<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Virtual Standby member cannot reach internal DNS or Internet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/92744#M9029</link>
    <description>&lt;P&gt;Thank you for your offer.&lt;/P&gt;&lt;P&gt;It's already under investigation. But I think we will have to revert to R80.30.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jul 2020 12:12:41 GMT</pubDate>
    <dc:creator>Jan_Kleinhans</dc:creator>
    <dc:date>2020-07-29T12:12:41Z</dc:date>
    <item>
      <title>Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/90412#M9022</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;after upgrade to R80.40 HFA 48 we encounter the following problem.&lt;/P&gt;&lt;P&gt;If the standby member of a VS (VS2 for example) tries to reach a system, for example the internal DNS, it doesn't work.&lt;/P&gt;&lt;P&gt;In the log we can see, that the package doesn't get send from the interface of the virtual machine but gets send out from an interface of the VS0 (in this example the Mgmt interface).&lt;/P&gt;&lt;P&gt;So the standby member has a Threat Emulation Error because it cannot reach the DNS or something else.&lt;/P&gt;&lt;P&gt;When we change the standby member to active state we get "Firewall - Domain resolving error. Check DNS configuration on the gateway (0)" errors in the log and have distorted internet access. The new standby member has now the same issue as the old standby member and cannot reach any address. If the new standby member will work as expected after some time we did not test as is was in production.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anybody else such a problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 14:09:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/90412#M9022</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2020-07-02T14:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/90615#M9023</link>
      <description>Have you done this by chance?&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111786" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111786&lt;/A&gt;</description>
      <pubDate>Mon, 06 Jul 2020 01:26:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/90615#M9023</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-06T01:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/90645#M9024</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;yes. It dind't work. But the problem got bigger now. If we switch to the standby member traffic is not working anymore because of thousands of RAD errors. Only if we stop the now standby member traffic flows as espected.&lt;BR /&gt;We opened a TAC as we are now working with one member only.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Jan</description>
      <pubDate>Mon, 06 Jul 2020 09:07:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/90645#M9024</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2020-07-06T09:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/91840#M9025</link>
      <description>&lt;P&gt;We're you able to resolve this, what was the solution?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 13:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/91840#M9025</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-07-18T13:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/92008#M9026</link>
      <description>&lt;P&gt;No we didn't.&lt;/P&gt;&lt;P&gt;The case is open but there is no real progress at the moment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We found the following SK.&lt;/P&gt;&lt;P&gt;sk168075 (Created 5 days ago). It says that reaching the internet or somthing else isn't possible since R80.10. But it worked till R80.30. We have another cluster with R80.20 where there is connectivity to DNS etc..&lt;/P&gt;&lt;P&gt;At the moment we have to debug TED on the standby member. But it already says that it cannot do a name resolving in the normal ted.elg.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;gethostbyname() failed for: threat-emulation.checkpoint.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 06:22:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/92008#M9026</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2020-07-21T06:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/92254#M9028</link>
      <description>&lt;P&gt;Kindly PM the SR number and I will take a look, thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 13:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/92254#M9028</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-07-23T13:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/92744#M9029</link>
      <description>&lt;P&gt;Thank you for your offer.&lt;/P&gt;&lt;P&gt;It's already under investigation. But I think we will have to revert to R80.30.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 12:12:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/92744#M9029</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2020-07-29T12:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/93144#M9030</link>
      <description>&lt;P&gt;After hours of Investigation a Checkpoint Engineer disabled the new routing behaviour of R80.40 with the fwkern enty:&lt;/P&gt;&lt;P&gt;fwha_cluster_hide_active_only=0&lt;/P&gt;&lt;P&gt;This works as a workaround. Checkpoint is also trying to create a hotfix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 09:35:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/93144#M9030</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2020-08-03T09:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/109314#M14825</link>
      <description>&lt;P&gt;I've just installed R80.40 with JHFA91, and it appears this is still an issue.&amp;nbsp; The default value for&amp;nbsp;&lt;SPAN&gt;fwha_cluster_hide_active_only = 1.&amp;nbsp; After changing this value to 0 access to the internet from the gateway now works so the standby member can now get its AV/ABOT updates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also for reference sk169154.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 21:47:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/109314#M14825</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-01-29T21:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/112281#M15579</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have exactly the same issue as one of my VSs (R80.40 take 89) has no internet access on standby member. I have added the fwkern entry as per attached but no change. do we have to reboot the cluster member? tried cpstop;cpstart as well.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 14:38:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/112281#M15579</guid>
      <dc:creator>Attiq786</dc:creator>
      <dc:date>2021-03-02T14:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/112285#M15582</link>
      <description>&lt;P&gt;Ok Sorted. It needed a reboot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 15:09:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/112285#M15582</guid>
      <dc:creator>Attiq786</dc:creator>
      <dc:date>2021-03-02T15:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/112290#M15583</link>
      <description>&lt;P&gt;It was strange though. I have 3 other VSs and none of them has this issue on standby member except this one. which was newly created.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 15:15:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/112290#M15583</guid>
      <dc:creator>Attiq786</dc:creator>
      <dc:date>2021-03-02T15:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118165#M16737</link>
      <description>&lt;P&gt;So, I had this same problem on 2 clusters of 23800's(R80.40) and adding the&amp;nbsp;&lt;SPAN&gt;fwha_cluster_hide_active_only =&amp;nbsp;0, fixed it.&amp;nbsp; The odd thing is that I also have 2 clusters of R80.40 on 5200's, and they worked like normal and didn't need the fix.&amp;nbsp; one difference was the 5200's weren't running TE or TX, whereas the others were.&amp;nbsp; Not sure why the inconsistency.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 14:54:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118165#M16737</guid>
      <dc:creator>Chris_Wilson</dc:creator>
      <dc:date>2021-05-11T14:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118184#M16742</link>
      <description>&lt;P&gt;I'm sure you checked, just want to stress that the standby node is not included in the implied rulebase.&lt;/P&gt;&lt;P&gt;So you have to explicitly allow the other member on the active members rulebase - which is of course the same &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;if not you will see a drop on the active node where standby member is source.&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 17:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118184#M16742</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2021-05-11T17:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118408#M16771</link>
      <description>&lt;P&gt;We also ran into this problem on upgrade to R80.40 from R80.20. The upgrade release notes do not tell you that the parameter fwha_cluster_hide_active_only is now set to 1 by default. The issue is that while the standby cluster members are now forwarding packets to the active member, there are no implied rules to allow this traffic. Adding in explicit access policy rules to allow the cluster members to accept and forward packets for each other fixed the issue for us and left the parameter turned on, as the R80.40 upgrade wants.&lt;/P&gt;&lt;P&gt;The new behavior is kinda sorta documented in an implied way through a chain of SKs: sk169154 &amp;amp; sk167874 &amp;amp; sk169975&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 17:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118408#M16771</guid>
      <dc:creator>Dale_Lobb</dc:creator>
      <dc:date>2021-05-14T17:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118410#M16772</link>
      <description>&lt;P&gt;In addition, we ran into a slight twist on this issue.&amp;nbsp; We used the Multi-Version Cluster upgrade option.&amp;nbsp; While MVC was on, the parameter fwha_cluster_hide_active_only&amp;nbsp; was set to "1" on all FW worker cores except one, where it was set to "0".&amp;nbsp; Apparently, it was being reset to "0" on one FW worker core after initial boot, but before the boot process ended.&amp;nbsp; Adding "fwha_forw_packet_to_not_active=1" to $FWDIR/boot/modules/fwkern.conf did not resolve problem.&amp;nbsp; TAC gave us an update to the startup script "/opt/CPsuite-R80.40/fw1/bin/fwstart" to force it back to "1" later in the boot process so that all FW workers were behaving the same.&amp;nbsp;&amp;nbsp; An email I have from TAC said this this bug is labelled "PRJ-20491" and will be fixed in a future HFA for R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To check if you have run into this bug in your own R80.40 upgrade, you can use a special feature of the "fw" command, "fw -i", to test the value of the param on each FW worker core:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# fw -i &amp;lt;fw_worker_number&amp;gt; ctl get int fwha_cluster_hide_active_only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example: fw -i 0 ctl get int fwha_cluster_hide_active_only&amp;nbsp; (to see the value set for FW Worker 0)&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 18:46:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/118410#M16772</guid>
      <dc:creator>Dale_Lobb</dc:creator>
      <dc:date>2021-05-14T18:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123814#M17823</link>
      <description>&lt;P&gt;Hi Date,&lt;/P&gt;&lt;P&gt;In case you want to set that command on the fly which will not survive reboot what will be the exact command:&lt;/P&gt;&lt;P&gt;To get it is clear:&lt;/P&gt;&lt;P&gt;# fw -i &amp;lt;fw_worker_number&amp;gt; ctl get int fwha_cluster_hide_active_only&lt;/P&gt;&lt;P&gt;Example: fw -i 0 ctl get int fwha_cluster_hide_active_only&amp;nbsp; (to see the value set for FW Worker 0)&lt;/P&gt;&lt;P&gt;How is the command when you want to set it?&lt;/P&gt;&lt;P&gt;Can not find anything for setting it in SKs.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 14:11:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123814#M17823</guid>
      <dc:creator>Darina2019</dc:creator>
      <dc:date>2021-07-14T14:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123832#M17825</link>
      <description>&lt;P&gt;Hi Darina,&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can set the parameter for all cores with the command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fw ctl set int fwha_cluster_hide_active_only 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Or for individual cores (workers) via:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fw -i &amp;lt;worker #&amp;gt; ctl set int fwha_cluster_hide_active_only 1&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Dale&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 15:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123832#M17825</guid>
      <dc:creator>Dale_Lobb</dc:creator>
      <dc:date>2021-07-14T15:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123834#M17826</link>
      <description>&lt;P&gt;So, I thought I would post this up.&amp;nbsp; After I had my problem, I had a case open and talked with a checkpoint engineer and he gave me the following info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In previous versions a workaround was done by disabling cluster NAT for local connections, with fwha_cluster_hide_active_only=1, this workaround should be deleted.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;For example from the CheckMates thread, this workaround (which advised for R80.30) is not good for R80.40.&lt;/P&gt;&lt;P&gt;I will explain to make our designs more clear:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;1) &lt;STRONG&gt;New R80.40 design:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;With fwha_cluster_hide_active_only=1 the design is that the packet flow will be:&lt;BR /&gt;&lt;BR /&gt;Standby -&amp;gt; Sync -&amp;gt; Active member -&amp;gt; going out with cluster VIP (source) -&amp;gt;&amp;nbsp; Peer getting the packet -&amp;gt; Peer responses to &lt;STRONG&gt;cluster VIP&amp;nbsp; -&amp;gt;&lt;/STRONG&gt;&amp;nbsp;Meaning Active member -&amp;gt; forwarding to Standby using Sync&lt;BR /&gt;&lt;BR /&gt;2) Old design fwha_cluster_hide_active_only=0:&lt;/P&gt;&lt;P&gt;Standby -&amp;gt;&amp;nbsp;&lt;STRONG&gt;going out with cluster VIP&lt;/STRONG&gt; (source) -&amp;gt;&amp;nbsp; Peer getting the packet -&amp;gt; Peer responses to &lt;STRONG&gt;cluster VIP&amp;nbsp; -&amp;gt;&lt;/STRONG&gt;&amp;nbsp;Meaning Active member -&amp;gt; forwarding to Standby using Sync&lt;BR /&gt;&lt;BR /&gt;3) Old design fwha_cluster_hide_active_only=0 + special cases like disabling cluster NAT:&lt;BR /&gt;&lt;BR /&gt;Standby -&amp;gt; Going out with &lt;STRONG&gt;physical Standby IP&lt;/STRONG&gt; (cluster NAT disabled) -&amp;gt; Peer getting the packet&amp;nbsp; -&amp;gt; Peer responses to Standby physical IP -&amp;gt; Standby&lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;We moved to use case 1 as a default because it works for all the topologies.&lt;BR /&gt;Case 2,3 has problem with some topologies and explained in sk169154&amp;nbsp; -&amp;gt; 3.4.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 15:38:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123834#M17826</guid>
      <dc:creator>Chris_Wilson</dc:creator>
      <dc:date>2021-07-14T15:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Standby member cannot reach internal DNS or Internet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123840#M17828</link>
      <description>&lt;P&gt;That is essentially what was told to me in my TAC case as well.&lt;/P&gt;&lt;P&gt;The bigger issue is that it became the default in R80.40 without being mentioned in the release notes.&amp;nbsp; And it also requires some sort of rulebase support to allow the active firewall to forward packets for the passive nodes.&amp;nbsp; There does not appear to be any implied rule to allow the traffic.&lt;/P&gt;&lt;P&gt;Then there is also the PRJ-20491 issue with fwha_cluster_hide_active_only getting set back to "0" for one or more firewall workers if you use the Multi-Version Cluster upgrade option, which, as far as I know, has not yet been resolved.&amp;nbsp; At least, it is not yet listed on the R80.40 HFA list of fixes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 16:22:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Virtual-Standby-member-cannot-reach-internal-DNS-or-Internet/m-p/123840#M17828</guid>
      <dc:creator>Dale_Lobb</dc:creator>
      <dc:date>2021-07-14T16:22:57Z</dc:date>
    </item>
  </channel>
</rss>

