<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP redunancy issue. in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/ISP-redunancy-issue/m-p/158904#M1704</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;- We are having 44k device, where isp redundancy is enabled.&lt;/P&gt;&lt;P&gt;- R80.20 SP GAIA OS.&lt;/P&gt;&lt;P&gt;ch02-02 &amp;gt; cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 192.0.*.* 33% ACTIVE FW-ch01-01&lt;BR /&gt;2 192.0.*.2 33% ACTIVE FW-ch01-02&lt;BR /&gt;3 192.0.*.3 33% ACTIVE FW-ch01-03&lt;BR /&gt;15 192.0.*.15 33% ACTIVE FW-ch02-01&lt;BR /&gt;16 (local) 192.0.*.16 33% ACTIVE FW-ch02-02&lt;BR /&gt;17 192.0.*.* 33% ACTIVE FW-ch02-03&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- cpstat fw shows isp redundnacy is proper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISP link table&lt;BR /&gt;---------------------&lt;BR /&gt;|Name|Status|Role |&lt;BR /&gt;---------------------&lt;BR /&gt;|NKN |OK |Primary|&amp;nbsp; ----&amp;gt; works well (eth1-02)&lt;BR /&gt;|BSNL|OK |Backup | ----&amp;gt; does not work.(eth1-01)&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;- All configuration seems fine, but the traffic through secondary link(BSNL) doesnot work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;traffic initiating frim checkpoint firewall&lt;/P&gt;&lt;P&gt;-&amp;nbsp;FW-ch02-02 &amp;gt; ping -I eth1-01 8.8.8.8&lt;BR /&gt;PING 8.8.8.8 (8.8.8.8) from 1**.2**.1**.**a eth1-01: 56(84) bytes of data.&lt;BR /&gt;From 1**.2**.1**.**a icmp_seq=1 Destination Host Unreachable&lt;BR /&gt;From 1**.2**.1**.**a icmp_seq=2 Destination Host Unreachable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW-ch02-02 &amp;gt; ping -I eth1-01 1**.2**.1**.**b&lt;BR /&gt;PING&amp;nbsp;1**.2**.1**.**b (1**.2**.1**.**b) from 1**.2**.1**.**a eth1-01: 56(84) bytes of data.&lt;BR /&gt;64 bytes from 1**.2**.1**.**b: icmp_seq=1 ttl=255 time=0.734 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- but when secondary isp directly connected to laptop, internet reachability is fine.&lt;/P&gt;&lt;P&gt;C:\Users\RS&amp;gt;tracert 8.8.8.8&lt;/P&gt;&lt;P&gt;Tracing route to dns.google [8.8.8.8]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;1 &amp;lt;1 ms &amp;lt;1 ms &amp;lt;1 ms 1**.2**.1**.**b&lt;BR /&gt;2 1 ms 1 ms 1 ms 172.24.221.154&lt;BR /&gt;3 * * * Request timed out.&lt;BR /&gt;4 * * * Request timed out.&lt;BR /&gt;5 11 ms 11 ms 11 ms 142.250.172.220&lt;BR /&gt;6 12 ms 12 ms 12 ms 172.253.68.113&lt;BR /&gt;7 14 ms 13 ms 13 ms 142.251.52.215&lt;BR /&gt;8 12 ms 12 ms 12 ms dns.google [8.8.8.8]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know what else needs to be checked here.&lt;/P&gt;&lt;P&gt;Or anyone faced similar kind of issue previously.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Shira&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 13:35:51 GMT</pubDate>
    <dc:creator>Shira</dc:creator>
    <dc:date>2022-10-06T13:35:51Z</dc:date>
    <item>
      <title>ISP redunancy issue.</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/ISP-redunancy-issue/m-p/158904#M1704</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;- We are having 44k device, where isp redundancy is enabled.&lt;/P&gt;&lt;P&gt;- R80.20 SP GAIA OS.&lt;/P&gt;&lt;P&gt;ch02-02 &amp;gt; cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 192.0.*.* 33% ACTIVE FW-ch01-01&lt;BR /&gt;2 192.0.*.2 33% ACTIVE FW-ch01-02&lt;BR /&gt;3 192.0.*.3 33% ACTIVE FW-ch01-03&lt;BR /&gt;15 192.0.*.15 33% ACTIVE FW-ch02-01&lt;BR /&gt;16 (local) 192.0.*.16 33% ACTIVE FW-ch02-02&lt;BR /&gt;17 192.0.*.* 33% ACTIVE FW-ch02-03&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- cpstat fw shows isp redundnacy is proper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISP link table&lt;BR /&gt;---------------------&lt;BR /&gt;|Name|Status|Role |&lt;BR /&gt;---------------------&lt;BR /&gt;|NKN |OK |Primary|&amp;nbsp; ----&amp;gt; works well (eth1-02)&lt;BR /&gt;|BSNL|OK |Backup | ----&amp;gt; does not work.(eth1-01)&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;- All configuration seems fine, but the traffic through secondary link(BSNL) doesnot work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;traffic initiating frim checkpoint firewall&lt;/P&gt;&lt;P&gt;-&amp;nbsp;FW-ch02-02 &amp;gt; ping -I eth1-01 8.8.8.8&lt;BR /&gt;PING 8.8.8.8 (8.8.8.8) from 1**.2**.1**.**a eth1-01: 56(84) bytes of data.&lt;BR /&gt;From 1**.2**.1**.**a icmp_seq=1 Destination Host Unreachable&lt;BR /&gt;From 1**.2**.1**.**a icmp_seq=2 Destination Host Unreachable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW-ch02-02 &amp;gt; ping -I eth1-01 1**.2**.1**.**b&lt;BR /&gt;PING&amp;nbsp;1**.2**.1**.**b (1**.2**.1**.**b) from 1**.2**.1**.**a eth1-01: 56(84) bytes of data.&lt;BR /&gt;64 bytes from 1**.2**.1**.**b: icmp_seq=1 ttl=255 time=0.734 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- but when secondary isp directly connected to laptop, internet reachability is fine.&lt;/P&gt;&lt;P&gt;C:\Users\RS&amp;gt;tracert 8.8.8.8&lt;/P&gt;&lt;P&gt;Tracing route to dns.google [8.8.8.8]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;1 &amp;lt;1 ms &amp;lt;1 ms &amp;lt;1 ms 1**.2**.1**.**b&lt;BR /&gt;2 1 ms 1 ms 1 ms 172.24.221.154&lt;BR /&gt;3 * * * Request timed out.&lt;BR /&gt;4 * * * Request timed out.&lt;BR /&gt;5 11 ms 11 ms 11 ms 142.250.172.220&lt;BR /&gt;6 12 ms 12 ms 12 ms 172.253.68.113&lt;BR /&gt;7 14 ms 13 ms 13 ms 142.251.52.215&lt;BR /&gt;8 12 ms 12 ms 12 ms dns.google [8.8.8.8]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know what else needs to be checked here.&lt;/P&gt;&lt;P&gt;Or anyone faced similar kind of issue previously.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Shira&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 13:35:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/ISP-redunancy-issue/m-p/158904#M1704</guid>
      <dc:creator>Shira</dc:creator>
      <dc:date>2022-10-06T13:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redunancy issue.</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/ISP-redunancy-issue/m-p/158927#M1705</link>
      <description>&lt;P&gt;What JHF are you on?&lt;BR /&gt;ISP Redundancy isn't supported until JHF 305.&lt;BR /&gt;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk155832" target="_blank"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk155832&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On a separate note, R80.20SP will be End of Support in Feb 2023, so hopefully you are planning an upgrade in the near future.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 16:27:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/ISP-redunancy-issue/m-p/158927#M1705</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-06T16:27:25Z</dc:date>
    </item>
  </channel>
</rss>

