<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VRRP Issue - Interface stuck in Init State in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179590#M29960</link>
    <description>&lt;P&gt;Hi Sijeel,&lt;/P&gt;
&lt;P&gt;Just so we can get better idea, can you please send below outputs from BOTH members?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob tablestat&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 01 May 2023 14:10:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-01T14:10:11Z</dc:date>
    <item>
      <title>VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179589#M29959</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We upgraded RAM in one of our&amp;nbsp; 4800 cluster , post-firewall reboot we noticed one of the interafce on standby member is in VRRP&amp;nbsp;initialize state.&lt;/P&gt;&lt;P&gt;We do see the arp entry of the active member on the standby member of that interface but don't see the arp entry of the standby member on the active member for the interface in the init state.&lt;/P&gt;&lt;P&gt;We have done the following workaround to mitigate this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We noticed that the virtual IP was changed automatically to the physical IP) which was later corrected.&lt;/LI&gt;&lt;LI&gt;Hotfix upgraded&lt;/LI&gt;&lt;LI&gt;Manual ARP entry added on active member&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Anti Spoofing disabled/enabled on the cluster&lt;/LI&gt;&lt;LI&gt;Firewall rebooted&lt;/LI&gt;&lt;LI&gt;Removing/adding interface from VRRP cluster.&lt;/LI&gt;&lt;LI&gt;Tried changing the Switch port which is connected to Stanby member interface.&lt;/LI&gt;&lt;LI&gt;The network team confirmed they are receiving Mac address for the standby interface on the switch end.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Further Analysis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Stanby member&amp;nbsp; interface eth1-01.xxxx is in vrrp initialize state however on active memebr&amp;nbsp; interface eth1-01.xxxx is in master state.&lt;/LI&gt;&lt;LI&gt;We unable to ping the active member interface from standby firewall and vice versa .&lt;/LI&gt;&lt;LI&gt;Able to receive the arp entries on stanby member&amp;nbsp; however we are not receiving arp entries from standby on active member&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;All other sub-interfaces are working perfectly fine.&lt;/LI&gt;&lt;LI&gt;Ideally, the route for the interface on&amp;nbsp; standby firewall should be directly connected(same as on active member and other interfaces ) however the best route is default route.&lt;/LI&gt;&lt;LI&gt;As per ASP drop logs, active member is dropping packets for stnaby member&amp;nbsp; due to local anti spoofing . the main reason is active memeber&amp;nbsp; has no entry in its arp table.&lt;/LI&gt;&lt;LI&gt;As per tcpdump logs on active member when we are trying to ping the remote end IP , its is getting ICMP echo message but it is not replying.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Is there something we are missing and what can bee done to resolve the issue. ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sijeel&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 13:51:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179589#M29959</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2023-05-01T13:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179590#M29960</link>
      <description>&lt;P&gt;Hi Sijeel,&lt;/P&gt;
&lt;P&gt;Just so we can get better idea, can you please send below outputs from BOTH members?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;cphaprob state&lt;/P&gt;
&lt;P&gt;cphaprob -a if&lt;/P&gt;
&lt;P&gt;cphaprob list&lt;/P&gt;
&lt;P&gt;cphaprob syncstat&lt;/P&gt;
&lt;P&gt;cphaprob roles&lt;/P&gt;
&lt;P&gt;cphaprob tablestat&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 14:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179590#M29960</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-01T14:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179614#M29978</link>
      <description>&lt;P&gt;Hi Andy,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the output. I have also added output for below command&lt;/P&gt;&lt;P&gt;show vrrp summary&lt;/P&gt;&lt;P&gt;show vrrp interface eth1-01.1491 ( Problematic interface on standby)&lt;/P&gt;&lt;P&gt;show route destination 163.166.149.35 (on standby )&lt;/P&gt;&lt;P&gt;show route destination 163.166.149.36 (on active )&lt;/P&gt;&lt;P&gt;show route direct&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sijeel&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 17:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179614#M29978</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2023-05-01T17:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179615#M29979</link>
      <description>&lt;P&gt;I have a call in 10 mins, but I quickly reviewed show interface command for problematic one and vmac and IDs looks correct to me. This happened AFTER upgrade you said?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 17:50:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179615#M29979</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-01T17:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179616#M29980</link>
      <description>&lt;P&gt;Can you also please send topology config, SPECIFICALLY for problematic interface? Please blur out any sensitive data.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 18:01:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179616#M29980</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-01T18:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179640#M29981</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20712i8068C7FD8104F0BD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Picture1.png" alt="Picture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Please find the topology&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 09:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179640#M29981</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2023-05-02T09:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179651#M29984</link>
      <description>&lt;P&gt;Thanks, but I more meant topology properties ONLY for interface you have issue with, if you double click on it. I think it would also be worth to contact TAC, so they can do remote session and see whats going on.&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 11:43:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179651#M29984</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-02T11:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179656#M29986</link>
      <description>&lt;P&gt;Hi .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the details , it been 2 months my team has raised a case with TAC but they arent able to identify the issue,&lt;/P&gt;&lt;P&gt;Do u have any idea what can be an issue as the connected route is not showing in the routing table? what could be a reason for such an issue,The link status is up for the interface&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 12:41:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179656#M29986</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2023-05-02T12:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179660#M29989</link>
      <description>&lt;P&gt;What type of NIC card is populated in the expansion slot?&lt;/P&gt;
&lt;P&gt;Anything odd in /var/log/messages ?&lt;/P&gt;
&lt;P&gt;Can you please confirm the version &amp;amp; jumbo that this gateway/cluster is installed with?&lt;/P&gt;
&lt;P&gt;(Note 4800 appliances are no longer supported).&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 13:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179660#M29989</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-05-02T13:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179665#M29990</link>
      <description>&lt;P&gt;Im really not sure, as looking at your screenshots, all seems correct to me. If TAC case has been ongoing for 2 months, did they at least escalate it? Sounds way too long for an issue like this...if connected route is missing, tells me something with the interface is wrong, since its not static route, cant be added manually. What steps did TAC provide you so far?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 13:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179665#M29990</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-02T13:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179690#M29993</link>
      <description>&lt;P&gt;Hi Chris,&amp;nbsp;&lt;/P&gt;&lt;P&gt;R80.40 +take 180 is installed . I dont see any odd messages also, the rest of the logical&amp;nbsp; interfaces on the physical port are working fine. the issue is with 1 logical interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Line card model : CPAP-4-1F Type 4 ports 1 gbe sfp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 14:00:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179690#M29993</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2023-05-02T14:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179693#M29994</link>
      <description>&lt;P&gt;the rest of the sub&amp;nbsp; interfaces are fine the issue is with this interafce. if this was ab issue with the physical interface then we would have faced the issue with all the sub-interfaces&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;.TAC has taken dumps , asked to update HF . Below steps have been done till now.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have noticed that virtual IP&amp;nbsp;163.166.149.33 was changed automatically to 163.166.149.36(physical IP) which was later corrected .&lt;/LI&gt;&lt;LI&gt;Hotfix upgraded&lt;/LI&gt;&lt;LI&gt;Manual ARP entry added on NOKFW35&lt;/LI&gt;&lt;LI&gt;Anti Spoofing disabled/enabled on cluster&lt;/LI&gt;&lt;LI&gt;Firewall rebooted&lt;/LI&gt;&lt;LI&gt;Removing/adding interface eth1-01.1491 from VRRP cluster.&lt;/LI&gt;&lt;LI&gt;Tried with changing Switch port which is connected with NOKFW36 eth1-01 interface .&lt;/LI&gt;&lt;LI&gt;Network team confirmed they are receiving mac address for vlan 1491 on the switch end.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As per zdebug&amp;nbsp;NOKFW35 is dropping packets for 163.166.149.36 due to local local&amp;nbsp; spoofing (screenshot attached)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 14:09:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179693#M29994</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2023-05-02T14:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179694#M29995</link>
      <description>&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Anti-Spoofing&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;drops indicate that the source IP address of the packet received on a certain interface is not a part of the defined interface's topology.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Local interface address spoofing&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;drops indicate that the Security Gateway / Cluster member received a packet with a source IP address that belongs to one of the local interfaces on the Security Gateway / Cluster member.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk115276" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk115276&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 14:14:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179694#M29995</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-02T14:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179778#M30018</link>
      <description>&lt;P&gt;Note Take 196 is the current recommended release and includes the following VRRP fixes for awareness.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vrrp.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20745i1C8BD0F075BC1AB8/image-size/large?v=v2&amp;amp;px=999" role="button" title="vrrp.png" alt="vrrp.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 03:31:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179778#M30018</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-05-03T03:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: VRRP Issue - Interface stuck in Init State</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179825#M30023</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48946"&gt;@Malik1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I think, as always,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;brings up a good point. To add to what he said, I would strongly consider also upgrade to R81.10, jumbo 94, if you can, as its super stable.&lt;/P&gt;
&lt;P&gt;Not sure if TAC made that recommendation yet.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 13:24:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VRRP-Issue-Interface-stuck-in-Init-State/m-p/179825#M30023</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-03T13:24:03Z</dc:date>
    </item>
  </channel>
</rss>

