<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1470 cluster bad ping results to lan interfaces in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/89114#M3732</link>
    <description>Still Gaia Embedded.</description>
    <pubDate>Fri, 19 Jun 2020 01:39:30 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-06-19T01:39:30Z</dc:date>
    <item>
      <title>1470 cluster bad ping results to lan interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88571#M3706</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using the latest r77.20.87 (990173004) build and created a locally managed 1470 cluster. I noticed that pinging the lan vip, lan ip of node 1 and of node 2 is quite bad.&lt;/P&gt;&lt;P&gt;Often pings just fail but the webinterface works and traffic seems to flow normally towards internet.&lt;/P&gt;&lt;P&gt;The lan interfaces are in their own subnet with a routing switch. Connected to the routing switch are internal networks. I've created a vpn with another site and from that site I can ping without any loss towards the internal networks. But pinging to the firewall lan interfaces and vip, just fails quite a lot.&lt;/P&gt;&lt;P&gt;Is that a known issue?&lt;/P&gt;&lt;P&gt;Jeroen&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 07:44:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88571#M3706</guid>
      <dc:creator>Jeroen_Demets</dc:creator>
      <dc:date>2020-06-15T07:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: 1470 cluster bad ping results to lan interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88658#M3711</link>
      <description>&lt;P&gt;R77.20 is &lt;STRONG&gt;&lt;U&gt;very old &lt;/U&gt;&lt;/STRONG&gt;but regarding your question:&lt;/P&gt;&lt;P&gt;I think you just hit this old limitation:&lt;/P&gt;&lt;P data-unlink="true"&gt;sk26874&lt;/P&gt;&lt;P&gt;So enabling &lt;STRONG&gt;fw_allow_simultaneous_ping&lt;/STRONG&gt; (set it to 1) should help you solve this problem.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 14:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88658#M3711</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2020-06-15T14:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: 1470 cluster bad ping results to lan interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88741#M3720</link>
      <description>&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;That fixed it and stopped us from worrying something is wrong.&lt;/P&gt;&lt;P&gt;We are actually using this setup with a transit network to a SD WAN setup and were also pinging through that. This means not through the default LAN.&lt;/P&gt;&lt;P&gt;I also used this &lt;SPAN&gt;sk42733&lt;/SPAN&gt; about "Connection from one side of the ClusterXL destined to the physical IP address of a non-Active cluster member on the other side of the ClusterXL fails"&lt;/P&gt;&lt;P&gt;with fwha_forw_packet_to_not_active and with fw_allow_simultaneous_ping active it now works perfectly and monitoring is happy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(and yes: R77.20 is old but that's the issue with SMB devices, they lag in features and version compared to big Gaia. I wish CP would use one OS everywhere just like most competitors do...)&lt;/P&gt;&lt;P&gt;I hope my reply helps others too.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 08:34:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88741#M3720</guid>
      <dc:creator>Jeroen_Demets</dc:creator>
      <dc:date>2020-06-16T08:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: 1470 cluster bad ping results to lan interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88763#M3722</link>
      <description>&lt;P&gt;There is also a default limit on the max ping size that will be accepted, this can also be&amp;nbsp; changed.&lt;/P&gt;
&lt;P&gt;Note the 1470 will never see R80.20.XX unfortunately. If this is a requirement migration to 1500 will need to be considered in future.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 11:01:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88763#M3722</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-06-16T11:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: 1470 cluster bad ping results to lan interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88769#M3724</link>
      <description>Tnx for the info about the ping size, good to know.&lt;BR /&gt;&lt;BR /&gt;About the 1500 series, they are still gaia embedded though...so different way of troubleshooting and with their own series of bugs&lt;BR /&gt;&lt;BR /&gt;but yes, we'll use them for future sites and if possible, centrally managed, as the SmartConsole and central logging is so much better than the webui.</description>
      <pubDate>Tue, 16 Jun 2020 11:29:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/88769#M3724</guid>
      <dc:creator>Jeroen_Demets</dc:creator>
      <dc:date>2020-06-16T11:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: 1470 cluster bad ping results to lan interfaces</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/89114#M3732</link>
      <description>Still Gaia Embedded.</description>
      <pubDate>Fri, 19 Jun 2020 01:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1470-cluster-bad-ping-results-to-lan-interfaces/m-p/89114#M3732</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-19T01:39:30Z</dc:date>
    </item>
  </channel>
</rss>

