<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall not forwarding traffic - policy unloaded in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Firewall-not-forwarding-traffic-policy-unloaded/m-p/72257#M1903</link>
    <description>&lt;P&gt;We have a 5000 series appliance that has not been added to a management station yet. In order to permit traffic through temporarily while we build other components we issues the 'fw unloadlocal' command. When we try to route through the firewall (using ping from a src outside one int and destined for a host on a different int) we see it get processed on the inbound interface (little i and big I) but it never leaves the destination interface.&lt;/P&gt;&lt;P&gt;We have verified we can ping the destination and that a route exists.&lt;/P&gt;&lt;P&gt;With the policy unloaded AND the firewall not being part of a management station would it not just act as a router and process traffic? Is there a debug command that can tell us whats going on?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2020 17:56:41 GMT</pubDate>
    <dc:creator>J_Saun</dc:creator>
    <dc:date>2020-01-14T17:56:41Z</dc:date>
    <item>
      <title>Firewall not forwarding traffic - policy unloaded</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Firewall-not-forwarding-traffic-policy-unloaded/m-p/72257#M1903</link>
      <description>&lt;P&gt;We have a 5000 series appliance that has not been added to a management station yet. In order to permit traffic through temporarily while we build other components we issues the 'fw unloadlocal' command. When we try to route through the firewall (using ping from a src outside one int and destined for a host on a different int) we see it get processed on the inbound interface (little i and big I) but it never leaves the destination interface.&lt;/P&gt;&lt;P&gt;We have verified we can ping the destination and that a route exists.&lt;/P&gt;&lt;P&gt;With the policy unloaded AND the firewall not being part of a management station would it not just act as a router and process traffic? Is there a debug command that can tell us whats going on?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 17:56:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Firewall-not-forwarding-traffic-policy-unloaded/m-p/72257#M1903</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-01-14T17:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall not forwarding traffic - policy unloaded</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Firewall-not-forwarding-traffic-policy-unloaded/m-p/72258#M1904</link>
      <description>&lt;P&gt;Nope, when the policy is unloaded there is no forwarding. It is then just a simple Linux host, not a router.&lt;/P&gt;
&lt;P&gt;After searching for this I found &lt;A href="https://www.cpug.org/forums/showthread.php/22701-fw-unloadlocal-and-routing-daemon-stopping" target="_self"&gt;this CPUG entry&lt;/A&gt;&amp;nbsp;that says to issue the following command to reanble IP forwading:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;echo 1 &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Thanks Tim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 18:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Firewall-not-forwarding-traffic-policy-unloaded/m-p/72258#M1904</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-01-14T18:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall not forwarding traffic - policy unloaded</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Firewall-not-forwarding-traffic-policy-unloaded/m-p/72260#M1905</link>
      <description>Thanks! That was it. Traffic is being forwarded now.</description>
      <pubDate>Tue, 14 Jan 2020 18:23:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Firewall-not-forwarding-traffic-policy-unloaded/m-p/72260#M1905</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-01-14T18:23:56Z</dc:date>
    </item>
  </channel>
</rss>

