Forum Discussion
jal1230_40013
Nimbostratus
Oct 16, 2012Auto last hop enabled with Checkpoint firewall
We have a pair of F5 LTM 3900's running version 11.1. We were able to ping Virtual servers from our Internal hosts thru a Checkpoint cluster. Once we turned auto-last hop on per vlan we can no longer ping the Virtual servers thru the checkpoint cluster. A capture sees the traffic getting to the F5 and back to the Firewall. I was wondering if anyone has seen this problem before with Auto last hop turned on and not able to ping virtual servers.
19 Replies
Sort By
- What_Lies_Bene1
Cirrostratus
The Checkpoints running VRRP? Actually I'm not sure that matters in this scenario. Auto Last Hop is normally globally enabled by default so I'm surprised you're having issues. - jal1230_40013
Nimbostratus
The checkpoints are not running VRRP Cluster XL. I ran captures on both the Firewall and F5. The ICMP traffic gets to the F5 and The Checkpoint receives it back from the F5. You can ping the Virtual servers from the Checkpoint, however the ICMP responses never gets back to my terminal on the inside network. Once I turn Auto last hop off on the vlan on the F5 I get replies at my terminal. - What_Lies_Bene1
Cirrostratus
Forgive me if I'm stating the obvious but; - jal1230_40013
Nimbostratus
Thanks Steve for Replying. The packets does noy get dropped the logs say they are passing. The packets captures look the same both devices are receiving and sending back over the correct interfaces. I know with ALH on the packet is sent back via mac instead of the default route for some reason when the Checkpoint gets the request back from the F5 it never sends it back to the internal host (myself). We are running VMAC on our Checkpoint Cluster. - What_Lies_Bene1
Cirrostratus
Regarding the captures on the F5, do any of the MAC addresses change, either source or destination? My suspicion is that the source or destination (most likely) MAC changes with ALH on, can you double-check? - jal1230_40013
Nimbostratus
Below is the mac-address that show in the tcpdump on the F5. The first mac is the Firewall the second is the mac from the F5. The Mac does not change at least from the F5 stance. - jal1230_40013
Nimbostratus
Below is the mac-address that show in the tcpdump on the F5. The first mac is the Firewall the second is the mac from the F5. The Mac does not change at least from the F5 stance. - What_Lies_Bene1
Cirrostratus
And if you display the ARP cache on the LTM, does the ARP entry for the firewall IP list the same MAC? - jal1230_40013
Nimbostratus
No this Mac does not show in the Cache. We use a transit network between the 2 devices. - What_Lies_Bene1
Cirrostratus
OK, so the MAC you listed earlier isn't actually the firewall MAC, it's the MAC of the next hop towards the firewall?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects