- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
Our environment consists of 2 Checkpoint Clusters (External & Internal Firewall) where each cluster comprises of three nodes. Also we've got two SMS servers in Active-Standby. All Gateways as well as management Servers are on 81.20 version. My issue is that when i am trying to backup gateway config via TFTP server this works only for active members, for standby nodes this fails. I am able to backup both SMS without any issue. Is there something i am missing. Fyi, TFTP Server is on the same subnet as the management network of all gateways. Also i've created the firewall policies required. Could you please assist on what i am missing?
Thanks in advance
@katsarasd I moved your post to the more appropriate space and also fixed the label.
In the cluster, connections from Standby member through a cluster interface may fail because they are NAT-ed behind VIP.
There are two options here:
1. use a private interface to open a connection to a backup server
2. Apply a workaround mentioned in sk169975
I would suggest the second option, as it is much simpler to move forward and does not require any network change.
Hello @_Val_
TFTP Server is on the same subnet as gateways management interface. Is there something additional i need to specify ?
Even if it is on the same network, if the GW is communicating with it on a cluster interface, it will be NAT-ed behind a VIP address. Did you read the SK I suggested?
You are abe to ping the TFTP server from the STANDBY member?
Yes standby members can ping tftp server
Maybe can you do a telnet test to the TFTP server? Maybe there is a service which is not TFTP, and you can make a test. Only the TFTP is failing?
Akos
I tried nc -v <server ip address> rdp port
for active member connection works
for standby members connection timeout
As I already mentioned, look into the SK. You will have to create No-NAT rule for the standby to work.
Sorry, but i am bit confused.
The cause of the issue of the sk169975
is of the no-nat rules. You mention above that i'll need to create no-nat rules for standby, it's not clear to me. sorry for the trouble.
Appears as Val had said its just a simple no-nat rule, thats it, does not need any other network changes.
Andy
No worries, the SK is indeed describing a bit different case, but it does have a link to the solution you need: sk34180
Please check it is clear enough, and let me know if it helps.
Hey @katsarasd
I did some more checking on this and found below sk...not sure if it may apply to you, but worth confirming.
Andy
https://support.checkpoint.com/results/sk/sk181866
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 18 | |
| 13 | |
| 12 | |
| 12 | |
| 10 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY