<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot Ping firewall outside interface IPV6 from inside host in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46687#M9013</link>
    <description>&lt;P&gt;Hi Moderators,&lt;/P&gt;&lt;P&gt;In our production environment, we are deploying IPv6 addressing.&amp;nbsp; For testing purpose, we configured 1 server on Ipv6 address and configured Ipv6 addresses on firewall as well. The server is able to reach internet but cannot ping firewall outside IPv6 IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule allows all services from server to firewall.&lt;/P&gt;&lt;P&gt;IPV6 IP is also configured on gateway object.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are getting accept logs when view in smart tracker.&lt;/P&gt;&lt;P&gt;When i run fw ctl zdebug + drop. I get following:&lt;/P&gt;&lt;P&gt;dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked&amp;nbsp;&lt;SPAN&gt;sk86984 but this for custom port.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kindly please guide.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2019 06:46:10 GMT</pubDate>
    <dc:creator>Ankur_Datta</dc:creator>
    <dc:date>2019-03-13T06:46:10Z</dc:date>
    <item>
      <title>Cannot Ping firewall outside interface IPV6 from inside host</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46687#M9013</link>
      <description>&lt;P&gt;Hi Moderators,&lt;/P&gt;&lt;P&gt;In our production environment, we are deploying IPv6 addressing.&amp;nbsp; For testing purpose, we configured 1 server on Ipv6 address and configured Ipv6 addresses on firewall as well. The server is able to reach internet but cannot ping firewall outside IPv6 IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule allows all services from server to firewall.&lt;/P&gt;&lt;P&gt;IPV6 IP is also configured on gateway object.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are getting accept logs when view in smart tracker.&lt;/P&gt;&lt;P&gt;When i run fw ctl zdebug + drop. I get following:&lt;/P&gt;&lt;P&gt;dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked&amp;nbsp;&lt;SPAN&gt;sk86984 but this for custom port.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kindly please guide.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 06:46:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46687#M9013</guid>
      <dc:creator>Ankur_Datta</dc:creator>
      <dc:date>2019-03-13T06:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping firewall outside interface IPV6 from inside host</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46701#M9020</link>
      <description>have you checked the ND routing on your gateways? &lt;BR /&gt;cross check the ::/masking on both. it is very usual mistake mate.&lt;BR /&gt;make sure that apart from icmp also tcp/udp packets flies in between the gateways (check the zdebug/logs (eld if needed) as well as fw monitor cpd/fwm traffic inter-crossing. ipv6 is tricky on CP and everywone knows that but believe me or not it is working &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Wed, 13 Mar 2019 08:15:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46701#M9020</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-13T08:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping firewall outside interface IPV6 from inside host</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46706#M9021</link>
      <description>and what about this SK ?&lt;BR /&gt;&lt;BR /&gt;sk102390: IPv6 ICMP traffic is dropped by "0 - Implied Rules"</description>
      <pubDate>Wed, 13 Mar 2019 08:27:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46706#M9021</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-13T08:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping firewall outside interface IPV6 from inside host</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46719#M9028</link>
      <description>&lt;P&gt;Hi Jerry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Routing is fine on gateway. The inside host is in a connected subnet. I can reach host Ipv6 IP from firewall. I will check the masking.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding SK, its for gateway till R77.20.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our gateway version is R77.30.&lt;/P&gt;&lt;P&gt;One more thing we found today. If we remove IPv6 and keep IPV4 only address. Server can't ping standby GW outside interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;traffic is going to primary firewall and then doesn't go out of outside interface.&lt;/P&gt;&lt;P&gt;in Fw monitor i am getting i &amp;amp; I.&amp;nbsp;&lt;/P&gt;&lt;P&gt;tcpdump shows echo request received on inside interface but no leaving traffic from outside interface.&lt;/P&gt;&lt;P&gt;logs says firewall is accepting the traffic.&lt;/P&gt;&lt;P&gt;Fw ctl zdebug + drop gives another reason for packet drop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;dropped by fwchain_reject_mtu Reason: rejected&lt;/P&gt;&lt;P&gt;I checked&amp;nbsp;&lt;SPAN&gt;sk119154, symptoms are same but we are not using VPN blade. Only firewall blade is being used.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 09:26:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46719#M9028</guid>
      <dc:creator>Ankur_Datta</dc:creator>
      <dc:date>2019-03-13T09:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping firewall outside interface IPV6 from inside host</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46997#M9114</link>
      <description>&lt;P&gt;Anyone please guide about this error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dropped by fwchain_reject_mtu Reason: rejected&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 06:29:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/46997#M9114</guid>
      <dc:creator>Ankur_Datta</dc:creator>
      <dc:date>2019-03-15T06:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping firewall outside interface IPV6 from inside host</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/47004#M9117</link>
      <description>sk119154&lt;BR /&gt;&lt;BR /&gt;Symptoms&lt;BR /&gt;&lt;BR /&gt;•Cannot connect to the Standby member from a non-local subnet (source and destination are not on the same subnet). &lt;BR /&gt;•Connecting to the Standby member from a local subnet (source and destination are on the same subnet) works. &lt;BR /&gt;•When running # fw ctl zdebug drop on the Standby member, the following line can be seen:&lt;BR /&gt; ;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 2.2.2.2:443 -&amp;gt; 20.0.0.1:58522 dropped by fwchain_reject_mtu Reason: rejected;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cause&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Environment: VPN Visitor Mode is enabled on port 443.&lt;BR /&gt;&lt;BR /&gt;When Visitor Mode is enabled, the Standby member will reject all traffic sent to it via the Visitor Mode port.&lt;BR /&gt;&lt;BR /&gt;By default, Visitor Mode is enabled on port 443.&lt;BR /&gt;</description>
      <pubDate>Fri, 15 Mar 2019 08:15:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cannot-Ping-firewall-outside-interface-IPV6-from-inside-host/m-p/47004#M9117</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-15T08:15:52Z</dc:date>
    </item>
  </channel>
</rss>

