<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251334#M42049</link>
    <description>&lt;P&gt;Hi Andy,&lt;BR /&gt;&lt;BR /&gt;yes - VMAC is checked.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jun 2025 12:54:28 GMT</pubDate>
    <dc:creator>Oliver_Matt</dc:creator>
    <dc:date>2025-06-16T12:54:28Z</dc:date>
    <item>
      <title>CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251331#M42046</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;I'm trying to use our old and unsupported Checkpoint 21800 Gateways as an analysis firewall in our Cisco ACI fabric. The gateways should be used to see the communication patterns between various devices. Based on the logs Cisco ACI contracts will be applied in the fabric. The gateways should only be used for initial analysis - no real world traffic.&lt;BR /&gt;&lt;BR /&gt;I've setup the gateways with the latest supported version 80.40 and the latest (recommended) Jumbo Take 211. ClusterXL was configured manually. CIsco recommends a one-armed firewall for this use case. Therefore the Cluster had been configured as follows:&lt;/P&gt;&lt;P&gt;fw-1 eth01 (cluster &amp;amp; sync) in aci pod 1 -&amp;gt; 10.200.90.4/29&lt;/P&gt;&lt;P&gt;fw-2 eth01 (cluster &amp;amp; sync) in aci pod 2 -&amp;gt; 10.200.90.5/29 (Active Node)&lt;/P&gt;&lt;P&gt;VMAC -&amp;gt; 10.200.90.6/29&lt;/P&gt;&lt;P&gt;Gateway -&amp;gt; 10.200.90.1/29&lt;BR /&gt;&lt;BR /&gt;Now I have this weird phenomenon:&lt;BR /&gt;&lt;BR /&gt;Ping checks under any linux environment (our linux jump host, cisco switches and routers) work flawlessly.&lt;BR /&gt;&lt;BR /&gt;Ping checks under Windows:&lt;BR /&gt;&lt;BR /&gt;Ping to 10.200.90.4 works perfect&lt;BR /&gt;Ping to 10.200.90.5 works perfect&lt;BR /&gt;Ping to 10.200.90.6 does not work&lt;BR /&gt;&lt;BR /&gt;After some wait time and no traffic to the above mentioned IPs it looks like this&lt;BR /&gt;&lt;BR /&gt;Ping to 10.200.90.4 works perfect&lt;BR /&gt;Ping to 10.200.90.5 does not work&lt;BR /&gt;Ping to 10.200.90.6&amp;nbsp;works perfect&lt;/P&gt;&lt;P&gt;and so on ...&lt;BR /&gt;&lt;BR /&gt;Did a wireshark trace under Windows and it showed that the Cluster is not responding from the VMAC IP 10.200.9.6 but instead responding from 10.200.9.5&lt;BR /&gt;&lt;BR /&gt;Verified under linux with fping&lt;/P&gt;&lt;P&gt;fping 10.200.90.4 10.200.90.5 10.200.90.6&lt;BR /&gt;10.200.90.4 is alive&lt;BR /&gt;10.200.90.5 is alive&lt;BR /&gt;&lt;STRONG&gt;[&amp;lt;- 10.200.90.5]10.200.90.6 is alive&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;means that fping received the ICMP echo reply from 10.200.90.6, but it came with a source address of 10.200.90.5.&lt;BR /&gt;&lt;BR /&gt;I've search all available SKs but without success. Any ideas from the experts how to solve or remediate this?&lt;BR /&gt;&lt;BR /&gt;Could "Cluster IP Addresses on Different Subnets" be a solution? But how to configure this on a one-armed-firewall?&lt;BR /&gt;&lt;BR /&gt;Any help is highly appreciated&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Kind regards&lt;BR /&gt;&lt;BR /&gt;Oliver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:32:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251331#M42046</guid>
      <dc:creator>Oliver_Matt</dc:creator>
      <dc:date>2025-06-16T12:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251332#M42047</link>
      <description>&lt;P&gt;Have you accounted for this or do I miss understand your scenario?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk26874" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk26874&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcontent.checkpoint.com/solutions?id=sk26874" target="_blank" rel="noopener"&gt;https://supportcontent.checkpoint.com/solutions?id=sk26874&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:56:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251332#M42047</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-16T12:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251333#M42048</link>
      <description>&lt;P&gt;Hey Oliver,&lt;/P&gt;
&lt;P&gt;Can you check if what I attached is checked or not?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:47:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251333#M42048</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-16T12:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251334#M42049</link>
      <description>&lt;P&gt;Hi Andy,&lt;BR /&gt;&lt;BR /&gt;yes - VMAC is checked.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:54:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251334#M42049</guid>
      <dc:creator>Oliver_Matt</dc:creator>
      <dc:date>2025-06-16T12:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251335#M42050</link>
      <description>&lt;P&gt;I would try uncheck it and see if it makes any difference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251335#M42050</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-16T12:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251336#M42051</link>
      <description>&lt;P&gt;Hi Chris,&lt;BR /&gt;&lt;BR /&gt;thx for the SKs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;sk102327 - Unable to ping cluster Virtual IP address from a cluster member in ClusterXL in High Availability and in Load Sharing modes. This is not my current situation.&lt;/P&gt;&lt;P&gt;sk26874 - this looks exactly like my problem - will investigate on that sk.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:56:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251336#M42051</guid>
      <dc:creator>Oliver_Matt</dc:creator>
      <dc:date>2025-06-16T12:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251337#M42052</link>
      <description>&lt;P&gt;Tried already several times without success. Will investigate in the sk26874 and post the outcome.&lt;BR /&gt;&lt;BR /&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:58:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251337#M42052</guid>
      <dc:creator>Oliver_Matt</dc:creator>
      <dc:date>2025-06-16T12:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251338#M42053</link>
      <description>&lt;P&gt;Apologies in my attempt to fix the old URL format I posted the incorrect SK identifier, hopefully the other is helpful!&lt;/P&gt;
&lt;P&gt;sk26874 - Cannot simultaneously ping Virtual IP address of the cluster and IP addresses of physical interfaces on cluster members from a remote host&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 13:02:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251338#M42053</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-16T13:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251339#M42054</link>
      <description>&lt;P&gt;Sounds like a good idea. Maybe also try zdebug command to see if any drops.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 12:59:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251339#M42054</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-16T12:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: CP21800 (R80.40 Jumbo T211) - reply not from Cluster IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251341#M42055</link>
      <description>&lt;P&gt;Hi Chris,&lt;BR /&gt;&lt;BR /&gt;again many thx - you've saved my day. sk26874 did the trick.&lt;BR /&gt;&lt;BR /&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 13:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP21800-R80-40-Jumbo-T211-reply-not-from-Cluster-IP/m-p/251341#M42055</guid>
      <dc:creator>Oliver_Matt</dc:creator>
      <dc:date>2025-06-16T13:14:21Z</dc:date>
    </item>
  </channel>
</rss>

