<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static routing not working after policy install in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34419#M1429</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have opened SR now and we are investigating it together with TAC. I will demand fix for this because it is the only way to have working SecureXL and still utilize secondary ISP somehow. Even though it is a manual way to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will update when there is a progress...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Nov 2018 17:57:29 GMT</pubDate>
    <dc:creator>HristoGrigorov</dc:creator>
    <dc:date>2018-11-26T17:57:29Z</dc:date>
    <item>
      <title>Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34410#M1420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anyone able to easily confirm this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Have two ISP connections: ISP-A and ISP-B configured in HA mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Add following static routes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;src: 192.168.0.0/24 via ISP-B, metric:10&lt;/P&gt;&lt;P&gt;src: 192.168.0.0/24 via ISP-A, metric: 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Observe static routing works fine and outgoing connections pass through ISP-B.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Do just any change and install policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. Observe static routing no longer works and in fact outgoing traffic is stuck and does not go through either of the ISP connections.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2018 03:41:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34410#M1420</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2018-10-11T03:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34411#M1421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What appliance and code version?&lt;/P&gt;&lt;P&gt;How did you configure the ISP redundancy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 11:58:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34411#M1421</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-12T11:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34412#M1422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanx and sorry, forgot to mention it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This is Check Point's 1470 Appliance R77.20.80 - Build 437&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP redundancy is in High-Availability mode with ISP-A being Primary and the other Secondary. Both ISPs are sharing same WAN interface using VLANs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 14:36:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34412#M1422</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2018-10-12T14:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34413#M1423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The other relevant question: locally managed or via external security management?&lt;/P&gt;&lt;P&gt;Based on what you're describing it seems like latter.&lt;/P&gt;&lt;P&gt;Also, is it all traffic going out 192.168.0.0/24 that fails after a policy push?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Oct 2018 07:58:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34413#M1423</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-13T07:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34414#M1424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, centrally managed. Only traffic that is supposed to go out through WAN interface fails. Other (internal) traffic works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Oct 2018 12:19:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34414#M1424</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2018-10-13T12:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34415#M1425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it ALL WAN traffic or just traffic destined for 192.168.0.0/24?&lt;/P&gt;&lt;P&gt;Either way, this seems like a bug and you should open a TAC caseso we can collect the appropriate Troubleshooting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Oct 2018 12:27:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34415#M1425</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-14T12:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34416#M1426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is outgoing routing, so only traffic from 192.168.0.0/24 to WAN is not working. I wanted quick confirm from someone else before I engage TAC because it all seem kind of peculiar to me and I am not sure if problem is not something I am doing wrong.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Oct 2018 18:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34416#M1426</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2018-10-14T18:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34417#M1427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried using the actual IP of the IPS-A and ISP-B gateways instead of the ISP-A or B setting?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Oct 2018 20:09:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34417#M1427</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-10-20T20:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34418#M1428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanx for the suggestion. I tried it but unfortunately end result is the same. What I noticed however is that there is still connectivity, I can telnet for example to port 80 or 443. So it must be some of the AC/UF blades that is failing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 03:49:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34418#M1428</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2018-10-22T03:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Static routing not working after policy install</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34419#M1429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have opened SR now and we are investigating it together with TAC. I will demand fix for this because it is the only way to have working SecureXL and still utilize secondary ISP somehow. Even though it is a manual way to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will update when there is a progress...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 17:57:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Static-routing-not-working-after-policy-install/m-p/34419#M1429</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2018-11-26T17:57:29Z</dc:date>
    </item>
  </channel>
</rss>

