- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Mates!
I deploy a new Cluster and SMS and this cluster has 2 interfaces(eth0 and eth1):
eth0(member1 - 172.31.1.2, member2 - 172.31.1.3, VIP - 172.31.1.1)
eth1(member1 - 172.31.0.8, member2 - 172.31.0.9, VIP - 172.31.0.10)
When I ping physical interfaces (.8 and .9 or .3 and .4) it replies normally and I can access ssh and web portal from that, but when I try to ping or access the VIP (.10 or .1) it does not respond. This is a brand new environment. I deploy many others and I didn't have to make any changes for it to work.
Any advice to make it work?
This is a distributed Cluster(2 members HA Active/Standby) + SMS R81.10 JHF take 87 all open servers Virtual appliances
Thank you!
See sk102118:
It is not possible to ping or connect over SSH to ClusterXL VIP address
or sk106425:
Connections through cluster to physical IP address of ClusterXL Standby member / VRRP Backup member ...
See sk102118:
It is not possible to ping or connect over SSH to ClusterXL VIP address
or sk106425:
Connections through cluster to physical IP address of ClusterXL Standby member / VRRP Backup member ...
Hello @HeikoAnkenbrand
I tried this sks, but nothing changed. In my LAB I noticed that sometimes the VIP reply ping and sometimes don't on eth0. In eth1 I can ping VIP and interfaces IPs simultaneously normally. I'm not sure why it occurs. Any advice? Other than those already mentioned
From where you are trying to reach VIPs ?
Do you see any drops on Active member using following command (from expert) while initiating the traffic ?
fw ctl zdebug + drop | grep 172.31.1.
@JozkoMrkvickaI tried to access it from the same subnet of each interface. In the case of my lab, from the 172.12.10(eth1) I can ping simultaneously interfaces IP and the VIP, but from the 192.168.10(eth) sometimes I can ping the VIP and sometimes dont.
In the case of customer environment nither interface ping the VIP, but I can access by SSH for example.
No drops on zdebug.
Hm, I dont think thats 100% accurate. I have R81.10 cluster lab and I can perfectly ping and ssh into VIP. No changes were ever made to any files to make that work.
@the_rockIndeed this is very weird. I already made labs in other times that no were need changes to work it too.
I agree. Let me see if I can verify it in lab Monday.
I'm very grateful for your help as always @the_rock !
I will check with my colleague tomorrow if I can turn 4 CP vm's back on, as we needed to turn them off for some Aruba testing. If I can, we can circle back and I will update you.
Cheers mate.
Always willing to help the best I can @Bernardes , my pleasure mate.
Hello Mates,
I had a similar issue as Bernardes but was able to resolve it.
What I have done is to reinitiate the SIC and copy topology to interfaces. After that, I was able to ping the VIP.
I hope it helps.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 13 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Fri 14 Nov 2025 @ 10:00 AM (CET)
CheckMates Live Netherlands - Veriti, Threat Exposure ManagementWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERFri 14 Nov 2025 @ 10:00 AM (CET)
CheckMates Live Netherlands - Veriti, Threat Exposure ManagementWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY