<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing Problem in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214897#M10672</link>
    <description>&lt;P&gt;First, uncheck "Show inactive routes" so we can see only the active routes. &amp;nbsp;If you have inactive routes, then you have a routing protocol administrative-distance (metric) problem. &amp;nbsp;Connected routes override static routes, which override all other routes (unless you have changed the protocol ranking manually).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2024 14:14:30 GMT</pubDate>
    <dc:creator>Duane_Toler</dc:creator>
    <dc:date>2024-05-21T14:14:30Z</dc:date>
    <item>
      <title>Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214893#M10671</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have the topology in the picture, and the L2TP 192.168.18.100 route is not working, and I can't open the web page. Additionally, the route to IP 10.0.219.246 is not working. I have the PCs in my office that go through the firewall via a Mikrotik port. Strangely, the SAS page on VLAN 249 with IP 10.0.200.249 opens. The other page on VLAN 219, 10.0.219.246:9082, does not open. Both are on the same logic and pass through the same router; only the VLAN changes. Could it be blocked at the port? Is an allow policy needed? The general firewall policy is to allow communication between internal interfaces. I haven't made it strict because I know it blocks everything. The 192.168.18.100:8080 that is blocked seems like the same problem. Maybe the ports need to be allowed? My PC, which goes through the Mikrotik, opens the web page with VPN. However, the PC that goes through the firewall doesn't open it. I suspect the ports are being blocked.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 13:34:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214893#M10671</guid>
      <dc:creator>lcako</dc:creator>
      <dc:date>2024-05-21T13:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214897#M10672</link>
      <description>&lt;P&gt;First, uncheck "Show inactive routes" so we can see only the active routes. &amp;nbsp;If you have inactive routes, then you have a routing protocol administrative-distance (metric) problem. &amp;nbsp;Connected routes override static routes, which override all other routes (unless you have changed the protocol ranking manually).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 14:14:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214897#M10672</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-05-21T14:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214898#M10673</link>
      <description>&lt;P&gt;i put microtik instead of firewall, and it worked with the same routing method. when i put sg1575 firewall it doesnt work. I did your solution and i dont have inactive routes and the problem is still the same&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 14:22:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214898#M10673</guid>
      <dc:creator>lcako</dc:creator>
      <dc:date>2024-05-21T14:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214899#M10674</link>
      <description>&lt;P&gt;Have you checked the gateway firewall logs? &amp;nbsp;You may have an anti-spoofing problem on some interface. &amp;nbsp; I also see your default route is via a DMZ VLAN interface; this is unusual. &amp;nbsp;This interface would need to be an External (Internet) topology for anti-spoofing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 14:32:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214899#M10674</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-05-21T14:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214901#M10675</link>
      <description>&lt;P&gt;what is strange too is that ip from route in line 9 cam be pinged. also line 8 can be pinged. line 10 , 7 and 6 cannot be pinged.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 14:38:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214901#M10675</guid>
      <dc:creator>lcako</dc:creator>
      <dc:date>2024-05-21T14:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214902#M10676</link>
      <description>&lt;P&gt;Which version/build firmware is this Spark device installed with?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 15:17:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214902#M10676</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-05-21T15:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214904#M10681</link>
      <description>&lt;P&gt;After you check the logs and anti-spoofing, check the interior router and make sure it has valid return routes via the SMB 1575 gateway. &amp;nbsp;How is your L2TP client connecting to the network; is it connecting via the SG1575 external interface, or something else? &amp;nbsp;Check the active routes on the L2TP client to see if the routes are being installed correctly. &amp;nbsp;You can try traceroute, but this may be ambiguous for an L2TP client, so don't fall into a trap of troubleshooting the wrong problem if traceroute fails. &amp;nbsp;However, if it works, then that is excellent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If line 9 can be pinged, but others cannot, check the internal router to make sure it has interfaces in "Up" state for those VLANs. &amp;nbsp;Check the hosts on those VLANs to make sure they can send return traffic via the internal router for your L2TP client (either default route, or something else).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 14:42:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214904#M10681</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-05-21T14:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214960#M10684</link>
      <description>&lt;P&gt;i reconfigured them again and i tried to&amp;nbsp;removed static routes , config OSPF&amp;nbsp;from firewall device/system/tools and i ping all of these ip from LAN 241 i cannot open them. from vlan of pc 241 in firewall i cannot open these ip , mostly web but from firewall i can ping them.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 07:00:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214960#M10684</guid>
      <dc:creator>lcako</dc:creator>
      <dc:date>2024-05-22T07:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214961#M10685</link>
      <description>&lt;P&gt;i reconfigured them again and i tried to&amp;nbsp;removed static routes , config OSPF&amp;nbsp;from firewall device/system/tools and i ping all of these ip from LAN 241 i cannot open them. from vlan of pc 241 in firewall i cannot open these ip , mostly web but from firewall i can ping them&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 07:00:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214961#M10685</guid>
      <dc:creator>lcako</dc:creator>
      <dc:date>2024-05-22T07:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214972#M10686</link>
      <description>&lt;P&gt;If a path using L2TP is in the mix have you configured MSS clamping (&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk121114" target="_self"&gt;sk121114&lt;/A&gt;) at all&lt;/SPAN&gt;?&lt;/P&gt;
&lt;P&gt;Again, are you running &lt;A href="https://support.checkpoint.com/results/sk/sk181080" target="_self"&gt;R81.10.10&lt;/A&gt; firmware (build &lt;SPAN&gt;996002906&lt;/SPAN&gt;) or something else?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/Anti-Spoofing-detection/m-p/207137#M10380" target="_blank" rel="noopener"&gt;Solved: Anti-Spoofing detection - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 09:57:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214972#M10686</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-05-22T09:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214976#M10687</link>
      <description>&lt;P&gt;i did ospf routing and i found the solution&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 10:10:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214976#M10687</guid>
      <dc:creator>lcako</dc:creator>
      <dc:date>2024-05-22T10:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214987#M10688</link>
      <description>&lt;P&gt;Ok great - what was the solution so others can understand the problem/cause better?&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 12:04:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/214987#M10688</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-05-22T12:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/225794#M11361</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/101665"&gt;@lcako&lt;/a&gt;, could you please share the solution, it will help us.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 15:04:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Problem/m-p/225794#M11361</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-05T15:04:26Z</dc:date>
    </item>
  </channel>
</rss>

