<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet leaves firewall, but doesnt reach peer device in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67670#M12071</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;One other tool for packet captures is&amp;nbsp;&lt;STRONG&gt;CPPCAP&amp;nbsp;&lt;/STRONG&gt;as described in&amp;nbsp;&lt;SPAN&gt;sk141412. In addition, you can correlate the captured output with that of the logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can I confirm we are dealing with an IPSec site-to-site VPN here? If not, please elaborate on the topology in question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 17 Nov 2019 15:39:35 GMT</pubDate>
    <dc:creator>Nick_Doropoulos</dc:creator>
    <dc:date>2019-11-17T15:39:35Z</dc:date>
    <item>
      <title>Packet leaves firewall, but doesnt reach peer device</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67666#M12070</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the scenario&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint ( 3 subnets) ------ &amp;gt; Symantec decrypter (2 subnets reaches, 3rd subnet doesnt reach).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Above devices are connected back to back, initially there are subnet with /27 routed between these two devices, post ip exhaust , one more /27 was added.&lt;/P&gt;&lt;P&gt;traffic reaches from checkpoint to symantec decrytor device, now second subnet is also exhausted.&lt;/P&gt;&lt;P&gt;now we are planning with 3 rd subnet in symantec side.&lt;/P&gt;&lt;P&gt;we could see packet leaving checkpoint exit interface through fwmonitor, but there is no received packets in packet capture of ssl decryptor.&lt;/P&gt;&lt;P&gt;Is there an alternate option to check packet leaving checkpoint other than fwmonitor or tcpdump.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;BSB&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 14:53:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67666#M12070</guid>
      <dc:creator>bsb</dc:creator>
      <dc:date>2019-11-17T14:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Packet leaves firewall, but doesnt reach peer device</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67670#M12071</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;One other tool for packet captures is&amp;nbsp;&lt;STRONG&gt;CPPCAP&amp;nbsp;&lt;/STRONG&gt;as described in&amp;nbsp;&lt;SPAN&gt;sk141412. In addition, you can correlate the captured output with that of the logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can I confirm we are dealing with an IPSec site-to-site VPN here? If not, please elaborate on the topology in question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 15:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67670#M12071</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2019-11-17T15:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Packet leaves firewall, but doesnt reach peer device</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67678#M12072</link>
      <description>&lt;P&gt;Seeing the packet hit capture point O in &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; just means it is leaving the Check Point code heading for the egress interface in Gaia.&amp;nbsp; Use &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; with the &lt;STRONG&gt;-e&lt;/STRONG&gt; option to see the destination MAC address of the problematic traffic and verify that the packet is actually leaving. If you don't see it leaving, run &lt;STRONG&gt;fw ctl zdebug drop&lt;/STRONG&gt; to see why, my guess would be outbound antispoofing enforcement or you've got some kind of problem with inconsistently applied subnet masks for the new subnet.&lt;/P&gt;
&lt;P&gt;If it is the same destination MAC as for subnet traffic that is working, it is not a firewall problem.&amp;nbsp; If the destination MAC is wrong that would explain why it is not showing up at the next hop as the switch will not forward it to that port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 22:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67678#M12072</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-11-17T22:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Packet leaves firewall, but doesnt reach peer device</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67701#M12073</link>
      <description>When you try to ping an IP from the new range, as it now should be enabled on the Symantec, do you get a reply? If not do you see an arp for any of the IP's in that range, I presume you have a route for the new range pointing to the Symantec?</description>
      <pubDate>Mon, 18 Nov 2019 08:44:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-leaves-firewall-but-doesnt-reach-peer-device/m-p/67701#M12073</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-11-18T08:44:00Z</dc:date>
    </item>
  </channel>
</rss>

