<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem in facing SIC Management to Branch office firewall in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59544#M84649</link>
    <description>&lt;P&gt;Now i am to ping Management -FW1-FW2 eachother&lt;/P&gt;&lt;P&gt;But SIC not forming ,,Still something is missing&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Aug 2019 20:44:31 GMT</pubDate>
    <dc:creator>Akram_wasim</dc:creator>
    <dc:date>2019-08-02T20:44:31Z</dc:date>
    <item>
      <title>Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59471#M84627</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;SPAN class="css-901oao css-16my406 r-1qd0xha r-ad9z0x r-bcqeeo r-qvutc0"&gt;&amp;nbsp;Currently i build my&amp;nbsp; Home lab for CCSA R.76 .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="css-901oao css-16my406 r-1qd0xha r-ad9z0x r-bcqeeo r-qvutc0"&gt;When i try to add or link Management and Branch Firewall SIC is not establishing &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="css-901oao css-16my406 r-1qd0xha r-ad9z0x r-bcqeeo r-qvutc0"&gt;Note : HQ F-W and Management SIC established working fine no problem with that,,.please help&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="r-18u37iz"&gt;&lt;A href="https://twitter.com/hashtag/CCSA?src=hashtag_click" target="_blank" rel="noopener"&gt;#CCSA&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="css-901oao css-16my406 r-1qd0xha r-ad9z0x r-bcqeeo r-qvutc0"&gt; .76&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can some one help me to resolve my problem&amp;nbsp;&lt;/P&gt;&lt;P&gt;@cbtnuggets R76&lt;/P&gt;&lt;P&gt;Below are the topology :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CBT.jpeg" style="width: 864px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2045i21D2F9D9DC55196A/image-size/large?v=v2&amp;amp;px=999" role="button" title="CBT.jpeg" alt="CBT.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 07:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59471#M84627</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T07:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59487#M84628</link>
      <description>I assume routes are ok.&lt;BR /&gt;&lt;BR /&gt;I think you have not pushed policy to HQ-FW1 after creating object of Branch-FW2 with correct IP.&lt;BR /&gt;This is necessary for HQ-FW1 to create relevant implied rules to allow Mgmt/GW-communication!</description>
      <pubDate>Fri, 02 Aug 2019 12:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59487#M84628</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2019-08-02T12:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59489#M84629</link>
      <description>HI Norbort,&lt;BR /&gt;&lt;BR /&gt;Thanks for reply,&lt;BR /&gt;I have one management , for the first gateway (HQFW) SIC is established.&lt;BR /&gt;In rule base table , I allow any source any destination is accept which mean from management to FW-2 need to form SIC but in my case ,SIC is not established ...Please help&lt;BR /&gt;</description>
      <pubDate>Fri, 02 Aug 2019 12:30:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59489#M84629</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T12:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59490#M84630</link>
      <description>&lt;P&gt;Routes are ok?&lt;/P&gt;&lt;P&gt;Can you reach gw2 from mgmt using SSH for example?&lt;/P&gt;&lt;P&gt;What are you seeing in log?&lt;/P&gt;&lt;P&gt;Have you tried capturing packets on gw1 using tcpdump/fw monitor?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 12:32:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59490#M84630</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2019-08-02T12:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59491#M84631</link>
      <description>I havent verified logs and but&lt;BR /&gt;&lt;BR /&gt;From management to GW2 when i ping 192.168.1.111 its unreachable..&lt;BR /&gt;&lt;BR /&gt;So which means there is problem with routes ? Correct me if i am wrong..</description>
      <pubDate>Fri, 02 Aug 2019 12:35:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59491#M84631</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T12:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59492#M84632</link>
      <description>from Management i added routes to 10.1.1.111&lt;BR /&gt;&lt;BR /&gt;on GW 1 i added routes to 192.168.1.1 outside ,so i taught from management we can able to reach GW2 ..&lt;BR /&gt;&lt;BR /&gt;whether i need to add routes from GW2 to Management, Is it necessary ?? Please reply&lt;BR /&gt;</description>
      <pubDate>Fri, 02 Aug 2019 12:38:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59492#M84632</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T12:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59493#M84633</link>
      <description>&lt;P&gt;Because this is the lab an you are trying to determine if your routing is OK, do the following:&lt;/P&gt;
&lt;P&gt;In your SmartConsole go to Global Policy Properties and enable ICMP as well as "Log Implied Rules".&lt;/P&gt;
&lt;P&gt;SSH into your branch gateway (or open an emulated console) and perform "fw unloadlocal".&lt;/P&gt;
&lt;P&gt;Its default policy will be blocking ICMP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then verify that your routing is working and that you are getting ICMP responses where expected.&lt;/P&gt;
&lt;P&gt;Configure Static NAT for the Management Server object to translate its internal IP into one of the available IPs in 192.168. network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Vladimir&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 12:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59493#M84633</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-08-02T12:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59494#M84634</link>
      <description>OK Vladimir ,I will check and come back if there is any issue..&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Fri, 02 Aug 2019 13:07:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59494#M84634</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T13:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59511#M84635</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Vladimir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Still facing same issue ,Unable to for SIC between Management to B-FW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unable to ping Management&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;help..&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="unable to ping Management.PNG" style="width: 364px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2051i7411AA4DB31C636D/image-size/large?v=v2&amp;amp;px=999" role="button" title="unable to ping Management.PNG" alt="unable to ping Management.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BFW routes.PNG" style="width: 780px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2052i67E8EBA4DA6849C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="BFW routes.PNG" alt="BFW routes.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SIC issue.PNG" style="width: 724px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2053iFBAA42F33BD8B755/image-size/large?v=v2&amp;amp;px=999" role="button" title="SIC issue.PNG" alt="SIC issue.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 18:10:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59511#M84635</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T18:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59512#M84636</link>
      <description>&lt;P&gt;You have no route on your gateway! As management is not in a directly attached network, you need to add correct routing!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 18:18:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59512#M84636</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2019-08-02T18:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59513#M84637</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13916"&gt;@Akram_wasim&lt;/a&gt;&amp;nbsp;, your management server's IP is not in your FW2 routing table.&lt;/P&gt;
&lt;P&gt;If you want to ping it, provided the static NAT is assigned to the Management server's object, you should be able to ping the IP you are NATing it to, i.e. one in the 192.168.1.*/24 range.&lt;/P&gt;
&lt;P&gt;Otherwise, provided you have ICMP enabled in Global properties, you should add a route to 10.1.1.25/255.255.255.255 to your BQF or specify the route to the entire 10.1.1.0/24 network with the next hop being external IP of your primary gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 18:19:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59513#M84637</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-08-02T18:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59517#M84638</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Vladimir&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Same issue&lt;/P&gt;&lt;P&gt;1. I have enabled the ICMP in Global properties&lt;/P&gt;&lt;P&gt;2. add default routes from BFW to FW1 external IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am unable to ping ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pic 1 : Add static Nat from Manager to 192.168.1.112&lt;/P&gt;&lt;P&gt;Pic 2 : routing table FW 2&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Static Nat from manager to 192.168.1....PNG" style="width: 674px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2054iCB0551CCF4FB48B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Static Nat from manager to 192.168.1....PNG" alt="Static Nat from manager to 192.168.1....PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Routing Table.PNG" style="width: 742px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2055i0236DAFB09594F7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Routing Table.PNG" alt="Routing Table.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 18:38:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59517#M84638</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T18:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59518#M84639</link>
      <description>can you help how to add route in B-FW ,Seriously i cant do it .Please help</description>
      <pubDate>Fri, 02 Aug 2019 18:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59518#M84639</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T18:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59519#M84640</link>
      <description>&lt;P&gt;Can you ping from BQFW the IP of 192.168.1.112?&lt;/P&gt;
&lt;P&gt;Have you enabled the "Log Implied Rules" in Global properties to see where your ICMP traffic is going in the logs?&lt;/P&gt;
&lt;P&gt;You either use static NAT and refer to the Management server by its' NATed IP (the most common scenario in practice), or in your lab environment, do not NAT, but rely on static routes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As shown in your screenshot below, the Static NAT is being applied to the "Security Gateway control connections".&lt;/P&gt;
&lt;P&gt;This means that you should be able to establish SIC with BQFW even in the absence of ICMP, if your routing is correct.&lt;/P&gt;
&lt;P&gt;Try performing "fw unloadlocal" on the BQFW and ping and trace route to it from your management server to see where things are breaking down.&lt;/P&gt;
&lt;P&gt;Additionally, verify that on your Management Server the default route is configured to use FW1 internal interface as it's gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 18:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59519#M84640</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-08-02T18:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59523#M84641</link>
      <description>&lt;P&gt;If you are using WebUI, it is self-explanatory.&lt;/P&gt;
&lt;P&gt;If you are trying to do this via Clish:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On your Management server (where SMS is the hostname of your management server):&lt;/P&gt;
&lt;P&gt;SMS&amp;gt; set static-route default nexthop gateway address 10.1.1.111 on&lt;/P&gt;
&lt;P&gt;SMS&amp;gt;save config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;On your HQ-FW1:&lt;/P&gt;
&lt;P&gt;HQ-FW1&amp;gt; set static-route 10.2.2.0/24 nexthop gateway address 192.168.1.222 on&lt;/P&gt;
&lt;P&gt;HQ-FW1&amp;gt; set static-route 172.16.2.0/24 nexthop gateway address 192.168.1.222 on&lt;BR /&gt;HQ-FW1&amp;gt;save config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;On your Branch-FW2:&lt;/P&gt;
&lt;P&gt;BQFW&amp;gt; set static-route 10.1.1.0/24 nexthop gateway address 192.168.1.111 on&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;BQFW&amp;gt; set static-route 172.16.1.0/24 nexthop gateway address 192.168.1.111 on&lt;BR /&gt;BQFW&amp;gt;save config&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 19:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59523#M84641</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-08-02T19:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59532#M84642</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Added all route as per instruction you had given to me&amp;nbsp; but same issue nothing has changed ,able to ping FW2 to Manager&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Br-Fw routes.PNG" style="width: 854px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2057i6E4A1C6D6AD9FEAF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Br-Fw routes.PNG" alt="Br-Fw routes.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hq-fw routes.PNG" style="width: 827px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2058iAC086A91477B1C76/image-size/large?v=v2&amp;amp;px=999" role="button" title="Hq-fw routes.PNG" alt="Hq-fw routes.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manager routes.PNG" style="width: 776px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2059iD89803260F8548B3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Manager routes.PNG" alt="Manager routes.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Above are current routing table after you shared me new routes ,i added everything and enable icmp in the global properties ,,i done everything ,, This is so headache,, i am unable to figure out.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 19:29:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59532#M84642</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T19:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59533#M84643</link>
      <description>&lt;P&gt;Show the route on your management server.&lt;/P&gt;
&lt;P&gt;Have you created the firewall objects, defined their topology, configured security policy for the HQ-FW, published it and installed?&lt;/P&gt;
&lt;P&gt;If not, you cannot expect this to work unless you perform "fw unloadlocal" on both firewalls.&lt;/P&gt;
&lt;P&gt;Please show a screenshot of your policy here.&lt;/P&gt;
&lt;P&gt;Please show the "Network" property of both firewall objects here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 19:37:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59533#M84643</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-08-02T19:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59535#M84644</link>
      <description>&lt;P&gt;P.S. In your management server's screenshot, the routes shown are NOT the one I have wrote you to add:&lt;/P&gt;
&lt;P&gt;On your Management server (where SMS is the hostname of your management server):&lt;/P&gt;
&lt;P&gt;SMS&amp;gt; set static-route default nexthop gateway address 10.1.1.111 on&lt;/P&gt;
&lt;P&gt;SMS&amp;gt;save config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VS. yours:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 967px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2060iE034EBD7C9AC8219/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Your management server cannot know how to reach the 10.2.2.0/24 network, your HQ-FW does.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 19:42:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59535#M84644</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-08-02T19:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall -My policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59537#M84645</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2061i26C3F0FED439B349/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy.png" alt="Policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 19:53:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59537#M84645</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T19:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in facing SIC Management to Branch office firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59540#M84646</link>
      <description>&lt;P&gt;manager routes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Managment route.PNG" style="width: 732px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2063iFD565E968C7EBE0B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Managment route.PNG" alt="Managment route.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 19:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-in-facing-SIC-Management-to-Branch-office-firewall/m-p/59540#M84646</guid>
      <dc:creator>Akram_wasim</dc:creator>
      <dc:date>2019-08-02T19:57:13Z</dc:date>
    </item>
  </channel>
</rss>

