<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suspecting cluster issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Suspecting-cluster-issue/m-p/85835#M9147</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have 2 physical vsx box and 1 box (VSX2) is down and waiting for RMA . So all VSs are ative in box 1 (VSX1) .&lt;/P&gt;&lt;P&gt;I have one issue there are 2 source servers (a.b.c.d = Server 1 and e.f.g.h = Server 2) and&amp;nbsp; same one&amp;nbsp; destination = i.j.k.l with port = 443 . Here one source server (a.b.c.d) when trying to access destination = i.j.k.l with port 1636 (unsuccess) and one source server =&lt;/P&gt;&lt;P&gt;e.f.g.h when trying to access dst : i.j.k.l with port 1636 (success) . We are getting the logs in firewall from both the source servers&amp;nbsp;&lt;/P&gt;&lt;P&gt;from same rule in "Logs and monitor" but when i run tcpdump for unsuccess source server (a.b.c.d) to dst : i.j.k.l with icmp&lt;/P&gt;&lt;P&gt;in box 1 (VSX1) we are getting only echo reply packet from i.j.k.l &amp;gt; a.b.c.d .&lt;/P&gt;&lt;P&gt;The only difference is that when we run traceroute from source = a.b.c.d(unsuccess) to destination = i.j.k.l 1st hop is switch (different box - Nexus SW1&lt;/P&gt;&lt;P&gt;after that it is dropping which next hop is firewall interface cluster ip )&amp;nbsp; and when we run traceroute from source = e.f.g.h(success) to destination = i.j.k.l (it covers all path 1st hop is switch different box - Nexxus SW2 from switch next hop is same firewall interface cluster ip).&lt;/P&gt;&lt;P&gt;1. Checked the route from the source servers to dst : i.j.k.l point to same next hop .&lt;/P&gt;&lt;P&gt;2. Check the reverse route also from i.j.k.l to (a.b.c.d) &amp;amp; (e.f.g.h) both are same .&lt;/P&gt;&lt;P&gt;3. Checked the route from the switch boxes (SW1 and SW2) point to same next hop ip i.e (cluster ip of interface of checkpoint fw)&lt;/P&gt;&lt;P&gt;4. Destination server is connected interface.&lt;/P&gt;&lt;P&gt;5. Source servers are able to pingable from firewalls particular VS&amp;nbsp;&lt;/P&gt;&lt;P&gt;6. Source server (a.b.c.d) is not able to ping destination (i.j.k.l) but source server (e.f.g.h ) is able to ping dst : 1.j.k.l .&lt;/P&gt;&lt;P&gt;7. Same rule is present in firewall for both the source servers to dst with icmp and 1636 port.&lt;/P&gt;&lt;P&gt;8. 2nd box of Firewall got down just nearly the issue started .&lt;/P&gt;&lt;P&gt;9. Some time when run debug command of kernel found "instance is fully utilized " and box cpu is reaching like fwk6 - 88-90%&lt;/P&gt;&lt;P&gt;&amp;nbsp; and fwk5 (70% = all communication is going through this VS 5).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea pls suggest !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2020 07:33:23 GMT</pubDate>
    <dc:creator>vikupoi_123</dc:creator>
    <dc:date>2020-05-20T07:33:23Z</dc:date>
    <item>
      <title>Suspecting cluster issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Suspecting-cluster-issue/m-p/85835#M9147</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have 2 physical vsx box and 1 box (VSX2) is down and waiting for RMA . So all VSs are ative in box 1 (VSX1) .&lt;/P&gt;&lt;P&gt;I have one issue there are 2 source servers (a.b.c.d = Server 1 and e.f.g.h = Server 2) and&amp;nbsp; same one&amp;nbsp; destination = i.j.k.l with port = 443 . Here one source server (a.b.c.d) when trying to access destination = i.j.k.l with port 1636 (unsuccess) and one source server =&lt;/P&gt;&lt;P&gt;e.f.g.h when trying to access dst : i.j.k.l with port 1636 (success) . We are getting the logs in firewall from both the source servers&amp;nbsp;&lt;/P&gt;&lt;P&gt;from same rule in "Logs and monitor" but when i run tcpdump for unsuccess source server (a.b.c.d) to dst : i.j.k.l with icmp&lt;/P&gt;&lt;P&gt;in box 1 (VSX1) we are getting only echo reply packet from i.j.k.l &amp;gt; a.b.c.d .&lt;/P&gt;&lt;P&gt;The only difference is that when we run traceroute from source = a.b.c.d(unsuccess) to destination = i.j.k.l 1st hop is switch (different box - Nexus SW1&lt;/P&gt;&lt;P&gt;after that it is dropping which next hop is firewall interface cluster ip )&amp;nbsp; and when we run traceroute from source = e.f.g.h(success) to destination = i.j.k.l (it covers all path 1st hop is switch different box - Nexxus SW2 from switch next hop is same firewall interface cluster ip).&lt;/P&gt;&lt;P&gt;1. Checked the route from the source servers to dst : i.j.k.l point to same next hop .&lt;/P&gt;&lt;P&gt;2. Check the reverse route also from i.j.k.l to (a.b.c.d) &amp;amp; (e.f.g.h) both are same .&lt;/P&gt;&lt;P&gt;3. Checked the route from the switch boxes (SW1 and SW2) point to same next hop ip i.e (cluster ip of interface of checkpoint fw)&lt;/P&gt;&lt;P&gt;4. Destination server is connected interface.&lt;/P&gt;&lt;P&gt;5. Source servers are able to pingable from firewalls particular VS&amp;nbsp;&lt;/P&gt;&lt;P&gt;6. Source server (a.b.c.d) is not able to ping destination (i.j.k.l) but source server (e.f.g.h ) is able to ping dst : 1.j.k.l .&lt;/P&gt;&lt;P&gt;7. Same rule is present in firewall for both the source servers to dst with icmp and 1636 port.&lt;/P&gt;&lt;P&gt;8. 2nd box of Firewall got down just nearly the issue started .&lt;/P&gt;&lt;P&gt;9. Some time when run debug command of kernel found "instance is fully utilized " and box cpu is reaching like fwk6 - 88-90%&lt;/P&gt;&lt;P&gt;&amp;nbsp; and fwk5 (70% = all communication is going through this VS 5).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea pls suggest !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 07:33:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Suspecting-cluster-issue/m-p/85835#M9147</guid>
      <dc:creator>vikupoi_123</dc:creator>
      <dc:date>2020-05-20T07:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecting cluster issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Suspecting-cluster-issue/m-p/85855#M9148</link>
      <description>&lt;P&gt;Contact TAC - VSX is far from easily configurable, and VSLS (i assume you are using) even more...&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 09:26:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Suspecting-cluster-issue/m-p/85855#M9148</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-05-20T09:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecting cluster issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Suspecting-cluster-issue/m-p/86035#M9149</link>
      <description>Hi ,&lt;BR /&gt;Problem has been solved the issue is occuring due to duplicate ips configured in 2 VMs after giving free ip in one VM issue resolved .&lt;BR /&gt;Thanks ! Sorry for incovenience .</description>
      <pubDate>Fri, 22 May 2020 06:21:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Suspecting-cluster-issue/m-p/86035#M9149</guid>
      <dc:creator>vikupoi_123</dc:creator>
      <dc:date>2020-05-22T06:21:38Z</dc:date>
    </item>
  </channel>
</rss>

