<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: policy installation failure on cluster in lab environment in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119782#M22280</link>
    <description>&lt;P&gt;So i did a Wireshark capture and it looks like the mgmt server itself is sending reset packets to the gateways (i also see some resets from the gateways to the mgmt server) when im pushing the policy, im trying to attach the pcap files but it wont let me, how else do i share the results? For now ill share some screenshots.&lt;/P&gt;&lt;P&gt;The mgmt server ip is 10.3.0.2 and gtwy ips are 10.9.0.2 and 10.9.0.3&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29 (1).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11894i18C16354C26EBE0D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29 (1).png" alt="2021-05-29 (1).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29 (2).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11895i6B9C9B5E912F4B4A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29 (2).png" alt="2021-05-29 (2).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11896iB9F4669EFAD3C558/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29.png" alt="2021-05-29.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 30 May 2021 01:23:39 GMT</pubDate>
    <dc:creator>kb89</dc:creator>
    <dc:date>2021-05-30T01:23:39Z</dc:date>
    <item>
      <title>policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119746#M22273</link>
      <description>&lt;P&gt;So I'm running a lab on gns3 and practicing some cluster deployment:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-28 (1).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11878iE220C7F9784603A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-28 (1).png" alt="2021-05-28 (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see in the topology i have 2 gateways deployed as a cluster at the top right named "Gtwy-3" and "Gtwy-4" , the problem is i cannot install policy no matter how much i try, the mgmt server is at the bottom named as "Mgmt-1" with its eth 1 interface having an ip of 10.3.0.2, SIC is established (and is communicating) between the server and the gateways in cluster and there is no loss of communication between them as i have already checked in the logs that traffic is being allowed for port 18191 between the server and the gateways in cluster, i can also ping between them with no issues, what more do i need to check to get this to work? Also the "Switch-5" that is connected to this cluster as can be seen in the image has its gi 0/0, 0/1, 0/2 ports configured as trunk.&lt;/P&gt;&lt;P&gt;Error is as shown below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Inkedsnip_LI.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11880iBCC69C6488E5111C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Inkedsnip_LI.jpg" alt="Inkedsnip_LI.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've tried installing multiple times and get the same error, clearly there is something wrong and i don't know what it is. It shows tcp connectivity failure but i don't see anything that would suggest something like that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More screenshots:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 444px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11881i37C5E43F54D4A45A/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11882i07E6C8D2C0741DD1/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11883iD07446D538DEB044/image-size/large?v=v2&amp;amp;px=999" role="button" title="logs.PNG" alt="logs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cap.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11884iE0E6635703C2CFA5/image-size/large?v=v2&amp;amp;px=999" role="button" title="cap.PNG" alt="cap.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 22:57:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119746#M22273</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-28T22:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119749#M22274</link>
      <description>&lt;P&gt;So have you actually tested the TCP connectivity on that IP and port from the management server with telnet to verify the other end is answering?&lt;BR /&gt;Any tcpdumps done to see what the traffic is actually doing?&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 23:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119749#M22274</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-28T23:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119751#M22275</link>
      <description>&lt;P&gt;Try this, just to make sure...when you are installing the policy, run this on fw -&amp;gt; fw ctl zdebug + grep | grep 18191 and see if you get any drops. If you do, then that will give you good indication as to why. I do find it a bit odd that its giving errors, but it shows communicating. I will say, once, a long time ago, I worked with a customer who was seeing that exact behavior and it turned out to be routing problem.&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 01:10:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119751#M22275</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-29T01:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119769#M22276</link>
      <description>&lt;P&gt;ok will have to check that out.&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 19:51:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119769#M22276</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-29T19:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119770#M22277</link>
      <description>&lt;P&gt;ok will try that out and reply here&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 19:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119770#M22277</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-29T19:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119771#M22278</link>
      <description>&lt;P&gt;i do not think its a routing issue as i am able to ping from the mgmt to the gateways without any loss of packets and ive checked the routing myself and its correct but lets see.&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 19:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119771#M22278</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-29T19:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119777#M22279</link>
      <description>&lt;P&gt;So i did a Wireshark capture and it looks like the mgmt server itself is sending reset packets to the gateways (i also see some resets from the gateways to the mgmt server) when im pushing the policy, im trying to attach the pcap files but it wont let me, how else do i share the results? For now ill share some screenshots.&lt;/P&gt;&lt;P&gt;The mgmt server ip is 10.3.0.2 and gtwy ips are 10.9.0.2 and 10.9.0.3&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29 (1).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11891i4304EE78AB9373DA/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29 (1).png" alt="2021-05-29 (1).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29 (2).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11893i3BFDEC1573728987/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29 (2).png" alt="2021-05-29 (2).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11892i0E471FCD8D7FA397/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29.png" alt="2021-05-29.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 01:22:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119777#M22279</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-30T01:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119782#M22280</link>
      <description>&lt;P&gt;So i did a Wireshark capture and it looks like the mgmt server itself is sending reset packets to the gateways (i also see some resets from the gateways to the mgmt server) when im pushing the policy, im trying to attach the pcap files but it wont let me, how else do i share the results? For now ill share some screenshots.&lt;/P&gt;&lt;P&gt;The mgmt server ip is 10.3.0.2 and gtwy ips are 10.9.0.2 and 10.9.0.3&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29 (1).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11894i18C16354C26EBE0D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29 (1).png" alt="2021-05-29 (1).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29 (2).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11895i6B9C9B5E912F4B4A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29 (2).png" alt="2021-05-29 (2).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-05-29.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11896iB9F4669EFAD3C558/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-29.png" alt="2021-05-29.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 01:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119782#M22280</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-30T01:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119783#M22281</link>
      <description>&lt;P&gt;If i do telnet this is what i get:&lt;/P&gt;&lt;P&gt;[Expert@Mgmt-1:0]# telnet 10.9.0.2 18191&lt;BR /&gt;Trying 10.9.0.2...&lt;BR /&gt;Connected to 10.9.0.2.&lt;BR /&gt;Escape character is '^]'.&lt;/P&gt;&lt;P&gt;So looks like its successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 01:33:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119783#M22281</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-30T01:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119784#M22282</link>
      <description>&lt;P&gt;also i tried that command and it wasnt showing any drops.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 01:36:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119784#M22282</guid>
      <dc:creator>kb89</dc:creator>
      <dc:date>2021-05-30T01:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119785#M22283</link>
      <description>&lt;P&gt;Ok, so here is my conclusion...if you checked the routing and all looks fine (I will take your word for it) and when you are pushing the policy, you see tcp communication breaks on port 18191, but no drops based on command I gave you, there is obviously SOMETHING in the network causing this problem. Considering this is gns3, I played with it long time ago, so I have no clue in the world if anything there could be a culprit. Im sorry, wish I could help you more, but maybe someone else can chime in and give other suggestions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually, here is one thing I would personally do...issue constant ping from mgmt to both gateways and other way around and observe when it actually stops when you are pushing the policy.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 02:48:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119785#M22283</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-30T02:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: policy installation failure on cluster in lab environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119832#M22284</link>
      <description>&lt;P&gt;1) First off in the gateway object definitions for the two cluster members, make sure you are specifying the "nearest" or "facing" IP addresses for the two gateways to avoid asymmetric handling of control traffic through the cluster.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) On each gateway run the expert mode command &lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt;.&amp;nbsp; Run &lt;STRONG&gt;fw stat&lt;/STRONG&gt; to verify the gateways have no policy loaded.&lt;/P&gt;
&lt;P&gt;Now attempt your policy push to both gateways and wait for it to fail.&lt;/P&gt;
&lt;P&gt;Now run &lt;STRONG&gt;fw stat&lt;/STRONG&gt; again, did either gateway get the policy?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If yes&lt;/EM&gt;, then you have an anti-spoofing issue blocking subsequent policy installation and monitoring traffic on TCP ports 256 and 18191 respectively.&amp;nbsp; To verify run these commands on both gateways in expert mode to disable anti-spoofing enforcement on the fly:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw&amp;nbsp; ctl&amp;nbsp; set&amp;nbsp; int&amp;nbsp; fw_antispoofing_enabled&amp;nbsp; 0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw&amp;nbsp; ctl&amp;nbsp; set&amp;nbsp; int&amp;nbsp; sim_anti_spoofing_enabled&amp;nbsp; 0&amp;nbsp; -a&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If things suddenly start working now you need to fix your topology settings on the cluster object in SmartConsole, run &lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; and try to push policy again.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If no&lt;/EM&gt;, check the time and date on the SMS and gateways to ensure it is in sync.&amp;nbsp; Assuming it is you have some kind of routing or NAT problem in the intervening network.&amp;nbsp; You will need to determine if the issue is in the forward direction (SMS-&amp;gt;gateway) or return direction (gateway-&amp;gt;SMS).&amp;nbsp; One way to help determine this is to initiate a policy pull from the gateway instead of pushing it from the SMS by running the following command in expert mode on both gateways after a &lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw fetch&amp;nbsp;10.3.0.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Does a pull work but not a push or vice-versa?&lt;/P&gt;
&lt;P&gt;3) Run a &lt;STRONG&gt;tcptraceroute -p 18191&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;tcptraceroute -p 256&lt;/STRONG&gt; from the SMS to the gateways and then from the gateways to the SMS and compare the results.&amp;nbsp; Any asymmetry?&amp;nbsp; NAT occurring somewhere?&amp;nbsp; Dead hops blocking the traffic?&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 13:16:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/policy-installation-failure-on-cluster-in-lab-environment/m-p/119832#M22284</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-30T13:16:46Z</dc:date>
    </item>
  </channel>
</rss>

