Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
stallwoodj
Collaborator
Collaborator
Jump to solution

Outbound Traffic from Standby Member

Hi,

On R81.20 cluster, outbound ICMP and TCP traffic from secondary member is shown with "fw monitor" to be going out the primary Active member (as below). 

As I'm trying to troubleshoot a physical link, please could you remind me what settings in Global / GuiDB / def I need to configure these days to always source outbound (internet) traffic from the local gateway?

Thanks

Jamie

 

[vs_0][ppak_0] eth3:i[44]: aa.bb.cc.158 -> dd.ee.ff.12 (ICMP) len=84 id=21637
ICMP: type=8 code=0 echo request id=31027 seq=1
[vs_0][fw_0] eth3:i[44]: aa.bb.cc.158 -> dd.ee.ff.12 (ICMP) len=84 id=21637
ICMP: type=8 code=0 echo request id=31027 seq=1
[vs_0][fw_0] eth3:I[44]: aa.bb.cc.158 -> dd.ee.ff.12 (ICMP) len=84 id=21637
ICMP: type=8 code=0 echo request id=31027 seq=1
[vs_0][fw_0] eth0:o[44]: aa.bb.cc.158 -> dd.ee.ff.12 (ICMP) len=84 id=21637
ICMP: type=8 code=0 echo request id=31027 seq=1
[vs_0][fw_0] eth0:O[44]: aa.bb.cc.156 -> dd.ee.ff.12 (ICMP) len=84 id=21637
ICMP: type=8 code=0 echo request id=11459 seq=1

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin
5 Replies
PhoneBoy
Admin
Admin
stallwoodj
Collaborator
Collaborator

Thanks Dameon! I couldn't work out the right question to search for in Support Center 🙂

However, the packets are still egressing the Active member through PerfomancePak connectivity, so I'm still having trouble testing the Standby's physical interface.

Cheers

Jamie

0 Kudos
Adam276
Contributor

I found this.  It doesn't mention anything about it not applying anymore...

"Changing the value of "perform_cluster_hide_fold" field does not change the ClusterXL behavior"
https://support.checkpoint.com/results/sk/sk154272

stallwoodj
Collaborator
Collaborator

Thanks,

The value stops the NAT but doesn't prevent the traffic from egressing via the active firewall!

0 Kudos
the_rock
Legend
Legend

That sk says there is some sort of fix for that...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events