Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mahajem
Participant
Jump to solution

How to disable NAT from VIP to Gateway when trying to ping GW?

Hello, I need to ping from a monitoring server to our CP GW physical IP but when I checked the logs I found out that only the VIP is replying and NATed to the active GW member. When I try to ping the GW physical IP it does not work but pinging to standby members physical IP is working. Can anyone help me? Do I need to manipulate the table.def with no_hide_services_ports = { <0,1>}? Is it possible to do this change only for the monitoring servers IP address and why is standby IP not NATed?

It shows me XLATE Destination IP (IP from active GW member)

NAT Rule number 0

Dst Port 0

Src Port 0

 

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

If the standby uses the VIP, the traffic would have to be communicated through the primary (which owns the VIP).

The SK I referred to modifies the behavior for all traffic on the specific gateway, whereas I believe the table.def modifications are more focused to specific types of traffic and apply to all gateways.
However, if you manage gateways of different versions, table.def changes need to be made multiple places.
They also need to be made again on an upgrade.

View solution in original post

4 Replies
PhoneBoy
Admin
Admin

What version/JHF is the gateways?
Did you also check: https://support.checkpoint.com/results/sk/sk34180 

0 Kudos
Mahajem
Participant

R81 JHF T92, yes I also saw this sk but where are the difference between editing table.def and this workaround? And why does the standby not using the VIP?

0 Kudos
PhoneBoy
Admin
Admin

If the standby uses the VIP, the traffic would have to be communicated through the primary (which owns the VIP).

The SK I referred to modifies the behavior for all traffic on the specific gateway, whereas I believe the table.def modifications are more focused to specific types of traffic and apply to all gateways.
However, if you manage gateways of different versions, table.def changes need to be made multiple places.
They also need to be made again on an upgrade.

the_rock
Legend
Legend

I also have a gut feeling sk Phoneboy gave is your best option, but you can verify with TAC if there might be better option.

Personally, I doubt it...

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events