- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Since yesterday we are experiencing a rather unusual and strange issue with one of our 3100 R81.20 (Take 26). Traffic stopped flowing all of a sudden. From the logs it was registered going out but no inbound traffic was happening. After a lot of fumbling around, we've changed the gateway External IP address and traffic begun flowing again. This morning, same issue. Reverting the IP address back to the original solved, at least by now. Has anyone ever experienced such an problem?
Regards
Rui Meleiro
Not using VMAC mode. Nevertheless, after a power cycle to the ISP router the problem was solved as of now. I guesstimate the problem was on that router and not the appliance.
Sounds like an urgent TAC case
Hi Rui,
ARP issue perhaps? Next time it happens, try doing a cluster failover, or if it's a single appliance run the following command:
#arping -c 4 -A -I eth1 10.20.10.20
Just replace 'eth1' with the correct interface and the IP address with whatever is configured on that interface.
Thank you for your insight, Ruan. My first though was also ARP, and have flushed all dynamic ARP tables on switchs and routers, including the appliance. Not sure how an arping probe will further that, but I'll make sure to check it.
What does fw ctl arp show when the issue occurs? Are you using a cluster?
Hadn't had the chance to get that while the issue was happening. At this moment - last IP address change is ongoing without any issues - I get all of the IP addresses listening on the same segment, using the same interface mac address the gateway has. Gateway IP is x.x.x.27 and IPs x.x.x.28 and x.x.x.29 are shown. This is a standalone gateway.
We upgraded customer recently to R81.20 and only weird issue I recall they had was that lost of users had their MS teams and zoom get disconnected randomly, but it was fixed by allowing all users to access all ms teams/zoom apps by creating a rule within internal layey in network ordered layer.
I cant say why that happened, but Im fairly sure its due to R81.20, as it was never an issue before upgrade (R80.40 and R81.10)
Anyway, onto your problem. I agree with the guys, sounds like an ARP problem. Do fw ctl zrp as @Timothy_Hall advised, but I also second what @_Val_ said. It definitely warrants call to TAC, as it rather sounds like an urgent problem.
You can also simply run arp when it works and when its broken and compare.
Andy
I have seen proxy ARP issues with R81.20 Take 24 so very interested to see the output of fw ctl arp when it happens. I assume you are not using VMAC mode?
Not using VMAC mode. Nevertheless, after a power cycle to the ISP router the problem was solved as of now. I guesstimate the problem was on that router and not the appliance.
Thank you all for the valuable input.
Happy to hear its fixed.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 22 | |
| 17 | |
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY