related to different VMACs because they are dependent on the physical interface MAC address of the current master.&lt;/P&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Static&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Manually set the VMAC address. Enter the VMAC address after the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="monospace"&gt;static-mac&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;keyword.&lt;/P&gt;
&lt;P class="listcontinue"&gt;&lt;STRONG class="bold"&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- If you configure different VMACs on the master and backup, you must make sure that you select the correct proxy ARP setting for NAT.&lt;/P&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Extended&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Gaia dynamically calculates and adds three bytes to the interface MAC address to generate more random address. If you select this mode, Gaia constructs the same MAC address for master and backups in the Virtual Router.&lt;/P&gt;
&lt;P class="listcontinue"&gt;&lt;STRONG class="bold"&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- If you set the VMAC mode to Interface or Static, syslog error messages show when you restart the computer or during failover. This is caused by duplicate IP addresses for the master and backup. This is expected behavior because the master and backups temporarily use the same virtual IP address until they get master and backup status.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;So it looks like your VRRP VIP for this interface has been set with the option vmac-mode interface.&lt;/P&gt;
&lt;P&gt;in clish do:&lt;/P&gt;
&lt;P&gt;show configuration mcvr&lt;/P&gt;
&lt;P&gt;This will show you all VIP commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 06:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-firewall-entries-in-Cisco-ARP-table/m-p/104384#M8247</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-12-06T06:57:48Z</dc:date>
    </item>
  </channel>
</rss>

