<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are DAIP gateways never really shown as connected ... even when they working just fine? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/101968#M4369</link>
    <description>&lt;P&gt;Hello Thomas,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;&amp;lt;&lt;SPAN&gt;so the DAIP GW´s get dummy IP´s starting at 0.0.0.1 ... here this guy has 0.0.0.2 ...&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;the MGMT will never reach a 0.0.0.2 adress ... &amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The mentioned 0.0.0.x - Addresses are only as you mentioned internal "dummy" IPs. They can be used for filtering, when you don't know the exact OIP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But as I mentioned, check if a NAT / DMZ-Host Configuration is there on your provider router for the checkpoint appliance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You need this, otherwise Management Node can never connect to the correct OIP.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2020 10:00:06 GMT</pubDate>
    <dc:creator>Us4r</dc:creator>
    <dc:date>2020-11-13T10:00:06Z</dc:date>
    <item>
      <title>Why are DAIP gateways never really shown as connected ... even when they working just fine?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99457#M4264</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;this is an issue which causes alot of questions by customers and by me too...&lt;BR /&gt;DAIP gatways are never shown in SmartConsole as conencted (green) but as disconnected (red)?&lt;BR /&gt;Since the first three appliances in the picture are really online (red) its annoying to see them as disconnected ...&lt;BR /&gt;&lt;BR /&gt;Is there a good explanation, and how to fix this?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DAIP_GW_SHOWN_AS_OFF.PNG" style="width: 548px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8496i16C26C82FAD5E5F0/image-size/large?v=v2&amp;amp;px=999" role="button" title="DAIP_GW_SHOWN_AS_OFF.PNG" alt="DAIP_GW_SHOWN_AS_OFF.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;In Dashboard they are listed with IP´s like 0.0.0.X and incrementing ...&amp;nbsp;&lt;BR /&gt;Every one of this appliances has of course internal unique IP adresses .. .is there are way to play with them and do some creepy NAT?&lt;BR /&gt;I think i have seen an article on CheckMates how to overcome this, but i cannot find it anymore ...&lt;BR /&gt;&lt;BR /&gt;Any help or ideas are welcome!&lt;BR /&gt;&lt;BR /&gt;best regards&lt;BR /&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 07:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99457#M4264</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-10-19T07:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why are DAIP gateways never really shown as connected ... even when they working just fine?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99471#M4265</link>
      <description>&lt;P&gt;This looks very unnatural - i would suggest to contact TAC to resolve it !&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 08:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99471#M4265</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-19T08:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why are DAIP gateways never really shown as connected ... even when they working just fine?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99487#M4268</link>
      <description>&lt;P&gt;Hello Thomas,&lt;/P&gt;&lt;P&gt;the Management Node needs to establish a connection to the DAIP Gateways. If this is not working because no NAT - Rules exist on the provider router for the SMB - Appliance, then you get the unreachable symbol presented.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 11:32:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99487#M4268</guid>
      <dc:creator>Us4r</dc:creator>
      <dc:date>2020-10-19T11:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why are DAIP gateways never really shown as connected ... even when they working just fine?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99490#M4269</link>
      <description>&lt;P&gt;In most cases, SMS is NATed behind a GW - see &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk66381&amp;amp;partition=Basic&amp;amp;product=Security" target="_blank"&gt;sk66381: How to configure &lt;STRONG&gt;Management&lt;/STRONG&gt; &lt;STRONG&gt;behind&lt;/STRONG&gt; &lt;STRONG&gt;NAT&lt;/STRONG&gt; &lt;STRONG&gt;in&lt;/STRONG&gt; Security Gateway 80 / 1100 / 1400 Appliance setup&lt;/A&gt; for help !&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 12:18:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99490#M4269</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-19T12:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why are DAIP gateways never really shown as connected ... even when they working just fine?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99493#M4270</link>
      <description>&lt;P&gt;Hello. well no, the SMS works perfect for other gateways with public IP ... just the DAIP IP GW´s are not shown as connected (green) but as disconnected (red)&lt;BR /&gt;The SMS hsa of course all this settings from SK66281&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;for example the VPN certificate says:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Subject: CN=XXXXXXXXXXXXXXXXXXXXXXXXX&lt;BR /&gt;Issuer: O=XXXXXXXXXXXXXXXXXXXX&lt;BR /&gt;Not Valid Before: Sun Oct 21 14:20:21 2018 Local Time&lt;BR /&gt;Not Valid After: Sat Oct 21 14:20:21 2023 Local Time&lt;BR /&gt;Serial No.: 75149&lt;BR /&gt;Public Key: RSA (2048 bits)&lt;BR /&gt;Signature: RSA with SHA256&lt;BR /&gt;Subject Alternate Names:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;----&amp;gt; LOOK HERE&amp;nbsp; Address: 0.0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CRL distribution points:&lt;BR /&gt;http://XXXXXXXXXXXXXXX:18264/ICA_CRL1.crl&lt;BR /&gt;CN=ICA_CRL1,O=XXXXXXXXXXXXXXXXX..bn78tq&lt;BR /&gt;Key Usage:&lt;BR /&gt;digitalSignature&lt;BR /&gt;keyEncipherment&lt;BR /&gt;Basic Constraint:&lt;BR /&gt;not CA&lt;BR /&gt;MD5 Fingerprint:&lt;BR /&gt;95:D1:57:3E:04:08:94:58:55:6E:CF:14:CC:58:A3:EA&lt;BR /&gt;SHA-1 Fingerprints:&lt;BR /&gt;1. 99:99:07:6C:7D:1C:10:8C:B8:A2:88:7F:5E:CB:0E:28:34:27:F0:A5&lt;BR /&gt;2. HOLE OMAN SHOW WERE MUTT WOW MATH FLO JAW MOLD LOAF FLY&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;so the DAIP GW´s get dummy IP´s starting at 0.0.0.1 ... here this guy has 0.0.0.2 ...&lt;BR /&gt;&lt;BR /&gt;the MGMT will never reach a 0.0.0.2 adress ...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;best regards&lt;BR /&gt;Thomas.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 12:45:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/99493#M4270</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-10-19T12:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why are DAIP gateways never really shown as connected ... even when they working just fine?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/101968#M4369</link>
      <description>&lt;P&gt;Hello Thomas,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;&amp;lt;&lt;SPAN&gt;so the DAIP GW´s get dummy IP´s starting at 0.0.0.1 ... here this guy has 0.0.0.2 ...&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;the MGMT will never reach a 0.0.0.2 adress ... &amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The mentioned 0.0.0.x - Addresses are only as you mentioned internal "dummy" IPs. They can be used for filtering, when you don't know the exact OIP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But as I mentioned, check if a NAT / DMZ-Host Configuration is there on your provider router for the checkpoint appliance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You need this, otherwise Management Node can never connect to the correct OIP.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 10:00:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/101968#M4369</guid>
      <dc:creator>Us4r</dc:creator>
      <dc:date>2020-11-13T10:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why are DAIP gateways never really shown as connected ... even when they working just fine?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/101971#M4370</link>
      <description>&lt;P&gt;This annoys me too &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I wish Check Point would add a status 'push' CPD AMON mechanism for DAIP gateways, so they can report to the SMS instead of the SMS only being able to pull status.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 10:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Why-are-DAIP-gateways-never-really-shown-as-connected-even-when/m-p/101971#M4370</guid>
      <dc:creator>Nik_Bloemers</dc:creator>
      <dc:date>2020-11-13T10:26:55Z</dc:date>
    </item>
  </channel>
</rss>

