<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic traffic to standby node is dropped by anti spoofing in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113163#M21242</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a situation, where some traffic towards a standby node in a cluster is dropped by anti spoofing.&lt;/P&gt;&lt;P&gt;ICMP and SNMP is being dropped by anti spoofing,&lt;/P&gt;&lt;P&gt;The traffic is being sent over vpn, and there are about 10-15 other locations with this set up, and it works just fine there.&lt;/P&gt;&lt;P&gt;Not sure if this is a version bug, it is running r80.20 with no jumbo. Other locations are mainly r80.30 and .40, with a few r80.10 and r77.30.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;fw ctl set int fwha_forw_packet_to_not_active has been set to 1 on both cluster members, and i can access the standby node on ssh without any issue, its just the other traffic being dropped. Traffic to the active node works just fine.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Has anyone seen anything similar before, and have any valuable input?&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Mar 2021 12:56:15 GMT</pubDate>
    <dc:creator>KM1895</dc:creator>
    <dc:date>2021-03-11T12:56:15Z</dc:date>
    <item>
      <title>traffic to standby node is dropped by anti spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113163#M21242</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a situation, where some traffic towards a standby node in a cluster is dropped by anti spoofing.&lt;/P&gt;&lt;P&gt;ICMP and SNMP is being dropped by anti spoofing,&lt;/P&gt;&lt;P&gt;The traffic is being sent over vpn, and there are about 10-15 other locations with this set up, and it works just fine there.&lt;/P&gt;&lt;P&gt;Not sure if this is a version bug, it is running r80.20 with no jumbo. Other locations are mainly r80.30 and .40, with a few r80.10 and r77.30.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;fw ctl set int fwha_forw_packet_to_not_active has been set to 1 on both cluster members, and i can access the standby node on ssh without any issue, its just the other traffic being dropped. Traffic to the active node works just fine.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Has anyone seen anything similar before, and have any valuable input?&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 12:56:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113163#M21242</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2021-03-11T12:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: traffic to standby node is dropped by anti spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113237#M21259</link>
      <description>&lt;P&gt;Am I understanding correctly that ICMP from an IP is getting dropped on anti-spoofing but SSH from the same IP is allowed?&lt;BR /&gt;That sounds like a bug.&lt;BR /&gt;I would ensure you have the latest recommended Jumbo Hotfix first.&lt;BR /&gt;If the problem still persists, raise a TAC case.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 20:59:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113237#M21259</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-11T20:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: traffic to standby node is dropped by anti spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113263#M21263</link>
      <description>&lt;P&gt;Could you please attach a screenshot of the drop or output from fw ctl zdebug command? I think that would be helpful in trying to figure out why this is happening.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 00:14:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113263#M21263</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-12T00:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: traffic to standby node is dropped by anti spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113288#M21268</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The icmp and snmp comes from the same address, and is dropped by antispoofing. The ssh is from another address, but that kinda proves the forward to not active parameter is working.&lt;/P&gt;&lt;P&gt;What i find really weird, is that i did some more troubleshooting today, and while the smartconsole logs clearly states antispoofing and drop, this never shows up on the cluster members when i do fw ctl zdebug drop on both of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im starting to lean towards some kind of bug here, and we are in the planning process of doing an upgrade to R80.40, which will hopefully solve this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 10:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/traffic-to-standby-node-is-dropped-by-anti-spoofing/m-p/113288#M21268</guid>
      <dc:creator>KM1895</dc:creator>
      <dc:date>2021-03-12T10:26:47Z</dc:date>
    </item>
  </channel>
</rss>

