- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Having weird issue in Checkpoint Cluster member.
We have configured cluster member but when i try to do telnet one of our internal server from Active node its getting succeed but same not getting succeed from Standby node.
When i analyzed logs, it seems active node physical interface ip is hidden behind respective interface cluster VIP IP as source.
In standby node, NAT not happening and it uses physical interface IP.
Now my question, how can we make config so that standby node also nat its physical ip with cluster vip for outgoing interface. i created manual NAT rule but there is no luck.
Same works when i make standby node to active by failover traffic. At the same active will become standby, so in this case it will fail in this node.
I suggest to set your standby member as a "Silent Standby"
Set these Kernel parameters:
fwha_silent_standby_mode=1
fwha_cluster_hide_active_only=0
Set the same parameters in both members.
You can set them on the fly:
fw ctl set int fwha_silent_standby_mode 1
fw ctl set int fwha_cluster_hide_active_only 0
More info:
To make it permanent see sk26202
If your management is below R80.40 you will need rules for the standby to initiate connections, as these will be evaluated in policy on the active.
Thanks for your help but unfortunately this doesn't helped me to resolve my issue.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY