<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hosts and DNS Configuration for a 7000 appliance in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210046#M34778</link>
    <description>&lt;P&gt;We have two 7000 security gateways configured as active / standby. When we make the standby gateway active, our end devices won't gate internet access but the gateway itself pings google.com. And now we have cross checked both gateway configurations and found a major difference between HOSTS &amp;amp; DNS TAB.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;STANDBY Gateway (PROBLEMATIC GATEWAY)&lt;BR /&gt;&lt;BR /&gt;CP-STANDBY&amp;gt; show host names&lt;BR /&gt;Host Name IP Address&lt;BR /&gt;CP-STANDBY&amp;nbsp; 7.7.7.3&lt;BR /&gt;localhost 127.0.0.1&lt;BR /&gt;localhost ::1&lt;BR /&gt;&lt;BR /&gt;ACTIVE Gateway (WORKING GATEWAY)&lt;BR /&gt;&lt;BR /&gt;CP-ACTIVE&amp;gt; show host names&lt;BR /&gt;Host Name IP Address&lt;BR /&gt;CP-ACTIVE 10.100.100.10&lt;BR /&gt;localhost 127.0.0.1&lt;BR /&gt;localhost ::1&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NOTE THAT:&lt;/STRONG&gt; &lt;EM&gt;&lt;STRONG&gt;7.7.7.3 is the management IP address for that gateway.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;The Real IP of 10.100.100.11 of the PROBLEMATIC GATEWAY.&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;10.100.100.10 is the Gateway IP Address for ACTIVE GATEWAY.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;7.7.7.2 is the management IP address of the ACTIVE GATEWAY.&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Which configuration of HOSTS is correct?&lt;BR /&gt;&lt;BR /&gt;This is an urgent issue and we need your support.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 30 Mar 2024 11:01:50 GMT</pubDate>
    <dc:creator>gemechisd</dc:creator>
    <dc:date>2024-03-30T11:01:50Z</dc:date>
    <item>
      <title>Hosts and DNS Configuration for a 7000 appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210046#M34778</link>
      <description>&lt;P&gt;We have two 7000 security gateways configured as active / standby. When we make the standby gateway active, our end devices won't gate internet access but the gateway itself pings google.com. And now we have cross checked both gateway configurations and found a major difference between HOSTS &amp;amp; DNS TAB.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;STANDBY Gateway (PROBLEMATIC GATEWAY)&lt;BR /&gt;&lt;BR /&gt;CP-STANDBY&amp;gt; show host names&lt;BR /&gt;Host Name IP Address&lt;BR /&gt;CP-STANDBY&amp;nbsp; 7.7.7.3&lt;BR /&gt;localhost 127.0.0.1&lt;BR /&gt;localhost ::1&lt;BR /&gt;&lt;BR /&gt;ACTIVE Gateway (WORKING GATEWAY)&lt;BR /&gt;&lt;BR /&gt;CP-ACTIVE&amp;gt; show host names&lt;BR /&gt;Host Name IP Address&lt;BR /&gt;CP-ACTIVE 10.100.100.10&lt;BR /&gt;localhost 127.0.0.1&lt;BR /&gt;localhost ::1&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NOTE THAT:&lt;/STRONG&gt; &lt;EM&gt;&lt;STRONG&gt;7.7.7.3 is the management IP address for that gateway.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;The Real IP of 10.100.100.11 of the PROBLEMATIC GATEWAY.&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;10.100.100.10 is the Gateway IP Address for ACTIVE GATEWAY.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;7.7.7.2 is the management IP address of the ACTIVE GATEWAY.&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Which configuration of HOSTS is correct?&lt;BR /&gt;&lt;BR /&gt;This is an urgent issue and we need your support.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 11:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210046#M34778</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-03-30T11:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Hosts and DNS Configuration for a 7000 appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210076#M34783</link>
      <description>&lt;P&gt;The way I always know that command is that it would show whatever IP is tied to eth0, ie external interface...I checked 2 clients' firewalls and thats what it shows. See example from my Azure lab:&lt;/P&gt;
&lt;P&gt;master:&lt;/P&gt;
&lt;P&gt;cpazurecluster1&amp;gt; show host names&lt;BR /&gt;Host Name IP Address&lt;BR /&gt;cpazurecluster1 10.5.0.4&lt;BR /&gt;localhost 127.0.0.1&lt;BR /&gt;localhost ::1&lt;BR /&gt;cpazurecluster1&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;backup:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cpazurecluster2&amp;gt; show host names&lt;BR /&gt;Host Name IP Address&lt;BR /&gt;cpazurecluster2 10.5.0.5&lt;BR /&gt;localhost 127.0.0.1&lt;BR /&gt;localhost ::1&lt;BR /&gt;cpazurecluster2&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25092i549EB5327DCCEAE5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 16:17:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210076#M34783</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-30T16:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Hosts and DNS Configuration for a 7000 appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210077#M34784</link>
      <description>&lt;P&gt;To add a comment I forgot before...IF ip addresses are right, do "get interfaces" in smart console, but WITHOUT topology, make sure it fetches correct info, install policy, do failover test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 16:37:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210077#M34784</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-30T16:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Hosts and DNS Configuration for a 7000 appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210095#M34787</link>
      <description>&lt;P&gt;i'm not sure the hosts are related, but in order to investigate what is going on you can do the following:&lt;/P&gt;
&lt;P&gt;first, i assume your cluster is in active/standby mode (healthy cluster).&lt;/P&gt;
&lt;P&gt;1. prepare some workstation for testing&lt;/P&gt;
&lt;P&gt;2. switch between cluster members&lt;/P&gt;
&lt;P&gt;3. now from the workstation, run: ping 9.9.9.9&lt;/P&gt;
&lt;P&gt;3.A if the ping doesn't work (no replies) do this:&lt;/P&gt;
&lt;P&gt;A. run on both members the following command:&lt;/P&gt;
&lt;P&gt;fw monitor -F "0,0,9.9.9.9,0,0" -F "9.9.9.9,0,0,0,0"&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk30583" target="_blank" rel="noopener"&gt;(https://support.checkpoint.com/results/sk/sk30583&lt;/A&gt;)&lt;BR /&gt;the filter used here with 9.9.9.9 is an example of internet address, and i'm filtering it once on the destination side (original connection), and once on the source side (for reply).&lt;BR /&gt;you can replace 9.9.9.9 with any internet ip address you want to test.&lt;BR /&gt;&lt;BR /&gt;*the reason i tell you to run on both, it to verify that the traffic from workstation to internet and the replies are flowing only through the new active member, and not via the old active member (such as when the old ARP is stuck on some network device). once that's verified you can run only on the active member for the next tests.&lt;/P&gt;
&lt;P&gt;B. copy all the outputs from both members to notepad, note which is active and which is standby.&lt;/P&gt;
&lt;P&gt;3B. if the above ping worked, try to ping something that needs resolving, like ping cnn.co&lt;/P&gt;
&lt;P&gt;if that doesn't work, figure out who is configured on the workstation as DNS server, and we will go from there:&lt;/P&gt;
&lt;P&gt;A. if it's internal server, try to look for logs from that dns server to the internet, or between the workstations to this dns server.&lt;/P&gt;
&lt;P&gt;B. you also can use the same fw monitor with custom filter to this dns server traffic).&lt;/P&gt;
&lt;P&gt;4. if the ping to domains also works and you have resolving, but you can't open http/https pages than do the same fw monitor above and this time open browser and brose to&amp;nbsp;&amp;nbsp;&lt;A href="http://9.9.9.9" target="_blank" rel="noopener"&gt;http://9.9.9.9&lt;/A&gt;&amp;nbsp;or &lt;A href="https://9.9.9.9" target="_blank" rel="noopener"&gt;https://9.9.9.9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;copy all outputs and paste here.&lt;/P&gt;
&lt;P&gt;break fw monitor with ctrl+C&lt;/P&gt;
&lt;P&gt;once you find what exactly doesn't work, you can also run fw ctl zdebug + drop on the active member let it run for 30sec, while you simulate the non working connection, copy and paste the output here.&lt;BR /&gt;break fw ctl zdebug + drop with ctrl+c&lt;BR /&gt;and then run: fw ctl debug 0 to reset the debugging.&lt;BR /&gt;(notice the zdebug consume CPU, so make sure you do that on proper maintenance window)&lt;/P&gt;
&lt;P&gt;in addition to that looks for the logs for the non working connections (some for example), you can also take screenshots and paste here.&lt;/P&gt;
&lt;P&gt;mention your workstation IP. and the non working connection you have tested while running fw monitor or debug.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 10:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hosts-and-DNS-Configuration-for-a-7000-appliance/m-p/210095#M34787</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-03-31T10:09:19Z</dc:date>
    </item>
  </channel>
</rss>

