<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot access Web GUI checkpoint firewall in cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21011#M89900</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks you, I'll try, but this device need working&amp;nbsp; 24/7, so I need plan to resole, can you tell me the problem, issue that may be encountered and estimate downtime.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Jan 2019 01:52:18 GMT</pubDate>
    <dc:creator>Vu_Le</dc:creator>
    <dc:date>2019-01-07T01:52:18Z</dc:date>
    <item>
      <title>Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21003#M89892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello and happy new year everyone,&lt;/P&gt;&lt;P&gt;I have two checkpoint firewall running cluster active - active, I want to configure new interface, but I only access web GUI one checkpoint firewall, number two firewall access log on smart console inform deny connect.&lt;/P&gt;&lt;P&gt;Someone can help me to fix it.&lt;/P&gt;&lt;P&gt;Thanks you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 03:00:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21003#M89892</guid>
      <dc:creator>Vu_Le</dc:creator>
      <dc:date>2019-01-04T03:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21004#M89893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you connecting via VPN? Please show us rule #10.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 06:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21004#M89893</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-01-04T06:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21005#M89894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Hello,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Could you please confirm some more details of the topology... w&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;here is&lt;/SPAN&gt;&amp;nbsp;the source address 172.18.95.X located in relation to the destination interface IP (172.18.6.X) that you are attempting to connect to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Some related solutions that may help isolate the cause are provided below for reference.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk119154 -&amp;nbsp;Cannot connect to the Standby member from a non-local subnet&lt;BR /&gt;sk106425 - Connections through cluster to physical IP address of ClusterXL member are dropped by Anti-Spoofing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;sk42733 -&amp;nbsp;Connection from one side of the ClusterXL destined to the physical IP address of a non-Active cluster member on the other side of the ClusterXL fails&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 07:11:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21005#M89894</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-04T07:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21006#M89895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you check the log you might find that your connections to the inactive cluster member are getting dropped as out-of-state or spoofed. Likely, your connection to the inactive member and the return traffic from it are on different interfaces on the inactive member. Traffic _to_ the inactive&amp;nbsp; member wants to go via the active member.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How I fixed this in my environment was to put static routes on the internal router that is adjacent to the cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose your mgmt segment is 10.2.65.0/24 and those are the addresses you are connecting to with the web GUI.&lt;/P&gt;&lt;P&gt;And, 10.2.44.0/24 is the backbone segment between the gateways and your adjacent internal router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's say 10.2.65.1 and 2 are the mgmt IPs of the two gateways, and 10.2.44.5 and 6 are the IPs of (say) eth1 of the two gateways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router has:&lt;/P&gt;&lt;P&gt;ip route 10.2.65.1 255.255.255.255 10.2.44.5&lt;/P&gt;&lt;P&gt;ip route 10.2.65.2 255.255.255.255 10.2.44.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't do this, this adjacent router sends all of the traffic for dest 10.2.44.0/24 to the active member. The traffic might still reach the inactive member after coming out the other side of the active member, but the reply from the inactive member will come out a different interface on it, hence will be dropped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 13:59:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21006#M89895</guid>
      <dc:creator>Steve_Runyon</dc:creator>
      <dc:date>2019-01-04T13:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21007#M89896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;(My apologies in advance if this isn't exactly your issue, but I wanted to put it out there all the same. Otherwise, please disregard.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a similar case open with TAC about this, but for me it was on a ClusterXL setup with dual 13800 appliances. TAC was able to reference &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43346"&gt;sk43346 &lt;/A&gt;with the following fix:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the following command in expert mode from both gateway CLIs:&lt;/P&gt;&lt;PRE&gt;[Expert@gateway]# fw ctl set int fwha_forw_packet_to_not_active 1&lt;/PRE&gt;&lt;P&gt;What this does is tell the cluster to permit answers from the secondary ClusterXL member, even though there hasn't been an HA state change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps you out. This was a major irritation for us for a long time before we finally discovered, with TAC's help, the actual fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Please note that I am hereby NOT responsible for an outage if you apply this command in your environment without thoroughly reading and understanding the sk I referenced above. Please do your due diligence and don't take my word for it alone!)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 16:37:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21007#M89896</guid>
      <dc:creator>crescentwire</dc:creator>
      <dc:date>2019-01-04T16:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21008#M89897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;fwha_forw_packet_to_not_active is one of very often recommendations in cases like this. There should be no outage because of it. Also, the command that you provided just changes the parameter until a reboot. The parameter should be written into fwkern.conf file, if it is required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More details and information are available in previous threads:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/6771"&gt;Problem accessing standby cluster member from non-local network&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/7912"&gt;Checkpoint Standby Cluster is using VIP to communicate with outside&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With routes added (as Steve mentioned above), it also should work. But I prefer to change the kernel parameter, as it helps with many other situations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2019 20:10:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21008#M89897</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2019-01-05T20:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21009#M89898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have allow this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76736_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 01:35:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21009#M89898</guid>
      <dc:creator>Vu_Le</dc:creator>
      <dc:date>2019-01-07T01:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21010#M89899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Chris,&lt;/P&gt;&lt;P&gt;Pls see topology, all source network in vlan on checkpoint firewall.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76737_pastedImage_1.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 01:38:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21010#M89899</guid>
      <dc:creator>Vu_Le</dc:creator>
      <dc:date>2019-01-07T01:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21011#M89900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks you, I'll try, but this device need working&amp;nbsp; 24/7, so I need plan to resole, can you tell me the problem, issue that may be encountered and estimate downtime.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 01:52:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21011#M89900</guid>
      <dc:creator>Vu_Le</dc:creator>
      <dc:date>2019-01-07T01:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access Web GUI checkpoint firewall in cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21012#M89901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Steve,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I give&amp;nbsp;a little more information, I can still access IP real management of Gateway01 but not Gateway02, so I just run one command add route?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 01:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cannot-access-Web-GUI-checkpoint-firewall-in-cluster/m-p/21012#M89901</guid>
      <dc:creator>Vu_Le</dc:creator>
      <dc:date>2019-01-07T01:55:44Z</dc:date>
    </item>
  </channel>
</rss>

