- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello,
we`ve installed two 5400 Firewalls running in a clusterXL, currently running on R80.10.
The Firewalls have been fully configured and policy is installed without errors on both sides (via management server).
After a planned reboot of one of the Firewalls, the firewall is not reachable anymore by IP from foreign networks.
Its only possible to reach it by IP via the directly connected Core Switch, which is the Gateway for the used network.
When I make a Ping from one of the Firewall to an outside network, it reports error:
abcd> ping xxxxxxxxx
connect: Network is unreachable
The ping to the Gateway IP is working
As I said, the firewall was fully configured, reachable and working (default route was set)
It seems like IP forwarding is disabled or something like that.
How can I fix this?
Why does it happen?
Thanks!
Your version is quite out of support, but I'd suggest starting with some layer 2 and 3 troubleshooting - is the default route in the table properly? Does the appliance have an ARP entry for the default route? Can you ping local IPs?
Also, check the clustering - is there a pnote for routed?
The Firewalls have been new installed and the next step would be the upgrade to the current version, but we have now this problem.
As i wrote:
all was working, routing, reachability also from outside location
But after reboot I cant ping anyhting except the default gateway address
Arp entry on the appliance is present for the default GW address
We recommend starting with a fresh install of your desired version off a USB key, rather than starting old and upgrading it. You'll get a cleaner install and better performance, as the file system on the disk will be newer and faster. An in-place upgrade (or clean install through CPUSE) will not upgrade the file system.
Is there even a JHF on the machine currently?
I agree with Emma, between troubleshooting this (without TAC) and navigating the multi-step upgrade save yourself some time.
Hey there,
thanks for your help.
The Firewall sadly is on the other side of the world, no joke at this point its 12000km away 🙂
I will try to find someone who can manage this upgrade as you suggested.
I will come back if the problem persists after upgrade.
I read all that was said here and Im almost 100% positive the upgrade here may not solve much, specially if the error says what you wrote, network is unreachable. Yes, I agree with both Emma and Chris, version is totally unsupported, but first, before you upgrade, routing should be fixed. Personally, you could be on R55 or R82, if routing is broken, it wont make any difference,
Lets start with basics here...if you run this command from expert mode -> ip r g 8.8.8.8, what do you see? Does it look correct? Also, can you send output of just route command?
Best,
Andy
Hi
[Expert@xxxxxxxxxx:0]# ip r g 8.8.8.8
RTNETLINK answers: Network is unreachable
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
aa.xxxxxxx.0 * 255.255.255.252 U 0 0 0 bond1 <----- Sync Link
bbxxxxxx.0 * 255.255.255.240 U 0 0 0 eth2 <----- Uplink
cc.xxxxxx16 * 255.255.255.240 U 0 0 0 Mgmt <---------- MGMT
ddxxxxxxxx.0 * 255.255.255.0 U 0 0 0 eth1 <--------------LAN
the default gateway is not present, also after set route default command
it should look like that, shouldnt it?
Destination Gateway Genmask Flags Metric Ref Use Iface
default a.b.c.1 0.0.0.0 UG 0 0 0 xxxxxxx
so the question is, why the device is losing the defualt route and why i cant configure it again?
Is routed running? Can you check the cluster pnotes?
can you help me with that?
how can I check this?
cphaprob stat
cphaprob list
ps aux | grep routed
Ok, maybe silly question, but if you are setting DG via clish, are you running save config to save it?
Andy
1) is the default route ip into same interface's network?
2) are you sure you are not configurin a default route ip assigned to your interface?
Sorry for dumb question 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
25 | |
13 | |
9 | |
9 | |
7 | |
7 | |
7 | |
6 | |
4 | |
4 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY