<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check Point 790 NAT problem in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164297#M7903</link>
    <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Hi!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;So first things first our setup is two Check Point 790 Appliance, the main is FW1, the secondary is FW2! This two is set in High Availability mode. Both Firewall has &lt;/SPAN&gt;&lt;SPAN&gt;R77.20.87&lt;/SPAN&gt;&lt;SPAN&gt; version which is the latest what i found.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;We have a problem with the Check Point FW1 firewall! When we on FW1, we cant reach the internet from internal network, and we can't get any data from the Check Point Firewall with monitoring tools also. Our ISP says that they cant see any problem at all, they can reach their own modem they see traffic on it. So we tried to reach internet from internal network, with browsers and with ICMP, no response at all. From inside we can reach the gateway, with browsers and with ping also, we can reach the servers etc, &lt;/SPAN&gt;&lt;SPAN&gt;so the internal network works!&lt;/SPAN&gt;&lt;SPAN&gt; We tried "Ping or Trace an IP Address |&amp;nbsp; Host name or IP address:" on the Check Point FW1, the Check Point can reach the internet through ICMP protocol, &lt;/SPAN&gt;&lt;SPAN&gt;so the Check Point can reach the internet!&lt;/SPAN&gt;&lt;SPAN&gt; The physical layer was checked, no problem was found! The switches and the cables was tried out and works fine! So we pulled out the FW1 WAN cable, and because the High Availability the FW2 became the gateway, and everything works fine! Internal network can reach the internet, VPN's works etc... We tried to switch it back to FW1, so we plugged back the WAN cable, and pulled out the FW2 WAN cable. The FW1 become the gateway. The problem was the same as I mentioned. So we changed back to FW2! It seems like a NAT problem, but I didn't found anything that is incorrect. IP address and DNS etc, it is well set. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;I'm still getting to know the checkpoint so maybe it is something obvious. Thanks a lot!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 06 Dec 2022 09:01:30 GMT</pubDate>
    <dc:creator>r0kika</dc:creator>
    <dc:date>2022-12-06T09:01:30Z</dc:date>
    <item>
      <title>Check Point 790 NAT problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164297#M7903</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Hi!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;So first things first our setup is two Check Point 790 Appliance, the main is FW1, the secondary is FW2! This two is set in High Availability mode. Both Firewall has &lt;/SPAN&gt;&lt;SPAN&gt;R77.20.87&lt;/SPAN&gt;&lt;SPAN&gt; version which is the latest what i found.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;We have a problem with the Check Point FW1 firewall! When we on FW1, we cant reach the internet from internal network, and we can't get any data from the Check Point Firewall with monitoring tools also. Our ISP says that they cant see any problem at all, they can reach their own modem they see traffic on it. So we tried to reach internet from internal network, with browsers and with ICMP, no response at all. From inside we can reach the gateway, with browsers and with ping also, we can reach the servers etc, &lt;/SPAN&gt;&lt;SPAN&gt;so the internal network works!&lt;/SPAN&gt;&lt;SPAN&gt; We tried "Ping or Trace an IP Address |&amp;nbsp; Host name or IP address:" on the Check Point FW1, the Check Point can reach the internet through ICMP protocol, &lt;/SPAN&gt;&lt;SPAN&gt;so the Check Point can reach the internet!&lt;/SPAN&gt;&lt;SPAN&gt; The physical layer was checked, no problem was found! The switches and the cables was tried out and works fine! So we pulled out the FW1 WAN cable, and because the High Availability the FW2 became the gateway, and everything works fine! Internal network can reach the internet, VPN's works etc... We tried to switch it back to FW1, so we plugged back the WAN cable, and pulled out the FW2 WAN cable. The FW1 become the gateway. The problem was the same as I mentioned. So we changed back to FW2! It seems like a NAT problem, but I didn't found anything that is incorrect. IP address and DNS etc, it is well set. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;I'm still getting to know the checkpoint so maybe it is something obvious. Thanks a lot!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Dec 2022 09:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164297#M7903</guid>
      <dc:creator>r0kika</dc:creator>
      <dc:date>2022-12-06T09:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point 790 NAT problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164376#M7907</link>
      <description>&lt;P&gt;Did you follow&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121096&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;sk121096: How to configure a &lt;STRONG&gt;cluster&lt;/STRONG&gt; between locally managed SMB appliances&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 20:59:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164376#M7907</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-06T20:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point 790 NAT problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164380#M7908</link>
      <description>&lt;P&gt;With reference to&amp;nbsp;&lt;SPAN&gt;sk153433 which specific build of R77.20.87 is deployed here?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 21:55:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164380#M7908</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-06T21:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point 790 NAT problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164410#M7912</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks everyone for the answers, we found out the problem is with the ISP modem.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Clearing ARP cache on the modem solved the problem!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Because when the firewalls switch between primary and secondary in the ARP cache the trafic goes to the secondary, ARP cache clears automatically after a hour in default, we changed it to 3 minutes and it works fine. It takes 5 minutes to the two Checkpoint to change which is primary member.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 09:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Check-Point-790-NAT-problem/m-p/164410#M7912</guid>
      <dc:creator>r0kika</dc:creator>
      <dc:date>2022-12-07T09:33:53Z</dc:date>
    </item>
  </channel>
</rss>

