<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB and Reboot in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219037#M10934</link>
    <description>&lt;P&gt;So, when using netstat -rn the result is the same as netstat -r when things are not working:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;netstat -r
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
default         113.113.192.1   0.0.0.0         UG        0 0          0 WAN
10.0.0.0        192.168.4.10    255.0.0.0       UG        0 0          0 vpnt10
192.168.3.0     *               255.255.255.0   U         0 0          0 LAN1
192.168.4.10    *               255.255.255.255 UH        0 0          0 vpnt10
113.113.192.0   *               255.255.224.0   U         0 0          0 WAN
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What DNS talking we about here? Is it my ISP DNS?&lt;/P&gt;
&lt;P&gt;I could not resolve "ua-113-113-192-":&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;nslookup ua-113-113-192- 8.8.8.8
Server:  dns.google
Address:  8.8.8.8

*** dns.google can't find ua-113-113-192-: Non-existent domain&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on SMB, DNS is configured like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; show dns
mode:                         global
proxy:                        on
resolving:                    on
primary ipv4-address:         10.8.0.12
secondary ipv4-address:       8.8.8.8
tertiary ipv4-address:
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where 10.8.0.12 is the our internal&amp;nbsp; DNS server behind the central gateway&lt;/P&gt;
&lt;P&gt;So,When the issue occurs, no pings can reach any destination:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8): 56 data bytes
^C
--- 8.8.8.8 ping statistics ---
6 packets transmitted, 0 packets received, 100% packet loss
Gateway-ID-7FB7C2DC&amp;gt; ping google.com
ping: bad address 'google.com'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2024 18:30:22 GMT</pubDate>
    <dc:creator>Moudar</dc:creator>
    <dc:date>2024-06-27T18:30:22Z</dc:date>
    <item>
      <title>SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/218994#M10924</link>
      <description>&lt;P&gt;&lt;FONT size="4"&gt;Hi there,&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV class="container"&gt;&lt;FONT size="4"&gt;I'm experiencing an issue with my SMB device. After a reboot, it takes approximately 30 minutes for the VPN tunnel to become operational again.&lt;/FONT&gt;&lt;BR /&gt;
&lt;DIV class="container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV class="container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="container"&gt;&lt;FONT size="4"&gt;Is there a specific setting or timer that could be adjusted to expedite the VPN tunnel re-establishment process? Or, is this a known limitation ?&lt;/FONT&gt;&lt;BR /&gt;
&lt;DIV class="container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV class="container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="container"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Jun 2024 13:21:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/218994#M10924</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-06-27T13:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/218996#M10925</link>
      <description>&lt;P&gt;Specific settings mismatches as side a DAIP gateway VPN scenario will often be slower but 30-minutes seems excessive.&lt;/P&gt;
&lt;P&gt;sk167473 explains the reasons in part, only one side can initiate the VPN and there is a need for DPD.&lt;/P&gt;
&lt;P&gt;What version/build is the gateway appliance?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 13:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/218996#M10925</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-06-27T13:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/218998#M10926</link>
      <description>&lt;P&gt;show software-version&lt;BR /&gt;This is Check Point's 1590 Appliance R81.10.07 - Build 397&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 13:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/218998#M10926</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-06-27T13:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219002#M10928</link>
      <description>&lt;P&gt;For awareness per sk179615...&lt;/P&gt;
&lt;P&gt;R81.10.08 is the current recommended release and R81.10.10 is the latest.&lt;/P&gt;
&lt;P&gt;Something else to consider if the issue persists after investigating the DAIP / DPD elements perhaps.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 15:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219002#M10928</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-06-27T15:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219004#M10929</link>
      <description>&lt;P&gt;this how my routing table looks like, when everything is ok.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; netstat -r
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
default         ua-113-113-192- 0.0.0.0         UG        0 0          0 WAN
10.0.0.0        192.168.4.10    255.0.0.0       UG        0 0          0 vpnt10
192.168.3.0     *               255.255.255.0   U         0 0          0 LAN1
192.168.4.10    *               255.255.255.255 UH        0 0          0 vpnt10
113.113.192.0   *               255.255.224.0   U         0 0          0 WAN
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the gateway reboots the routing table looks like this for about 30 min:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;netstat -r
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
default         113.113.192.1   0.0.0.0         UG        0 0          0 WAN
10.0.0.0        192.168.4.10    255.0.0.0       UG        0 0          0 vpnt10
192.168.3.0     *               255.255.255.0   U         0 0          0 LAN1
192.168.4.10    *               255.255.255.255 UH        0 0          0 vpnt10
113.113.192.0   *               255.255.224.0   U         0 0          0 WAN
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;after about 30 mins it changes and works again&lt;/P&gt;
&lt;P&gt;any ideas?&lt;/P&gt;
&lt;P&gt;what is the difference between 113.113.192.1 and ua-113-113-192-&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 14:32:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219004#M10929</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-06-27T14:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219032#M10933</link>
      <description>&lt;P&gt;Try netstat -rn when everything's ok.&lt;BR /&gt;I'm guessing it'll be the same in both cases.&lt;/P&gt;
&lt;P&gt;That suggests DNS is related to this issue.&lt;BR /&gt;You should check if DNS is working when the issue is occurring.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 16:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219032#M10933</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-27T16:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219037#M10934</link>
      <description>&lt;P&gt;So, when using netstat -rn the result is the same as netstat -r when things are not working:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;netstat -r
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
default         113.113.192.1   0.0.0.0         UG        0 0          0 WAN
10.0.0.0        192.168.4.10    255.0.0.0       UG        0 0          0 vpnt10
192.168.3.0     *               255.255.255.0   U         0 0          0 LAN1
192.168.4.10    *               255.255.255.255 UH        0 0          0 vpnt10
113.113.192.0   *               255.255.224.0   U         0 0          0 WAN
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What DNS talking we about here? Is it my ISP DNS?&lt;/P&gt;
&lt;P&gt;I could not resolve "ua-113-113-192-":&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;nslookup ua-113-113-192- 8.8.8.8
Server:  dns.google
Address:  8.8.8.8

*** dns.google can't find ua-113-113-192-: Non-existent domain&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on SMB, DNS is configured like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; show dns
mode:                         global
proxy:                        on
resolving:                    on
primary ipv4-address:         10.8.0.12
secondary ipv4-address:       8.8.8.8
tertiary ipv4-address:
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where 10.8.0.12 is the our internal&amp;nbsp; DNS server behind the central gateway&lt;/P&gt;
&lt;P&gt;So,When the issue occurs, no pings can reach any destination:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8): 56 data bytes
^C
--- 8.8.8.8 ping statistics ---
6 packets transmitted, 0 packets received, 100% packet loss
Gateway-ID-7FB7C2DC&amp;gt; ping google.com
ping: bad address 'google.com'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 18:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219037#M10934</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-06-27T18:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219043#M10935</link>
      <description>&lt;P&gt;Looks like after reboot internet is not working. Is this correct understanding?&lt;/P&gt;
&lt;P&gt;Then we do not need to troubleshoot VPN issues but ISP issues maybe?&lt;/P&gt;
&lt;P&gt;DNS is internal IP i see so that would go via tunnel that is down? That leaves you with 8.8.8.8 that also is not working.&lt;/P&gt;
&lt;P&gt;Can you confirm if internet is working after reboot?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 20:20:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219043#M10935</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-27T20:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219046#M10936</link>
      <description>&lt;P&gt;After reboot nothing works!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8): 56 data bytes
^C
--- 8.8.8.8 ping statistics ---
10 packets transmitted, 0 packets received, 100% packet loss&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Internet is not working directly after reboot, but it works after about 25-30 minutes when everything else start to work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so netstat -r looks like this directly after reboot:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;netstat -r
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
default         113.113.192.1   0.0.0.0         UG        0 0          0 WAN
10.0.0.0        192.168.4.10    255.0.0.0       UG        0 0          0 vpnt10
192.168.3.0     *               255.255.255.0   U         0 0          0 LAN1
192.168.4.10    *               255.255.255.255 UH        0 0          0 vpnt10
113.113.192.0   *               255.255.224.0   U         0 0          0 WAN
&lt;/LI-CODE&gt;
&lt;P&gt;netstat -r looks like this after 25-30 minutes when everything start to work:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;netstat -r
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
default         ua-113-113-192- 0.0.0.0         UG        0 0          0 WAN
10.0.0.0        192.168.4.10    255.0.0.0       UG        0 0          0 vpnt10
192.168.3.0     *               255.255.255.0   U         0 0          0 LAN1
192.168.4.10    *               255.255.255.255 UH        0 0          0 vpnt10
113.113.192.0   *               255.255.224.0   U         0 0          0 WAN
&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 27 Jun 2024 21:29:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219046#M10936</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-06-27T21:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219063#M10937</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have seen this behavior before.&lt;/P&gt;&lt;P&gt;Do not use a DNS behind a VPN you have to create yourself. It does not work (chicken / egg) consistently. and especially if you need DNS to create the Tunnel it gets weird.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the GW just use internet DNS servers (from your ISP, Google,...) behind the GW you can publish the internal DNS via DHCP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;BR /&gt;Peter&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 07:38:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219063#M10937</guid>
      <dc:creator>JP_Rex</dc:creator>
      <dc:date>2024-06-28T07:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219109#M10949</link>
      <description>&lt;P&gt;Good tip, indeed these DNS servers should have specific routes for them outside the VPN.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 14:29:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219109#M10949</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-06-28T14:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219211#M10952</link>
      <description>&lt;P&gt;I did as you said, the time it takes to move from 113.113.192.1&amp;nbsp; to ua-113-113-192- is now about 20 minutes!&lt;/P&gt;
&lt;P&gt;Is that normal? Or should I do something more?&lt;/P&gt;
&lt;LI-CODE lang="ruby"&gt; show dns
mode:                         global
proxy:                        on
resolving:                    on
primary ipv4-address:         8.8.8.8
secondary ipv4-address:       8.8.8.8
tertiary ipv4-address:

&lt;/LI-CODE&gt;
&lt;P&gt;What about (&lt;STRONG&gt;mode&lt;/STRONG&gt;) global or internet, does that have any thing to do with this problem?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2024 17:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219211#M10952</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-06-30T17:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: SMB and Reboot</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219333#M10971</link>
      <description>&lt;P&gt;The fact you cannot ping 8.8.8.8 or any other IP's after reboot tells me there is an internet access issue. The DNS and VPN not working is just an outcome of not working internet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should focus on this to be honest. Is it cluster? Maybe make packet capture on WAN interface to see what is going on.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If internet not working try to atleast ping DG to see if that is working:&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;113.113.192.1&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Jul 2024 21:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-and-Reboot/m-p/219333#M10971</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-01T21:35:32Z</dc:date>
    </item>
  </channel>
</rss>

