<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Management traffic over bridge interface in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Management-traffic-over-bridge-interface/m-p/115377#M464</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I have deployment R80.20SP Security Group with two SGMs. The SG is running as bridge with some bridge interfaces and every bridge interfaces are consist of 2 VLAN Interfaces with no IP Address.&lt;/P&gt;&lt;P&gt;Traffic from SG's management interface to internet needs to pass SG bridge interface. The Anti-Virus &amp;amp; Anti-Bot are not able to update database and i found traffic dropped when coming in to bridge interface with following drop log "local interface spoofing" after running sk105899 &amp;amp; disable stateful inspection, no same drop message and appear the new log like this :&lt;/P&gt;&lt;P&gt;[1_02]@;1309518;[cpu_1];[fw4_5];fw_log_drop_ex: Packet proto=6 10.199.10.27:3461 1 -&amp;gt; 23.217.113.224:443 dropped by fw_handle_first_packet Reason: fwconn_key_ini t_links (INBOUND) failed;&lt;/P&gt;&lt;P&gt;Anyone have same experience or know the appropriate SK for this case ?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Apr 2021 11:39:02 GMT</pubDate>
    <dc:creator>Ilham_Syuhada</dc:creator>
    <dc:date>2021-04-06T11:39:02Z</dc:date>
    <item>
      <title>Management traffic over bridge interface</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Management-traffic-over-bridge-interface/m-p/115377#M464</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I have deployment R80.20SP Security Group with two SGMs. The SG is running as bridge with some bridge interfaces and every bridge interfaces are consist of 2 VLAN Interfaces with no IP Address.&lt;/P&gt;&lt;P&gt;Traffic from SG's management interface to internet needs to pass SG bridge interface. The Anti-Virus &amp;amp; Anti-Bot are not able to update database and i found traffic dropped when coming in to bridge interface with following drop log "local interface spoofing" after running sk105899 &amp;amp; disable stateful inspection, no same drop message and appear the new log like this :&lt;/P&gt;&lt;P&gt;[1_02]@;1309518;[cpu_1];[fw4_5];fw_log_drop_ex: Packet proto=6 10.199.10.27:3461 1 -&amp;gt; 23.217.113.224:443 dropped by fw_handle_first_packet Reason: fwconn_key_ini t_links (INBOUND) failed;&lt;/P&gt;&lt;P&gt;Anyone have same experience or know the appropriate SK for this case ?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 11:39:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Management-traffic-over-bridge-interface/m-p/115377#M464</guid>
      <dc:creator>Ilham_Syuhada</dc:creator>
      <dc:date>2021-04-06T11:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Management traffic over bridge interface</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Management-traffic-over-bridge-interface/m-p/115577#M467</link>
      <description>&lt;P&gt;Please open TAC request for this&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 12:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Management-traffic-over-bridge-interface/m-p/115577#M467</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-04-08T12:17:28Z</dc:date>
    </item>
  </channel>
</rss>

