Vlad, to make it even more complicated I will add a little bit of naughty stuff here:
- vMAC wasnt enabled indeed
- HSRP/VRRP was causing an issues
- Hosts on STATIC object IP were 2 SMS devices (Management HA)
- proxy arp was set but when removed there was no difference traffic flow wise, still Management HA couldn't communicate via VIP IP from ClusterXL hosts (core gw).
- when proxy arp was removed it still didn't work, only when IPS got into the Huawei crap (...) they've found mismatches on their config, fixed dynamic routing and all started to work as it should
now I'm facing similar story on R80.10 infra where Management HA cannot comm with CPUSE due to (potentially) upstream FW glitch as the proxy-arp in or not in place makes no difference. Static object NAT made on SMS boxes itself (by Dash).
still CPUSE cannot be reached by SMS's itself.
good thing is that it will get resovled soon when Compliance Team get on with it and sort their FW ruleset mess out.
best,
Jerry
Jerry