Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mahesh027cse1
Explorer

How to Check Point maintaining connection for GRE traffic

Hi,

Can anyone please help to understand how Checkpoint firewall,  GRE through traffic handling.

I am getting an issue.  GRE is configured on both end route and in between i have CheckPoint firewall.When a fail-over (primary to secondary) occurs, GRE is stop working and then i need to request with network person to bounce the Router GRE terminated physical port. I need to understand CheckPoint GRE through traffic handling, and how it maintain in connection table, i tried to find documents but no luck.

Route --->CheckPoint ---> Router  

 

 

0 Kudos
5 Replies
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Is the connection subject to NAT and does the issue occur only on Failover or also during policy installation?

Service object:

gre.png


CCSM R77/R80/ELITE
0 Kudos
mahesh027cse1
Explorer

There is no NAT for GRE traffic. But when we did fail-over (Primary to secondary), We need to reset the GRE interface to establish connection.  Can you please help to understand how Check Point maintaining state-full fail-over for GRE through traffic.  

"Synchronize connection if State Synchronization is enabled on the cluster" is by default enabled for the GRE object.

0 Kudos
amdhim0004
Contributor

Hi @mahesh027cse1 

I know the solution.

But first can you please tell me if you have Primary/Secondary two GREs setup or only Single Tunnel?

Thanks 

Amandeep

0 Kudos
DT-ISP-DD
Explorer

Hi amdhim0004,

can you please tell me your solution? I have a similar issue with GRE at an R80.30 Cluster.

Thanks!

0 Kudos
Kevin_Taverner
Explorer

Can you tell us what your solution is?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events