> Source: [sk138872](https://support.checkpoint.com/results/sk/sk138872)

# sk138872 - Ping fails after ISP redundancy fails over

| Property | Value |
|----------|-------|
| Solution ID | sk138872 |
| Date Created | 2018-11-01 |
| Last Modified | 2022-07-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * A ping command issued from internal host failing once the ISP fails over, while all other connections are switching to the new ISP connection and are working as expected.
* The command `#fw ctl zdebug drop` shows "dropped by misp_rt_chain Reason: Interface is inactive".
* The command `#tcpdump -Peni any -s 0 host x.x.x.x` shows ICMP echo request packets only.

## Cause

When initiating a ping command an entry(5-tuples) is created in the connection table with a timeout of 30 seconds. The connection table entry holds the ISP which was used when the connection was first recorded. Once the ISP fails over, the existing connections will fail until they are recorded again with the new active ISP.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
