- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm running R81.10 with JF 78 in a lab environment to try and understand VSX but I am having a weird issue and not sure if its NAT or ARP related or not. I have a machine behind each VS in a different subnet and I am able to successfully ping each other but I am unable to ping the internet router.
fw monitor shows the traffic entering the physical interface (i and I) and out the warp interface (o and O) but I dont see the return the traffic. I have automatic static NAT set and I see the NAT being applied for both small o and big O but no return traffic.
Its my understanding that the Virtual Switch is just a simple layer 2 switch and fw monitor doesn't show any traffic on the outgoing physical interface but I suspect that is expected behavior. tcpdump does show the NATted traffic egressing but no return traffic.
I could see the arp on the Virtual System was coming up as incomplete and put in a static arp entry in to see if that would fix the issue, but still not joy.
Is there a way to see the mac address table? Since its a L2 device I am not going to see ARP. It shouldn't be a routing issue as these are all directly connected subnets and I am propagating all the routes as well.
High Level Diagram
Internet Router
|
Virtual Switch
| | |
VS2 VS3 VS4
FW1 FW2 FW3
Any ideas on where to check next? I am not sure if i'm missing something as my experience has been with physical gateways and not VSX.
I assume you are pinging the routes from the internal networks and not VSs themselves. The latter won't work. If you do, please run fw monitor as the first diagnostics tool.
Yes I am pinging them from networks behind the VSs.
In fw monitor I am able to see the traffic enter the physical interface (ethX) and egress out the warp interface. I am pretty sure its a L2 issue at this point.
Are you able to attach the actual fw monitor capture file here and give us the IP addresses affected? If we could open in it in wireshark, it may shed more light as to why its failing. Though, I agree with you, sounds like L2 issue to me as well.
If you do traceroute, where exactly does it fail?
I am pretty sure I have found the issue. I think this is a VMware issue and its due to promiscuous mode not being enabled on the virtual switch. I have reached out to the team that manages it and its also NOT something I can get changed.
I may try and rebuild this LAB in workstation instead and hopefully I will have more luck.
Yep, that must be it.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY