- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
we have centally managed Appliance 1900 with RAS VPN configured. The SMB has been added to a cluster consisting of a single node.
I can connect, but in the routing table I see all my networks and interfaces instead of the manually specified encryption domain. Why doesn't the security gateway see the local domain?
Thank you!
Im gonna be 100% honest with you...none of this makes much logical sense to me. I dont personally see how this can even happen, specially considering that VPN domain stays the SAME, so it really begs the question, what else changes?
Those SKs you listed would appear to be relevant to this, at least in my opinion.
On another note, is this split or full tunnel?
Andy
I know what I will say now is probably "shot in the dark" as the saying goes, but I recall one time, while back, I was having similar issue with a customer and we discovered when failover was initiated, all worked fine...how, I have no clue, but when we failed back, all was okay again.
Maybe something to try...
Andy
let me show you something that can cause my problem:
That tells me issue with clustering config, run below on both to compare.
Andy
cphaprob roles
cphaprob state
cphaprob -l list
cphaprob -i list
cphaprob syncstat
I've opened a new topic for Cluster issue, could you please check it?
Just responded with same lol
Andy
Hey mate, did you manage to get this fixed with the cluster setup?
Andy
Hi Andy, no, i didn't. I just moved everything to the standalone Node that is centrally managed now (so we moved one little step forward). Now I will work with support, but from Monday. Today I got another issue with another cluster, that was working till today...
K, just responded there.
Andy
Hey mate, any luck with this?
Andy
Hallo Andy,
unfortunately, I didn't get any further, but I had the opportunity to test the RAS VPN on another single-node cluster, the Applicance 9000 R81.20 - it works...
Okay, no problem...so is clustering functional at this point, at least?
Andy
Clustering on SMB is a little different than non-SMB.
While a single node cluster may be ok for temporary (eg failure situation), you’d still have two cluster nodes configured until you repair/replace the other.
This not like the situation where a second cluster node has never been configured (your case).
In theory it should work, but it seems like you’re running into some sort of bug.
If you haven’t already, I suggest engaging TAC.
a few days ago, we also tested a cluster with two nodes - the same behavior: my laptop didn't get any routes from the VPN domain, but only local routers on gateway.
Just to update this case - the CheckPoint Support is still working on it...
This is a known shortcoming:
https://support.checkpoint.com/results/sk/sk141335
Set the topology to "Manually defined on the Security Management server, based on the below Topology Table"
and make sure all interfaces are defined correctly:
G_W_Albrecht thank you very much! now i see requered networks, but the routing table is strange: in the encryption domain, I have a network 192.168.0.0/22, but why was it split multiple times?
192.168.0.0 255.255.255.0 172.16.100.2 172.16.100.3 1
192.168.0.0 255.255.255.255 172.16.100.2 172.16.100.3 1
192.168.0.2 255.255.255.254 172.16.100.2 172.16.100.3 1
192.168.0.4 255.255.255.252 172.16.100.2 172.16.100.3 1
192.168.0.8 255.255.255.248 172.16.100.2 172.16.100.3 1
192.168.0.16 255.255.255.240 172.16.100.2 172.16.100.3 1
192.168.0.32 255.255.255.224 172.16.100.2 172.16.100.3 1
192.168.0.64 255.255.255.192 172.16.100.2 172.16.100.3 1
192.168.0.128 255.255.255.128 172.16.100.2 172.16.100.3 1
192.168.1.0 255.255.255.0 172.16.100.2 172.16.100.3 1
192.168.2.0 255.255.254.0 172.16.100.2 172.16.100.3 1
How are the interfaces configured ? And what is 192.168.0.1 that is missing here ?
the interfaces are configured in the simple way as on non-clustered node.
192.168.0.1 is the Gateway IP.
a short update: the firmware update to R81.10.17 (996004620) didn't help, in a week we have a remote session with Support to check the router angain and to collect new debug logs
Hello All!
Finally we found the sollution with CheckPoint Support - we were really close: the sk141335 and sk92676 must be implemented simultaneously!
Thank you very to all of you!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY