- Products
- Learn
- Local User Groups
- Partners
- More
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi,
I am using R81.20 with JHF-take 65 for my FW1 and FW2. I made cluster.
While enabling the Load balance , I am not able to reach global dns 8.8.8.8 from both Gateway.
on HA we are able to reach global dns.
Attached some snap for reference.
Cphaprob stat output
Ping global dns
What do you see with a tcpdump when trying this?
i hvnt taken tcpdump , will post on Monday .
We definitely need more info. As Phoneboy advised, run tcpdump, fw monitor, try ip r g 8.8.8.8. Can you also send us output of route command from expert mode?
What does traceroute show? Network unreachable is super generic error that can mean multiple things. Could be interface issue, default gateway problem, route.
Best,
Andy
What switches do you have and how is the multicast/IGMP/arp config?
See also sk44898
Valid point Chris.
I have bunch of colleagues who deal with Aruba constantly (I personally dont as much), but I always hear them talk about igmp snooping. Maybe something you can verify if its enabled. Obviously, if you have multicast traffic on your network, that needs to be enabled, otherwise, probably not.
Andy
I'm not sure the bonds are so relevant here but you can check to ensure the hashing mode aligns.
Per the sk article I referenced above Load-sharing cluster mode isn't compatible with all vendors switches, you may need to implement some changes.
Hi,
I hv one query ,i hv gone through some documents from checkpoint that Load sharing will not work when Ipsec and Mobile blade enable...is it true? or ?
Please see sk101539 for more information, some limitations are version specific.
Also worth mentioning to keep an eye out for ElasticXL with R82 in terms of load-sharing capabilities.
Hey @VIKASH_GIRI
Were you able to get any traction on this issue?
Best,
Andy
HI,
Its running setup so not able to do any troubleshooting , i will get time on weekend only . will keep you posted.
Most L3 routers (not L2 switches) will refuse to cache a multicast MAC address received in an ARP reply so you will probably need to hardcode this on all L3 devices surrounding the gateway.
For your L2 switches, not all switches will handle multicast MAC addresses correctly, and will not consistently forward traffic bound for a multicast MAC to all the proper ports. Once again, hardcoding the multicast MACs at the switch level may be required. To summarize:
MULTICAST MACs = HARDCODING PAIN & SUFFERING
When taking your tcpdumps, make sure to include the -e option so you can see the Layer 2 MAC addresses.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 63 | |
| 38 | |
| 23 | |
| 12 | |
| 11 | |
| 10 | |
| 10 | |
| 9 | |
| 9 | |
| 8 |
Thu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Fri 10 Apr 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 45: Harmony SASE updateThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY