- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I have set up a LAB environment on VMWARE and in my lab setup i am not able to reach the web UI of my second gateway for running initial wizard for further configuration and SIC integration with the manager.
My Manager, Client Machine (windows VM) and first Gateway all are in same network 192.68.0.1/24, however interface eth2 of GW-1 has 67.83.0.111/24 and my GW-2 management interface eth0 has 67.83.0.114/24 so both my GW-1 eth2 and GW-2 eth0 are in same network but still after multiple attempts i am not able to reach my web UI of GW-2.
I have allowed all the required traffic on my GW1-1.
I am getting destination host unreachable error on client machine and on GW-1 cli kindly help.
What version was installed?
What do you see in the logs when you try to access GW-2?
Have you done any troubleshooting on the gateway itself (e.g. tcpdump) to see if the traffic is even reaching the gateway?
The version installed on all the devices is R81.10
in the logs I can see that the traffic is showing accepted for the http connection that I initiate from my client machine, however i am not able to get any icmp logs which I initiate from client machine as well as from the Gateway-1 towards Gateway-2
Is GW-1 performing NAT?
What routes does GW-2 have?
Gateway -2 has a default route to route traffic towards network 67.83.0.0/24 via interface eth0 on which the IP configured is 67.83.0.114/24. also gateway -2 has no NAT on it.
Gateway -1 has a route for same destination via interface eth2 which has the IP configured as 67.83.0.111/24
Gateway -1 also has a default route which routes the traffic via 192.168.0.1/24 which is gateway of the management network configured in my topology.
The routing tables should match on both cluster members.
I can tell you that 9 times out of 10, when you see the message destination host unreachable, it means proper route is missing.
Andy
Can you suggest what should be the proper routes in this topology scenario?
Are those part of cluster or two gateways where traffic is passing through for another gateway through first?
I am still not getting your scenario? what is your source and destination IP then>?
As phoneboy said, routing has to match on both members for this to work right.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 20 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY