<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can't ping gateway firewall even i install policy any to any in Off Topic</title>
    <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177540#M209</link>
    <description>&lt;P&gt;It is not your license, it is your topology definitions.&amp;nbsp; After installing policy to your gateway and things aren't working, run these commands:&lt;/P&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;fw ctl set int fw_antispoofing_enabled 0&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;sim feature anti_spoofing off; fwaccel off; fwaccel on&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Do things work now?&amp;nbsp; It is your topology definitions that have a problem, your issue has nothing to do with your license.&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 06 Apr 2023 11:53:26 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2023-04-06T11:53:26Z</dc:date>
    <item>
      <title>can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177331#M204</link>
      <description>&lt;P&gt;I lost communication with a gateway checkpoint open server R 77.30 after installed a simple policy where i allowed a service.&lt;/P&gt;&lt;P&gt;I can not ping even from the Lan network the to Lan interfaces.&lt;/P&gt;&lt;P&gt;Has&amp;nbsp;anyone faced this problem ?&lt;/P&gt;&lt;P&gt;After that i did fw unloadlocal&amp;nbsp; command to the gateway ,at this moment I&amp;nbsp; ping from the Lan of the branch the gateway of checkpoint at branch but not pass traffic to the center.&lt;/P&gt;&lt;P&gt;the route and all thing are ok. just gateway firewall not let traffic to pass from the LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;license of this gateway firewall has more than 10 years but is never expire does it have to do with the license?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 05:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177331#M204</guid>
      <dc:creator>ilirz</dc:creator>
      <dc:date>2023-04-05T05:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177334#M205</link>
      <description>&lt;P&gt;Are you attempting to ping from a directly connected subnet or elsewhere, was the gateway rebooted?&lt;/P&gt;
&lt;P&gt;The "fw unloadlocal" command prevents all traffic from passing through the Security Gateway (Cluster Member), because it disables the IP Forwarding in the Linux kernel on the Security Gateway (Cluster Member).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: R77.30 is no longer supported please refer:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.checkpoint.com/support-services/support-life-cycle-policy/#software-support" target="_blank"&gt;https://www.checkpoint.com/support-services/support-life-cycle-policy/#software-support&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 07:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177334#M205</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-05T07:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177336#M206</link>
      <description>&lt;P&gt;Thanks Chris, i ping frpm the lan network directly connected with checkpoint gateway.&lt;/P&gt;&lt;P&gt;I rebooted also but the same problem.&lt;/P&gt;&lt;P&gt;I have facing the same problem with 3 other gateway open server R 77.30 .&lt;/P&gt;&lt;P&gt;After policy install they not let traffic to pass and no logs for traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 07:16:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177336#M206</guid>
      <dc:creator>ilirz</dc:creator>
      <dc:date>2023-04-05T07:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177443#M207</link>
      <description>&lt;P&gt;You have an antispoofing problem, correct your interface and topology settings on your gateway object(s), run &lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; on the gateways then reinstall policy to them.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 15:56:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177443#M207</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-04-05T15:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177537#M208</link>
      <description>&lt;P&gt;Hi Timothy&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have faced the same problem with 3 checkpoint gateway open server R77.30.&lt;/P&gt;&lt;P&gt;At the moment that i installed new policy the communication with gateway lost&amp;nbsp; and even from local lan direct connected can not ping local checkpoint gateway.&lt;/P&gt;&lt;P&gt;Does it have to do with the license or the version r 77.30 because those security gateway have been licensed since 2012 and license say never.&lt;/P&gt;&lt;P&gt;I can not find the reason why it happen in a short time with three gateway after policy install&amp;nbsp; both of them are R 77.30 and licensed since 2012 only FW, VPN, IA?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 11:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177537#M208</guid>
      <dc:creator>ilirz</dc:creator>
      <dc:date>2023-04-06T11:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177540#M209</link>
      <description>&lt;P&gt;It is not your license, it is your topology definitions.&amp;nbsp; After installing policy to your gateway and things aren't working, run these commands:&lt;/P&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;fw ctl set int fw_antispoofing_enabled 0&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;sim feature anti_spoofing off; fwaccel off; fwaccel on&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Do things work now?&amp;nbsp; It is your topology definitions that have a problem, your issue has nothing to do with your license.&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 06 Apr 2023 11:53:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177540#M209</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-04-06T11:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177542#M210</link>
      <description>&lt;P&gt;Just do basic zdebug command on the fw when you have this issue...yea, R77.30 is not supported since few years back, but this has zero to do with the version : - ). Anyway, say if you are coming from 10.50.10.50 pinging the fw, when it fails, just ssh to the box and run below from expert mode:&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep 10.50.10.50&lt;/P&gt;
&lt;P&gt;the observe the drops, it would show you the behavior&lt;/P&gt;
&lt;P&gt;You can also do following -&amp;gt; fw monitor -e "accept host(10.50.10.50) and icmp;"&lt;/P&gt;
&lt;P&gt;Hope those help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 11:58:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177542#M210</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-06T11:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping gateway firewall even i install policy any to any</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177548#M211</link>
      <description>&lt;P&gt;Whilst I agree with &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Can you also confirm the JHF/Jumbo used with these gateways and do they use proxy-arp?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 12:10:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/can-t-ping-gateway-firewall-even-i-install-policy-any-to-any/m-p/177548#M211</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-06T12:10:40Z</dc:date>
    </item>
  </channel>
</rss>

