<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Asymmetry in routes in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174181#M29090</link>
    <description>&lt;P&gt;Did you involve TAC already ?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 08:24:07 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-03-09T08:24:07Z</dc:date>
    <item>
      <title>Asymmetry in routes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174178#M29089</link>
      <description>&lt;P&gt;We have a problem where we need to transfer traffic from the DMZ segment to another router.&lt;BR /&gt;We published a DMZ network via AntiDDoS systems through an R2 router. The firewall itself goes to the Internet through R1.&lt;BR /&gt;Traffic must be routed by the DMZ network through R2.&lt;BR /&gt;When we collect tcpdump we find a route asymmetry, that traffic comes from R2 and goes to R1.&lt;BR /&gt;We created a PBR so that traffic from the LAN goes one route and traffic to the Internet goes through router R2. I think I configured the PBR incorrectly. How to set PBR correctly, maybe there is a recommendation?&lt;/P&gt;&lt;P&gt;Additional information:&lt;BR /&gt;I set up NAT to the Internet for server x.x.x.100 through address x.x.189.14.&lt;BR /&gt;And also ProxyArp x.x.189.14 to aders 172.x.x.244&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Scheme.jpg" style="width: 866px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20002i4B2EE7234A12B3D0/image-dimensions/866x178?v=v2" width="866" height="178" role="button" title="Scheme.jpg" alt="Scheme.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBR.jpg" style="width: 774px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20000i4807BDCF0542C976/image-dimensions/774x393?v=v2" width="774" height="393" role="button" title="PBR.jpg" alt="PBR.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dump.jpg" style="width: 788px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20001i290DA704AB8B4524/image-dimensions/788x65?v=v2" width="788" height="65" role="button" title="dump.jpg" alt="dump.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 08:19:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174178#M29089</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2023-03-09T08:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetry in routes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174181#M29090</link>
      <description>&lt;P&gt;Did you involve TAC already ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 08:24:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174181#M29090</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-09T08:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetry in routes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174194#M29094</link>
      <description>&lt;P&gt;No, I did not start SR in TAC. I wanted to learn from my colleagues. TAS usually does not help with settings of new solutions&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 09:07:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174194#M29094</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2023-03-09T09:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetry in routes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174197#M29095</link>
      <description>&lt;P&gt;If you did follow documented processes (&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_Advanced_Routing_AdminGuide/Content/Topics-GARG/Policy-Based-Routing.htm" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;R81.20 Gaia Advanced Routing Administration Guide - &lt;STRONG&gt;Policy&lt;/STRONG&gt; &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;Routing&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;, &lt;A href="https://support.checkpoint.com/results/sk/sk100500" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk100500: &lt;STRONG&gt;Policy&lt;/STRONG&gt;-&lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;Routing&lt;/STRONG&gt; (PBR) on Gaia OS&lt;/SPAN&gt;&lt;/A&gt;) but it does not work as expected, you can ask TAC for help. They will not perform what CP Professional Services does but will assist you in resolving the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 09:28:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174197#M29095</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-09T09:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetry in routes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174199#M29096</link>
      <description>&lt;P&gt;We think the PBR is working, but may have misconfigured it. Either the traffic doesn't go to PBR and we need to write the policy differently&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 09:49:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetry-in-routes/m-p/174199#M29096</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2023-03-09T09:49:04Z</dc:date>
    </item>
  </channel>
</rss>

