<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic originating from standby VS fails to reach DNS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88033#M9194</link>
    <description>&lt;P&gt;Exactly! That was my question! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But how do you force a standby VS to communicate to active VR / VS?&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2020 10:04:47 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2020-06-11T10:04:47Z</dc:date>
    <item>
      <title>Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88023#M9192</link>
      <description>&lt;P&gt;Have a peculiar problem after introducing Virtual Router on our VSX to interconnect most VSes on that cluster.&lt;/P&gt;
&lt;P&gt;If traffic originates from a VS on the &lt;STRONG&gt;standby&lt;/STRONG&gt; VSX and it needs to reach another VS (i.e. Identity Sharing on port 15105) or a service that's behind another VS (i.e. DNS for FQDN objects), it will stop dead in it's tracks at the standby VR - I'm assuming VR is not forwarding traffic as it is in standby state. Diagram below might help understanding the issue:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image.png" style="width: 632px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6466iEAC6F53DFEBDF99C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not too sure if anyone else has seen it? And possibly found a solution. I tried to search SKs but did not find anything relevant.&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Seems like obvious solution in HA VSX case, would be first forwarding packet from standby VS1 to active VS1, then routing it normally via active VSX. And when packet is returned to active VS1, it would forward it back to originating standby VS1. This way we would resolve both FQDN case and IA publishing.&lt;/P&gt;
&lt;P&gt;Currently we have lots of domain alerts in logs from standby VSX:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image.png" style="width: 927px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6467i595D34CF71DCE782/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as well as standby VS that's publishing IDs to other VSes is marked as "failed" in SmartConsole:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image.png" style="width: 880px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6469iFBFBA649C2703A39/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 08:44:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88023#M9192</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-06-11T08:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88030#M9193</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the standby instance of the virtual-router on the standby VSX does nothing, did not forwarding any traffic.&lt;/P&gt;
&lt;P&gt;This is following virtual-router is only supported with VSX-HA.&lt;/P&gt;
&lt;P&gt;If something on the standby node needs to access something behind another VS, the traffic flow has to go over the virtual-router on the active node.&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 09:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88030#M9193</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-11T09:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88033#M9194</link>
      <description>&lt;P&gt;Exactly! That was my question! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But how do you force a standby VS to communicate to active VR / VS?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 10:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88033#M9194</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-06-11T10:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88143#M9195</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;are these DNS and PEP connections NATed behind the internal VSX-IP of the VS?&lt;/P&gt;
&lt;P&gt;They should leave the system with the "real" IP of the VS. If I remember rightly there was a problem with PEP in ClusterXL and a wrong NAT for the physical node. Maybee the problem is the same here with VSX. But right now I can't found the sk&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 11:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88143#M9195</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-11T11:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88329#M9196</link>
      <description>&lt;P&gt;No, NAT does happen correctly and no internal VSX IPs are used once traffic islis VS. Otherwise it would not work on active VSX either.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 06:52:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/88329#M9196</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-06-12T06:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/90457#M9197</link>
      <description>Hi.&lt;BR /&gt;Have you found a solution for this problem? We are not using Virtual Routers but have the same problem that the standby VSses cannot reach DNS or other destinations.&lt;BR /&gt;Are you using R80.40 ?&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;&lt;BR /&gt;Jan</description>
      <pubDate>Fri, 03 Jul 2020 06:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/90457#M9197</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2020-07-03T06:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/90479#M9198</link>
      <description>&lt;P&gt;Nope. We're on R80.30 T155. But the problem is only present when VR is in the path. Those VSes that have direct physical connection or via virtual switch work ok. So I believe you have uncovered totally different problem on R80.40&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 11:20:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/90479#M9198</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-07-03T11:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic originating from standby VS fails to reach DNS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/94962#M9199</link>
      <description>&lt;P&gt;Interestingly enough the issue was resolved after I installed T215 (from T155)! Not too sure if anyone was still interested, but here you go! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 22:32:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-originating-from-standby-VS-fails-to-reach-DNS/m-p/94962#M9199</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-08-23T22:32:14Z</dc:date>
    </item>
  </channel>
</rss>

