<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129137#M23558</link>
    <description>&lt;P&gt;RFC1918 does not include broadcast address&lt;/P&gt;&lt;P&gt;check&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104114&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,#Security%20Policy%20configuration" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104114&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,#Security%20Policy%20configuration&lt;/A&gt;&amp;nbsp;for the suggested firewall rules&lt;/P&gt;</description>
    <pubDate>Fri, 10 Sep 2021 18:33:25 GMT</pubDate>
    <dc:creator>JanVC</dc:creator>
    <dc:date>2021-09-10T18:33:25Z</dc:date>
    <item>
      <title>Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/128964#M23519</link>
      <description>&lt;P&gt;It appears that I may have uncovered a bug in my R80.30 lab environment after installing&amp;nbsp; R80.30 Gaia 2.6.18 Jumbo Hotfix Accumulator Security Gateway and Standalone GA Take 237.&lt;/P&gt;&lt;P&gt;After this JHA is installed the DHCP Relay stops working.&lt;/P&gt;&lt;P&gt;I have a desktop VLAN that hangs off one interface of my HA cluster and then a server VLAN that is off of another.&amp;nbsp; The server VLAN contains the DHCP server.&lt;/P&gt;&lt;P&gt;With take 237 installed the desktops simply are not able to retrieve IP addresses.&lt;/P&gt;&lt;P&gt;A packet capture on the DHCP server itself shows the DHCP Discover and Offer over and over.&amp;nbsp; A packet capture on the desktop in question shows only DHCP discovers being sent and the offer never being received.&lt;/P&gt;&lt;P&gt;I did a tcpdump on the Check Point interface directly connected to the VLAN the DHCP server is on and opened in wireshark.&amp;nbsp; I see Boot Requests and Boot Reply's.&lt;/P&gt;&lt;P&gt;When I do a tcpdump on the Check Point interface directly connected to the desktop VLAN I only see Boot Request's.&lt;/P&gt;&lt;P&gt;I have verified proper DHCP Relay configuration and security policy.&amp;nbsp; Neither of which has changed.&lt;/P&gt;&lt;P&gt;Looking through logs in SmartConsole I don't see anything blocked.&amp;nbsp; All of my rules are set to log.&lt;/P&gt;&lt;P&gt;I have a No NAT rule configured so traffic between these two subnets is not NAT'ed.&lt;/P&gt;&lt;P&gt;It appears that this may be a roach motel scenario.&lt;/P&gt;&lt;P&gt;On the gateway when I run a fwl ctl zdebug |+drop during the dhcp&amp;nbsp; process I see the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;@;39007;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=-1 ?:0 -&amp;gt; ?:0 dropped by fw ha_select_arp_packet Reason: CPHA replies to arp;&lt;BR /&gt;@;39481;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=17 192.168.0.30:67 -&amp;gt; 10.1.1.1:67 dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;&lt;BR /&gt;@;39549;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=17 192.168.0.30:67 -&amp;gt; 10.1.1.1:67 dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;&lt;BR /&gt;@;39652;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=17 192.168.0.30:67 -&amp;gt; 10.1.1.1:67 dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;&lt;BR /&gt;@;39788;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=17 192.168.0.30:67 -&amp;gt; 10.1.1.1:67 dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;&lt;BR /&gt;@;39893;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=-1 ?:0 -&amp;gt; ?:0 dropped by fwha_select_arp_packet Reason: CPHA replies to arp;&lt;BR /&gt;@;40232;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=17 192.168.0.30:67 -&amp;gt; 10.1.1.1:67 dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.0.30 is the IP of my DHCP server and 10.1.1.1 is the VIP of my cluster (the DHCP Relay)&lt;/P&gt;&lt;P&gt;When I uninstall JHA Take 237 DHCP works properly.&lt;/P&gt;&lt;P&gt;Has anyone else encountered this yet?&lt;/P&gt;&lt;P&gt;Does Check Point have a process to report a possible bug discovered in a lab environment with gateways that don't have support?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 15:42:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/128964#M23519</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-09-08T15:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/128979#M23526</link>
      <description>&lt;P&gt;Scenario 3 in this SK seems applicable:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909&lt;/A&gt;&lt;BR /&gt;You might try the workaround listed there.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 20:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/128979#M23526</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-08T20:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129131#M23553</link>
      <description>&lt;P&gt;I took a look at that SK but I am not sure.&amp;nbsp; I am not using SAML, remote access VPN, and 80.30 isn't specifically mentioned.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:16:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129131#M23553</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-09-10T18:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129132#M23554</link>
      <description>&lt;P&gt;Sorry, wrong SK.&lt;BR /&gt;Try:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97642&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97642&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:20:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129132#M23554</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-10T18:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129134#M23556</link>
      <description>&lt;P&gt;I believe this issue may be caused by incorrect firewall policy rules for DHCP and for whatever reason this worked before the JHA.&lt;/P&gt;&lt;P&gt;I have uploaded my DHCP rules and the two temp rules I created for testing that allow DHCP to work again.&lt;/P&gt;&lt;P&gt;DC-01_192.168.0.30 is the DHCP server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:26:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129134#M23556</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-09-10T18:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129136#M23557</link>
      <description>&lt;P&gt;Looks like you’re using the legacy services.&lt;BR /&gt;Recommend you follow the guidance here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104114&amp;amp;partition=Advanced&amp;amp;product=ClusterXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104114&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&lt;/A&gt;,&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:31:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129136#M23557</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-10T18:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129137#M23558</link>
      <description>&lt;P&gt;RFC1918 does not include broadcast address&lt;/P&gt;&lt;P&gt;check&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104114&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,#Security%20Policy%20configuration" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104114&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,#Security%20Policy%20configuration&lt;/A&gt;&amp;nbsp;for the suggested firewall rules&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:33:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129137#M23558</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2021-09-10T18:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129310#M23594</link>
      <description>&lt;P&gt;Yes, scenario # 3 in that SK indeed sounds like the issue I am encountering.&amp;nbsp; Unfortunately neither workaround resolved the issue.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 17:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129310#M23594</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-09-13T17:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129422#M23603</link>
      <description>&lt;P&gt;also see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk175206" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk175206&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 16:32:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129422#M23603</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2021-09-14T16:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129423#M23604</link>
      <description>&lt;P&gt;Just for interest sake and not sure if it's at all relevant, but &lt;SPAN&gt;sk175206 was released today - "DHCP relay issues after upgrading to R80.40 take_120".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Different versions but perhaps the same code change in both Jumbo's.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 16:33:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129423#M23604</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-09-14T16:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129425#M23605</link>
      <description>&lt;P&gt;Very interesting.&amp;nbsp; Thank you for sharing.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 16:51:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129425#M23605</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-09-14T16:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129436#M23607</link>
      <description>&lt;P&gt;This resolved my issue in 80.30 as well.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 18:51:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/129436#M23607</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-09-14T18:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug Gaia 2.6.18 JHA Security Gateway and Standalone GA Take 237 - DHCP Relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/131996#M23894</link>
      <description>&lt;P&gt;Thanks! I was getting nowhere with support on this after applying Take 125. This post lead me to the solution which required me moving my dhcp-request/dhcp-reply rules to the top of my ruleset. I had some "any" service rules above and the DHCP traffic was hitting those instead. Strange, that it had all worked fine before the Jumbo.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 15:01:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-bug-Gaia-2-6-18-JHA-Security-Gateway-and-Standalone-GA/m-p/131996#M23894</guid>
      <dc:creator>Robert_Sutton</dc:creator>
      <dc:date>2021-10-18T15:01:36Z</dc:date>
    </item>
  </channel>
</rss>

