sk183124 - Cannot access ClusterXL Standby member through Bridge interface

Cannot access ClusterXL Standby member through Bridge interface

Symptoms

Example packet capture command and output:

[Expert@HostName:0]# cppcap -f "host 192.168.10.200"

23:43:17.542796 In [eth2] 192.168.10.200 > 192.168.1.4 IPP 1

dropped by fw_cluster_ttl_anti_spoofing Reason: ttl check drop;

dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;

Configuring the kernel parameters as per sk105899 does not resolve the issue.

Cause

The current ClusterXL design does not support this traffic flow. Here is the brief diagram of the traffic flow that also applies for traffic initiates from the Standby member:

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix configuration instructions:

Refer to sk168597 - How to install a Hotfix.

Note: If the Cluster Virtual IP is enabled on the Management interface and the specific traffic (for example, updating IPS, Anti-Bot, or Anti-Virus signatures) initiated by the Security Gateway needs to go through the bridge interface, to make it work, follow sk43807: Anti-Virus / URL Filtering / IPS update fails on the Standby member of ClusterXL in High Availability mode or sk34180: Outgoing connections from cluster members are sent with cluster Virtual IP address instead of member's Physical IP address to make the cluster member use its physical IP address for initiating the traffic.

Step 1: Apply the required kernel parameters on each Cluster Member.

  1. Connect to the command line on the Security Gateway / each Cluster Member.

  2. Log in to the Expert mode.

  3. Back up the current fwkern.conf and simkern.conf files.

[Expert@HostName:0]# cp -v $FWDIR/boot/modules/fwkern.conf{,_ORIGINAL}

`[Expert@HostName:0]# cp -v $PPKDIR/conf/simkern.conf{,_ORIGINAL}`
  1. Add these kernel parameters to the fwkern.conf file.

Note: Spaces and comments are not allowed.

[Expert@HostName:0]# vi $FWDIR/boot/modules/fwkern.conf

`fwha_silent_standby_mode=1`  
`fw_local_interface_anti_spoofing=0`  
`fw_antispoofing_enabled=0`  
`fwx_bridge_use_routing=2`  
`fwx_bridge_reroute_enabled=1`
  1. Add this kernel parameter (spaces and comments are not allowed) to the simkern.conf file.

Note: Spaces and comments are not allowed.

[Expert@HostName:0]# vi $PPKDIR/conf/simkern.conf

`sim_anti_spoofing_enabled=0`
  1. Reboot the Security Gateway / Cluster Member.

Step 2: Disable Extended Cluster Anti-Spoofing.

  1. Open SmartConsole.

  2. Navigate to Cluster Object Properties > Network Management > Advanced.

  3. Uncheck the option Enabled Extended Cluster Anti-Spoofing.

  4. Install the Access Control policy.

  5. Test traffic to confirm the resolution.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.