<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing Persistence Question - Embedded GAIA in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12718#M301</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It has long been behavior on Check Point gateways to disable IP Forwarding until a real security policy is loaded.&lt;/P&gt;&lt;P&gt;SMB devices are a little different in that they have a different set of default policies, including ones that pass traffic, but the same basic principles apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;for moving posts when needed, it's part of what I do&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Apr 2018 17:01:28 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-04-05T17:01:28Z</dc:date>
    <item>
      <title>Routing Persistence Question - Embedded GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12715#M298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Evening -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have approx. 25 x 1450 gateways on embedded GAIA_R77.20.70 - configured with an external WAN interface and an internal switch - LAN1_switch. To get the switch to pass packets to the WAN interface routing was enabled in&amp;nbsp;&lt;/P&gt;&lt;P&gt;# /proc/sys/net/ipv4/ip_forward by setting the value to &amp;lt;1&amp;gt;. Good to go. BUT, i am unable to get it to survive reboots! i also tried enabling it by # sysctl -w net.ipv4.ip_forward=1. Again, reboot killed it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make it persistent and survive reboots in full GAIA, or other 'full' distro, I would edit /etc/sysctl.conf , but this file does not seem to exist in the embedded version.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone else come across this snafu - and found a fix? Or anyone know if an equivalent sysctl.conf file exists in embedded GAIA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2018 05:48:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12715#M298</guid>
      <dc:creator>CP_SA</dc:creator>
      <dc:date>2018-04-05T05:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Persistence Question - Embedded GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12716#M299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If everything is working properly, you should not need to manually set this value to 1.&lt;/P&gt;&lt;P&gt;The only reason it would ever be set to zero is if, for some reason, it is unable to load a security policy.&lt;/P&gt;&lt;P&gt;Either that or there is something peculiar about your configuration.&lt;/P&gt;&lt;P&gt;What does “fw stat” show?&lt;/P&gt;&lt;P&gt;Also let’s move this to the &lt;A href="https://community.checkpoint.com/community/infinity-general/smb-smp?sr=search&amp;amp;searchId=5a4d44b9-0222-4022-adbd-1bedb2b26491&amp;amp;searchIndex=0" target="_blank"&gt;https://community.checkpoint.com/community/infinity-general/smb-smp?sr=search&amp;amp;searchId=5a4d44b9-0222-4022-adbd-1bedb2b26491&amp;amp;searchIndex=0&lt;/A&gt;‌ space where it belongs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:02:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12716#M299</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T09:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Persistence Question - Embedded GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12717#M300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These guys are all centrally managed and policy is not being pushed until they are deployed. . We thought that this might be the issue as well. And, we actually have not re-loaded one once they are deployed - I simply verify - and they all have been successful so I did not re-visit it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was in my pre-configuring, without policy, that was driving me crazy. I would configure, set the routing, test connectivity from the Lan to the WAN and then power it down - pull them out to verify just prior to deployment and it would not have survived the re-load.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for confirming the suspicion - I will re-load a deployed one and verify the persistence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for moving the thread - i am a Checkmates noob and completely overlooked it!&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2018 15:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12717#M300</guid>
      <dc:creator>CP_SA</dc:creator>
      <dc:date>2018-04-05T15:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Persistence Question - Embedded GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12718#M301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It has long been behavior on Check Point gateways to disable IP Forwarding until a real security policy is loaded.&lt;/P&gt;&lt;P&gt;SMB devices are a little different in that they have a different set of default policies, including ones that pass traffic, but the same basic principles apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;for moving posts when needed, it's part of what I do&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2018 17:01:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-Persistence-Question-Embedded-GAIA/m-p/12718#M301</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-05T17:01:28Z</dc:date>
    </item>
  </channel>
</rss>

