<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VRRP is backup state at both of firewalls in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13932#M998</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all make sure that the priority on both members are different by no more than 20, but in your case 10. Advise use prio delta of 10 and prio of 195 and 200, with both numbers ending in a 0 it is not always clear which of the 2 should be master.&lt;/P&gt;&lt;P&gt;Check the state on both members with &lt;STRONG&gt;cphaprob stat&amp;nbsp;&lt;/STRONG&gt; and see if both members show active/active.&lt;/P&gt;&lt;P&gt;In Dashboard/SmartConsole have you set the clustering method to VRRP? In the global settings also look for the allow VRRP setting to be allowed before first.&lt;/P&gt;&lt;P&gt;For a test type &lt;STRONG&gt;set vrrp&amp;nbsp;monitor-firewall off&amp;nbsp;&lt;/STRONG&gt; and see what happens.&lt;/P&gt;&lt;P&gt;Last thing to check is to see for sure that the switches you have connected both FW's to, are set to allow multicast traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Nov 2018 22:10:46 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2018-11-07T22:10:46Z</dc:date>
    <item>
      <title>VRRP is backup state at both of firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13930#M996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Expert,&lt;/P&gt;&lt;P&gt;Both of firewalls are backup state in VRRP cluster mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73305_pastedImage_6.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73304_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Already enable for cluster gateways via cpconfig. and reboot both of firewalls also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73303_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please kindly advice it. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 06:05:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13930#M996</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-11-07T06:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP is backup state at both of firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13931#M997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like you have enabled both ClusterXL and VRRP clustering at once.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 08:25:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13931#M997</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-11-07T08:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP is backup state at both of firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13932#M998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all make sure that the priority on both members are different by no more than 20, but in your case 10. Advise use prio delta of 10 and prio of 195 and 200, with both numbers ending in a 0 it is not always clear which of the 2 should be master.&lt;/P&gt;&lt;P&gt;Check the state on both members with &lt;STRONG&gt;cphaprob stat&amp;nbsp;&lt;/STRONG&gt; and see if both members show active/active.&lt;/P&gt;&lt;P&gt;In Dashboard/SmartConsole have you set the clustering method to VRRP? In the global settings also look for the allow VRRP setting to be allowed before first.&lt;/P&gt;&lt;P&gt;For a test type &lt;STRONG&gt;set vrrp&amp;nbsp;monitor-firewall off&amp;nbsp;&lt;/STRONG&gt; and see what happens.&lt;/P&gt;&lt;P&gt;Last thing to check is to see for sure that the switches you have connected both FW's to, are set to allow multicast traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 22:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13932#M998</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-11-07T22:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP is backup state at both of firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13933#M999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like that case, how can I off for one of services in either one please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 23:41:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13933#M999</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-11-07T23:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP is backup state at both of firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13934#M1000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maarten,&lt;/P&gt;&lt;P&gt;Thanks a lot for your points. I will follow that. Yes, I set for VRRP settings in Smart Dashboard. Global settings is allowed already. Now, All members are 2x master.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 23:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13934#M1000</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-11-07T23:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP is backup state at both of firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13935#M1001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So this will happen when the members do not "see" each other, so go back to the switches and make sure the VLAN's are present on the switches and also in the trunk between switches.&lt;/P&gt;&lt;P&gt;You can start by checking if you can ping the other box in the same network, if allowed by policy.&lt;/P&gt;&lt;P&gt;Check logging if the VRRP is actually not dropped, if so make sure to add an allow rule for the gateways to the VRRP Multicast address.&lt;/P&gt;&lt;P&gt;When you are running in VMware, make sure to disable all security on the Switch ports that connect to the FW's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 09:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13935#M1001</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-11-08T09:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP is backup state at both of firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13936#M1002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just share the info that what we resolve for this issue as per below:&lt;/P&gt;&lt;P&gt;1. Enable cluster gateways at both firewalls via cpconfig and reboot both of firewalls.&lt;/P&gt;&lt;P&gt;2. After that both of firewalls are master mode changes.&lt;/P&gt;&lt;P&gt;3. And then, add&amp;nbsp;VRRP rules at the firewalls and push down the policies. After that, it will resolve for the issue as one firewall one is master state and another one is backup state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 14:17:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VRRP-is-backup-state-at-both-of-firewalls/m-p/13936#M1002</guid>
      <dc:creator>Myo_Min_Zaw</dc:creator>
      <dc:date>2018-11-08T14:17:57Z</dc:date>
    </item>
  </channel>
</rss>

