<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro Dual site sync troubleshooting in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-site-sync-troubleshooting/m-p/242874#M3213</link>
    <description>&lt;P&gt;The SGM sync packets for SG1 will traverse VLAN 3801 on the site_sync interface(s). Check the switching layer for any issues around duplicate MACs and the switch suspending ports.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 03:25:01 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2025-03-04T03:25:01Z</dc:date>
    <item>
      <title>Maestro Dual site sync troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-site-sync-troubleshooting/m-p/242402#M3207</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I am having issues with Maestro Dual site (Single MHO) synchronization through external L2 switches. Since the customer does not want to use QinQ I turned it off, then we created trunk ports on the switches and we allowed VLAN IDs 3951 for MHO and 3801+ for the SGs. The MHO sync works fine, but the SGs sync does not work and I do not know if it is some kind of issue on the MHO or on the switches.&lt;BR /&gt;IF I ping from SGM 1_1 (192.0.2.1) to SGM 2_1 on the sync network: ping 192.0.2.15 then there is no answer and I can see in tcpdump that the SGM 1_1 is ARP asking for MAC of 192.0.2.15:&lt;/P&gt;&lt;P&gt;[Expert@FW-JUST_EXT-ch01-01:0]# ping 192.0.2.15&lt;BR /&gt;PING 192.0.2.15 (192.0.2.15) 56(84) bytes of data.&lt;BR /&gt;From 192.0.2.1 icmp_seq=1 Destination Host Unreachable&lt;BR /&gt;From 192.0.2.1 icmp_seq=2 Destination Host Unreachable&lt;BR /&gt;From 192.0.2.1 icmp_seq=3 Destination Host Unreachable&lt;BR /&gt;From 192.0.2.1 icmp_seq=4 Destination Host Unreachable&lt;/P&gt;&lt;P&gt;[Expert@FW-JUST_EXT-ch01-01:0]# tcpdump -nni Sync host 192.0.2.15&lt;BR /&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on Sync, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;BR /&gt;16:51:10.486344 ARP, Request who-has 192.0.2.15 tell 192.0.2.1, length 28&lt;BR /&gt;16:51:11.488348 ARP, Request who-has 192.0.2.15 tell 192.0.2.1, length 28&lt;BR /&gt;16:51:13.485469 ARP, Request who-has 192.0.2.15 tell 192.0.2.1, length 28&lt;BR /&gt;16:51:14.486357 ARP, Request who-has 192.0.2.15 tell 192.0.2.1, length 28&lt;/P&gt;&lt;P&gt;However I cannot find any of those ARPs on the MHO itself to verify that those ARP packets are leaving the MHO. Is there a way how to verify that the sync packets from SGM 1_1 are leaving the MHO1 via the external sync and are sent to MHO2 (SGM 2_1) through the switches?&lt;BR /&gt;The packets should be leaving the MHO with the 192.0.2.x source IP or is MHO sending even the SG sync packets with the MHO sync IP 203.0.113.x?&lt;/P&gt;&lt;P&gt;Thank you&lt;BR /&gt;Arnost&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 12:45:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-site-sync-troubleshooting/m-p/242402#M3207</guid>
      <dc:creator>Arnost_Odvalil</dc:creator>
      <dc:date>2025-02-26T12:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Dual site sync troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-site-sync-troubleshooting/m-p/242874#M3213</link>
      <description>&lt;P&gt;The SGM sync packets for SG1 will traverse VLAN 3801 on the site_sync interface(s). Check the switching layer for any issues around duplicate MACs and the switch suspending ports.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 03:25:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-site-sync-troubleshooting/m-p/242874#M3213</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-03-04T03:25:01Z</dc:date>
    </item>
  </channel>
</rss>

