<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.20 Issue : Monitoring standby cluster members via VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52573#M10411</link>
    <description>Hi Danny&lt;BR /&gt;i just solved this with R&amp;amp;D.&lt;BR /&gt;Yes fwha_forw_packet_to_not_active=1 will not do any difference.&lt;BR /&gt;You need a jhf with both accpck and fw_wrapper.&lt;BR /&gt;Last part have been to use kernel command fwha_cluster_hide_ip=1 instead.&lt;BR /&gt;&lt;BR /&gt;But again you need to have 2 hotfixed installed on top of r80.20 take 47 GA&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;Kim</description>
    <pubDate>Sat, 04 May 2019 08:10:19 GMT</pubDate>
    <dc:creator>Kim_Moberg</dc:creator>
    <dc:date>2019-05-04T08:10:19Z</dc:date>
    <item>
      <title>R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48278#M9426</link>
      <description>&lt;P&gt;As a Check Point Partner we are monitoring the Check Point systems of our customers via SNMPv3 over VPN.&lt;/P&gt;
&lt;P&gt;When monitoring standby cluster nodes via VPN this of course leads to a "&lt;EM&gt;Clear text packet should be encrypted&lt;/EM&gt;" error in ClusterXL as the active cluster node already decrypts the SNMP packets and forwards it in clear text to the standby member which expects the packets to be encrypted.&lt;/P&gt;
&lt;P&gt;The solution always was &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42733" target="_self"&gt;sk42733&lt;/A&gt;:&lt;/P&gt;
&lt;PRE&gt;[Expert@&lt;STRONG&gt;node1&lt;/STRONG&gt;:0]# cat $FWDIR/boot/modules/fwkern.conf
fwha_forw_packet_to_not_active=1&lt;BR /&gt;
[Expert@&lt;STRONG&gt;node2&lt;/STRONG&gt;:0]# cat $FWDIR/boot/modules/fwkern.conf
fwha_forw_packet_to_not_active=1&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;Check Point stopped supporting this option in R80.20.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It works in all versions prior to R80.20. The official statement is that it's by design of the product as mentioned in Scenario 1 of &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93204" target="_self"&gt;sk93204&lt;/A&gt;. The interesting point is that initially Check Point Support tried to fix it by providing us with a hotfix which didn't work and only then started to argue about the product design.&lt;/P&gt;
&lt;P&gt;This means for all Check Point users out there:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;You cannot directly login to standby cluster nodes via VPN anymore (SSH, GAiA WebUI)&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;You cannot securely monitor the standby cluster nodes via VPN (ICMP, SNMP)&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;You need to create workarounds that make troubleshooting times longer and raise complexity&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 13:39:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48278#M9426</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-03-22T13:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48280#M9427</link>
      <description>Can you send me the related SR privately? Let me ask around in R&amp;amp;D.</description>
      <pubDate>Fri, 22 Mar 2019 13:36:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48280#M9427</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-22T13:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48282#M9428</link>
      <description>&lt;P&gt;Sent.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 13:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48282#M9428</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-03-22T13:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48285#M9431</link>
      <description>&lt;P&gt;Hi Danny&lt;/P&gt;&lt;P&gt;I tried the same fwkern.conf change but didn't work too.&lt;/P&gt;&lt;P&gt;Heard about a work-around to create a no-nat rule to each secure gateway.&lt;/P&gt;&lt;P&gt;Else I installed JHF43 which had a fix to this issue, but I am not sure if this solved SNMP issue you are describing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 13:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/48285#M9431</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2019-03-22T13:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52547#M10404</link>
      <description>&lt;P&gt;Check Point support provided a working hotfix to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk137592" target="_self"&gt;R80.20 JHF (Take 43)&lt;/A&gt;. However, it's not working from Take 47 anymore. Waiting for a new hotfix..&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 20:44:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52547#M10404</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-05-03T20:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52562#M10409</link>
      <description>&lt;P&gt;This really shouldn't be a hotfix.&lt;/P&gt;
&lt;P&gt;I'd expect this to be a part of the JHFAs and version releases as a prerequisite.&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 02:00:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52562#M10409</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-04T02:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52572#M10410</link>
      <description>I already told my colleagues to open as many SRs as possible for this issue (so for each customer we upgrade to R80.20), so TAC has awareness this should be part of JHF</description>
      <pubDate>Sat, 04 May 2019 08:03:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52572#M10410</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2019-05-04T08:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52573#M10411</link>
      <description>Hi Danny&lt;BR /&gt;i just solved this with R&amp;amp;D.&lt;BR /&gt;Yes fwha_forw_packet_to_not_active=1 will not do any difference.&lt;BR /&gt;You need a jhf with both accpck and fw_wrapper.&lt;BR /&gt;Last part have been to use kernel command fwha_cluster_hide_ip=1 instead.&lt;BR /&gt;&lt;BR /&gt;But again you need to have 2 hotfixed installed on top of r80.20 take 47 GA&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;Kim</description>
      <pubDate>Sat, 04 May 2019 08:10:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52573#M10411</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2019-05-04T08:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52629#M10424</link>
      <description>There are specific requirements that hotfixes have to meet before they are rolled into a jumbo.&lt;BR /&gt;Not knowing anything about the specific hotfixes, I can't comment what the specific issues are in this case.&lt;BR /&gt;That said, awareness of a widespread issue is definitely a factor, so open those SRs &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 05 May 2019 19:39:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/52629#M10424</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-05T19:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/53569#M10699</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A small update.&lt;/P&gt;&lt;P&gt;Found the SK related to this issue.&lt;/P&gt;&lt;P&gt;&lt;A title="SK147493: Unable to connect to the Standby Cluster member from a non-local subnet via SSH or WebUI" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk147493&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_blank" rel="noopener"&gt;SK147493: Unable to connect to the Standby Cluster member from a non-local subnet via SSH or WebUI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A title="SK93204: ClusterXL: Accessing Standby member through IPSec VPN" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93204&amp;amp;partition=General&amp;amp;product=ClusterXL," target="_blank" rel="noopener"&gt;SK93204: ClusterXL: Accessing Standby member through IPSec VPN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using R80.20 GA Take 47 I had to upgrade these hotfix before getting it to work.&lt;/P&gt;&lt;P&gt;accel_HOTFIX_R80_20_JHF_T47_001_MAIN_GA_FULL.tgz&lt;BR /&gt;fw1_wrapper_HOTFIX_R80_20_JHF_T47_001_MAIN_GA_FULL.tgz&lt;/P&gt;&lt;P&gt;I had to use fwkern settings fwha_cluster_hide_active_only=1.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Yesterday I did a CPUSE in-place upgrade to R80.30 T200 Official GA release.&lt;BR /&gt;fwkern settings was saved due to upgrade but I cannot access SSH and Web UI over VPN after. Ping work.&lt;/P&gt;&lt;P&gt;Back to same issue again. Opened a new case and linked to the original case.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will keep you updated if anything new happens &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 08:57:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/53569#M10699</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2019-05-16T08:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/53570#M10700</link>
      <description>&lt;P&gt;We've also wanted in past to monitor firewall clusters on internet via VPN, but it doesn't make sense to send it to tunnel when using ssh, snmpv3 and restricted source IP access.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 07:08:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/53570#M10700</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2019-05-16T07:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/53572#M10701</link>
      <description>&lt;P&gt;It makes perfect sense to monitor the status of standby cluster members in order to known if they are available in cases of cluster failovers. Check Point provides working solutions also for the latest JHF take. I hope they'll include it with the next JHF take in order to avoid having to install an additional hotfix.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 07:16:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/53572#M10701</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-05-16T07:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/54607#M10908</link>
      <description>&lt;P&gt;Check Point has addressed this issue in &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk137592" target="_self"&gt;R80.20 Jumbo Hotfix&lt;/A&gt; (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk147493" target="_self"&gt;Take 80&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;CP is no longer recommending changing the flag fwha_forw_packet_to_not_active flag, as described in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93204" target="_self"&gt;sk93204&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 22:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/54607#M10908</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-05-28T22:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Issue : Monitoring standby cluster members via VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/54612#M10909</link>
      <description>Hi Danny&lt;BR /&gt;Thats the one I have been refering to.&lt;BR /&gt;PMTR-33209, PMTR-30582&lt;BR /&gt;&lt;BR /&gt;If you upgrade to R80.30 it is not released in the first version. Wait for the first GA take or ask for JHF that solves this issue.</description>
      <pubDate>Wed, 29 May 2019 04:25:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Issue-Monitoring-standby-cluster-members-via-VPN/m-p/54612#M10909</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2019-05-29T04:25:20Z</dc:date>
    </item>
  </channel>
</rss>

