That looks suspiciously like this configuration (and this problem): https://community.checkpoint.com/message/8899-re-how-to-configure-external-interface-in-clusterxl?co...
In fact, the network diagram looks nearly identical to the linked thread.
It may be a coincidence, of course.
To verify it is NOT a Check Point problem:
- fw unloadlocal on one of the cluster members (this unloads the firewall policy)
- Attempt to ping the ISP gateway from the same cluster member
If you can not ping the ISP gateway in this situation, then it's unlikely to be a Check Point issue (or it could be a basic networking issue).
If you can ping the ISP gateway in this situation, then:
- fw fetch localhost to reload the policy to the cluster member
- Open a second ssh session to the cluster member
- Attempt to ping the ISP gateway from one session while running tcpdump on the other.
If you can see ping packets leave your gateway and responses not come back, then it's likely an issue with your switch configuration.
If you can see ping packets come back and the ping is not successful, then it might be a Check Point configuration issue and I recommend working with the Check Point TAC: Contact Support | Check Point Software
If none of this makes any sense, I strongly suggest working with your local Check Point partner or SE who can work with you one on one.
If you need a pointer to who to contact, please send me a private message and I will connect you.