Forum Discussion
jal1230_40013 Nimbostratus
Nimbostratus
Oct 16, 2012Auto last hop enabled with Checkpoint firewall
 We have a pair of F5 LTM 3900's running version 11.1. We were able to ping Virtual servers from our Internal hosts thru a Checkpoint cluster. Once we turned auto-last hop on per vlan we can no longer...
jal1230_40013 Nimbostratus
Nimbostratus
Oct 23, 2012Yes the servers are on the same subnet as the F5's The gateway for the subnets themsleves are the checkpoint, we have a special subnet for the Virtual addresses, that when a transaction comes in it goes thru the checkpoints, to the F5 and than to the server. We do have default routes setup for all the transit networks back to the checkpoint. Before we turned ALH on to fix a issue we were able to ping the Virtual address the tcpdumps do show the ICMP packet talking between the devices. I agree that with ALH on the issue is related to the way Checkpoint uses the mac address.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects