Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mahesh027cse1
Explorer

How to Check Point maintaining connection for GRE traffic

Hi,

Can anyone please help to understand how Checkpoint firewall,  GRE through traffic handling.

I am getting an issue.  GRE is configured on both end route and in between i have CheckPoint firewall.When a fail-over (primary to secondary) occurs, GRE is stop working and then i need to request with network person to bounce the Router GRE terminated physical port. I need to understand CheckPoint GRE through traffic handling, and how it maintain in connection table, i tried to find documents but no luck.

Route --->CheckPoint ---> Router  

 

 

0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

Is the connection subject to NAT and does the issue occur only on Failover or also during policy installation?

Service object:

gre.png


CCSM R77/R80/ELITE
0 Kudos
mahesh027cse1
Explorer

There is no NAT for GRE traffic. But when we did fail-over (Primary to secondary), We need to reset the GRE interface to establish connection.  Can you please help to understand how Check Point maintaining state-full fail-over for GRE through traffic.  

"Synchronize connection if State Synchronization is enabled on the cluster" is by default enabled for the GRE object.

0 Kudos
amdhim0004
Contributor

Hi @mahesh027cse1 

I know the solution.

But first can you please tell me if you have Primary/Secondary two GREs setup or only Single Tunnel?

Thanks 

Amandeep

0 Kudos
DT-ISP-DD
Explorer

Hi amdhim0004,

can you please tell me your solution? I have a similar issue with GRE at an R80.30 Cluster.

Thanks!

0 Kudos
Kevin_Taverner
Explorer

Can you tell us what your solution is?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events