<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster XL - MAC ADDRESS MOVEs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/94485#M18683</link>
    <description>&lt;P&gt;I fixed this by:&lt;/P&gt;&lt;P&gt;1. Setting the parameter ccl_preserve_src_MAC to 1 on each cluster member&lt;/P&gt;&lt;P&gt;2. Found that this did stop the 02:00:00:00:00:00 mac address from appearing, but I had another issue, which was an unbelievable amount of DNS traffic bouncing between cluster members&lt;/P&gt;&lt;P&gt;3. On a whim, I did a cpstop/cpstart on the standby member. This stopped the DNS traffic. I failed over and did the same on the active member&lt;/P&gt;&lt;P&gt;4. I&amp;nbsp;&lt;EM&gt;reverted&lt;/EM&gt; the parameter ccl_preserve_src_MAC back to 0 on both members, and the mac address 02:00:00:00:00:00 did not come back&lt;/P&gt;&lt;P&gt;So a bit of a mystery to me, but my gateways are in a better place.&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2020 12:05:47 GMT</pubDate>
    <dc:creator>David_C1</dc:creator>
    <dc:date>2020-08-18T12:05:47Z</dc:date>
    <item>
      <title>Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84709#M17081</link>
      <description>&lt;P&gt;Hello guys ,&lt;/P&gt;&lt;P&gt;I will described below the scenario and please advice if anyone else faced this issue.&lt;/P&gt;&lt;P&gt;involved: DNS server - 2 Clusters with 4 members (R80.20) - Nexus switch&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS send the packet to 1st layer firewall with correct MAC address.&lt;/P&gt;&lt;P&gt;14:28:31.177248 XX:XX:XX:XX:e6:86 &amp;gt; XX:XX:XX:XX:96:b8, ethertype IPv4 (0x0800), length 156: XX.XX.XX.70.domain &amp;gt; XX.XX.XX.65.10253: 1178 NXDomain 0/1/0 (114)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then the 1st layer firewall received the packet correctly.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;14:28:31.191342 XX:XX:XX:XX:e6:86 &amp;gt; XX:XX:XX:XX:96:b8, ethertype IPv4 (0x0800), length 156:XX.XX.XX.70.domain &amp;gt; XX.XX.XX.65.10253:&amp;nbsp; 1178 NXDomain 0/1/0 (114)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Afterwards the next packet translated to the below by the 4th member of the cluster.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;14:28:31.191358 &lt;STRONG&gt;02:00:00:00:00:00&lt;/STRONG&gt; &amp;gt; XX:XX:XX:XX:90:64, ethertype IPv4 (0x0800), length 156: XX.XX.XX.70.domain &amp;gt; XX.XX.XX.65.10253:&amp;nbsp; 1178 NXDomain 0/1/0 (114)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Notes:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1.Captures on DNS and switch shows that DNS never send those MAC address&amp;nbsp;02:00:00:00:00:00 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.All Packets that includes mac address&amp;nbsp;02:00:00:00:00:00 are outbound traffic from FW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. CCP mode broadcast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4.Confirm from switch that this MAC is generated on FW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. we cannot find and relate any errors on FW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any advises&amp;nbsp;are welcome!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2020 04:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84709#M17081</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2020-05-10T04:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84736#M17093</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5854"&gt;@Geomix7&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;can you please explain more detailed your environment.&lt;/P&gt;
&lt;P&gt;You wrote something about a 4th member of the cluster, sounds like a cluster with 4 nodes. But at the beginning of your writing you wrote 2 clusters with 4 members.... Do you have 2 clusters and both with 2 nodes or anything else?&lt;/P&gt;
&lt;P&gt;How about your ClusterXL mode. HA or LoadSharing, vmac ?&lt;/P&gt;
&lt;P&gt;What is the problem?&lt;/P&gt;
&lt;P&gt;Please be aware that sometimes sending and receiving MACs are different. It depends on the ClusterXL configuration.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2020 16:32:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84736#M17093</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-05-10T16:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84746#M17099</link>
      <description>02:00 are normally used by VRRP only when using extended VMAC, but then the rest of the mac is not all 0's, as VRRP will use a VMAC derived from the IP of the interface.</description>
      <pubDate>Sun, 10 May 2020 17:56:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84746#M17099</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-05-10T17:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84789#M17109</link>
      <description>Dear Wolfgang ,&lt;BR /&gt;We have 2 clusters which each one has 4 nodes.&lt;BR /&gt;Each cluster is in HA mode and also is setup with magic MAC.&lt;BR /&gt;The problem is that we can see many mac moves with specific mac 02:00:00:00:00:00 which appeared randomly on all nodes.We are trying to figure out what is the root cause of this issue.</description>
      <pubDate>Mon, 11 May 2020 04:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84789#M17109</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2020-05-11T04:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84790#M17110</link>
      <description>Dear Maarten,&lt;BR /&gt;&lt;BR /&gt;We are not have enable VRRP implementation.</description>
      <pubDate>Mon, 11 May 2020 04:59:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84790#M17110</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2020-05-11T04:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84813#M17113</link>
      <description>&lt;P&gt;AFAIK, Check Point does not use port&amp;nbsp;&lt;SPAN&gt;10253 for any of the communications.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 08:57:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/84813#M17113</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-05-11T08:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/87396#M17576</link>
      <description>&lt;P&gt;Dear All ,&lt;/P&gt;&lt;P&gt;After many hours of remote sessions please find below the solution:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We had implemented the&amp;nbsp; ccl_preserve_src_MAC=1 This command changed the MAC address format to the old format (like R77.30).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After that the MAC moves of MAC address&amp;nbsp;0200.0000.0000&amp;nbsp;has been stopped and issue was resolved.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 07:51:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/87396#M17576</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2020-06-05T07:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/87422#M17594</link>
      <description>yeah, I had a case when upgrade from 77.30 to 80.20 and VMAC. In R80x the VMAC is calculated differently than older version and the problem I faced was internet traffic not coming back. 10 minutes after this we found that it's an ARP problem and the router facing Internet doesn't know what to do with the packets. Clearing the arp-table fixed the problem.</description>
      <pubDate>Fri, 05 Jun 2020 12:21:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/87422#M17594</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2020-06-05T12:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/94064#M18630</link>
      <description>&lt;P&gt;I am seeing just about the same issue. I don't ever recall setting the ccl_preserve_src_MAC parameter. I have three clusters connected to the same vlan. Two were R80.40 with JHFA Take 48, one was R80.20 with JHFA 134. It was almost entirely DNS traffic that exhibited this behavior (there was a very small amount of Identity Awareness traffic). Based on support recommendation, I upgraded everything to R80.40 with JHFA Take 67. I still have the issue with the DNS traffic, but no longer with the IA traffic. sk168076 describes a similar issue to what I'm seeing. I am waiting to hear back from support.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 20:11:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/94064#M18630</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2020-08-13T20:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/94448#M18677</link>
      <description>&lt;P&gt;Hello David ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had permanently solved this issue by&amp;nbsp;&lt;SPAN&gt;setting the ccl_preserve_src_MAC parameter on one cluster to 1 and to the other cluster to 0.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 06:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/94448#M18677</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2020-08-18T06:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster XL - MAC ADDRESS MOVEs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/94485#M18683</link>
      <description>&lt;P&gt;I fixed this by:&lt;/P&gt;&lt;P&gt;1. Setting the parameter ccl_preserve_src_MAC to 1 on each cluster member&lt;/P&gt;&lt;P&gt;2. Found that this did stop the 02:00:00:00:00:00 mac address from appearing, but I had another issue, which was an unbelievable amount of DNS traffic bouncing between cluster members&lt;/P&gt;&lt;P&gt;3. On a whim, I did a cpstop/cpstart on the standby member. This stopped the DNS traffic. I failed over and did the same on the active member&lt;/P&gt;&lt;P&gt;4. I&amp;nbsp;&lt;EM&gt;reverted&lt;/EM&gt; the parameter ccl_preserve_src_MAC back to 0 on both members, and the mac address 02:00:00:00:00:00 did not come back&lt;/P&gt;&lt;P&gt;So a bit of a mystery to me, but my gateways are in a better place.&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 12:05:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-XL-MAC-ADDRESS-MOVEs/m-p/94485#M18683</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2020-08-18T12:05:47Z</dc:date>
    </item>
  </channel>
</rss>

