- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
We are experiencing DNS issues with the management network, specifically with the MGMT interface of firewalls and managers.
Firewalls mgmt interfaces and Managers which are belong to managment network 10.20.90.0/24 are not accessing internet. From managers servers (10.20.90.10, and 10.20.90.20) can ping 8.8.8.8 and others, but it is not reachable to the internet services (DNS).
Urgent assist!
Hey brother,
Im just about to start work, but to repeat what I mentioned in my response to your message before, how is topology configured? Does this happen on multiple firewalls?
Andy
Hey Andy,
I can ping 8.8.8.8 and outside interface of firewall Smartconsole (MGMT server) 10.1.90.20, But resolve to the www.google.com or checkpoint.com not working.
[Expert@COM-EFW-01:0]# fw ctl zdebug drop | grep 10.1.90.20
@;74285308.808030;[vs_0];[tid_26];[fw4_26];fw_log_drop_ex: Packet proto=17 10.1.90.20:59268 -> 239.255.255.250:1900 dropped by fw_log_ip_routing_failure Reason: IP multicast routing failed (missing OS route);
@;74285555.808168;[vs_0];[tid_34];[fw4_34];fw_log_drop_ex: Packet proto=17 10.1.90.20:59268 -> 239.255.255.250:1900 dropped by fw_log_ip_routing_failure Reason: IP multicast routing failed (missing OS route);
@;74286043.808271;[vs_0];[tid_36];[fw4_36];fw_log_drop_ex: Packet proto=17 10.1.90.20:59268 -> 239.255.255.250:1900 dropped by fw_log_ip_routing_failure Reason: IP multicast routing failed (missing OS route);
@;74286313.808406;[vs_0];[tid_31];[fw4_31];fw_log_drop_ex: Packet proto=17 10.1.90.20:59268 -> 239.255.255.250:1900 dropped by fw_log_ip_routing_failure Reason: IP multicast routing failed (missing OS route);
^C
Next time perform for exit: "fw ctl debug 0"
cpdev_wait_ioctl_done_mq: ack select failed 23, Interrupted system call
cpdev_user_ioctl_mq: failed to receive ack, Interrupted system call, op 3222829798
cpdev_user_ioctl: ioctl failed to device /vs0/dev/fw0
: Interrupted system call
Cannot unset debug filter
I don't want to route managment servers and smartconsole through mgmt interface, it should be route through internal interface which is bond2.
[Expert@COM-EFW-01:0]# ip route show
default via 213.55.84.9 dev bond1 proto 7
10.0.0.0/8 via 172.24.1.3 dev bond2 proto 7
10.1.0.0/24 via 172.24.1.3 dev bond2 proto 7
10.1.0.111 via 172.24.1.3 dev bond2 proto 7
10.1.0.112 via 172.24.1.3 dev bond2 proto 7
10.1.0.113 via 172.24.1.3 dev bond2 proto 7
10.1.1.0/24 via 172.24.1.3 dev bond2 proto 7
10.1.9.0/24 via 172.24.1.3 dev bond2 proto 7
10.1.10.0/24 via 172.24.1.3 dev bond2 proto 7
10.1.20.0/24 via 172.24.1.3 dev bond2 proto 7
10.1.50.0/24 via 172.24.1.3 dev bond2 proto 7
10.1.60.0/24 via 172.24.1.3 dev bond2 proto 7
10.1.90.0/24 dev Mgmt proto kernel scope link src 10.1.90.11
Hi @the_rock Andy,
I think I have to create two separate planes: a management plane and a data plane.
I have created the management plane and checked the IP route using ip r g 8.8.8.8, which shows "network is unreachable." However, from the data plane, ip r g 8.8.8.8 is reachable.
My goal is to ensure that management network traffic passes through the management plane to reach external internet traffic.
Hey Yeruel.
I cant recall now how you do that, but there is some dplace/mplane config in the clish, just check from show configuration.
Andy
Hi @yeruel
AFAIK, there is a fully separated from the Data plane, therefore you need to add the routing etc. in the Managament plane too. There is no passage between the two planes.
Here is the sk: https://support.checkpoint.com/results/sk/sk138672
Akos
Can I configure routing to the internet without separate management and dataplane?
What I am facing the issue is my management 10.1.90.0/24 is routing via mgmt interface of GW (10.1.90.11). I don't want to route the managment network via mgmt interface of gw. I think the direct interface is used as priority for routing to internet. what is your advice? I can ping from the managment smartconsole server 10.1.90.20 to the internet 8.8.8.8, but the checkpoint.com and google.com is not reachable. the traffic is blocked by gw mgmt interface,
How can I adjust the link cost value of interfaces direct connected, I want to OSPF should be the priority and the preferred route than direct connected.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY