<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Packet replying does not match initial connection (R80.10) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65540#M12187</link>
    <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;I have a problem about checkpoint R80.10 like this:&lt;/P&gt;&lt;P&gt;I create a rule like below:&lt;/P&gt;&lt;P&gt;From IP_SOURCE to IP_DST, service : TCP_8082&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic1.png" style="width: 820px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2818i0F0AF846404F4B23/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic1.png" alt="pic1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;But when I search log drop from DST to SRC, I saw that&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;replying packet get dropped&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;because CP does not see it as a replying packet; (Checkpoint think this is new connection from DST to SRC and simply drop it by cleanup rule)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic2.png" style="width: 806px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2820i58A5A74950B2551E/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic2.png" alt="pic2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;So please let me know why or any step to troubleshoot it?&lt;/P&gt;&lt;P&gt;Thank a lot!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Oct 2019 01:32:15 GMT</pubDate>
    <dc:creator>minhhaivietnam</dc:creator>
    <dc:date>2019-10-23T01:32:15Z</dc:date>
    <item>
      <title>Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65540#M12187</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;I have a problem about checkpoint R80.10 like this:&lt;/P&gt;&lt;P&gt;I create a rule like below:&lt;/P&gt;&lt;P&gt;From IP_SOURCE to IP_DST, service : TCP_8082&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic1.png" style="width: 820px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2818i0F0AF846404F4B23/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic1.png" alt="pic1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;But when I search log drop from DST to SRC, I saw that&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;replying packet get dropped&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;because CP does not see it as a replying packet; (Checkpoint think this is new connection from DST to SRC and simply drop it by cleanup rule)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pic2.png" style="width: 806px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2820i58A5A74950B2551E/image-size/large?v=v2&amp;amp;px=999" role="button" title="pic2.png" alt="pic2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;So please let me know why or any step to troubleshoot it?&lt;/P&gt;&lt;P&gt;Thank a lot!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 01:32:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65540#M12187</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2019-10-23T01:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65572#M12188</link>
      <description>&lt;P&gt;The firewall is dropping this reply probably because it has no record of it in the state table.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the screenshot you provided, can you find the earlier log entry for this particular connection showing when the connection started (Accept action)?&amp;nbsp; Source port will be 36366 and destination port will be 8082 for the connection start.&amp;nbsp; To get more visibility into how these connections are starting and ending enable Accounting on the rule in the Track column which will show you how long the connection lasted and when it ended, standard logging of a connection only shows when the connection started.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For even more info about connection state transitions see &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101221&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk101221: &lt;STRONG&gt;TCP&lt;/STRONG&gt; &lt;STRONG&gt;state&lt;/STRONG&gt; &lt;STRONG&gt;logging&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 13:49:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65572#M12188</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-10-22T13:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65612#M12189</link>
      <description>&lt;P&gt;Thank for reply Hall,&lt;/P&gt;&lt;P&gt;I search log from SRC to DST with port 8082,&lt;SPAN&gt;36366&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="allow.png" style="width: 786px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2824iE683BA4F05D280D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="allow.png" alt="allow.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;=&amp;gt; see that the time is same as the time of dropped packet of replying direction(1:46:53PM) . So maybe the initial connection was closed right after it was established, then replying packet was dropped because of no connection exist.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;=&amp;gt; Do you agree with my guess?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 01:49:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65612#M12189</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2019-10-23T01:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65629#M12190</link>
      <description>&lt;P&gt;the logs are from two different FWs:&amp;nbsp;DC-Internet-Fw-&lt;STRONG&gt;01&lt;/STRONG&gt; and&amp;nbsp;&amp;nbsp;DC-Internet-Fw-&lt;STRONG&gt;02&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;may be Async Routing, misconfigured VRRP etc.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 07:29:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65629#M12190</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2019-10-23T07:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65634#M12191</link>
      <description>&lt;P&gt;Thanks Haas,&lt;/P&gt;&lt;P&gt;In my situation, 2 FWs are cluster with each other(using load sharing mode). How can I adjust for replying packet to go through&amp;nbsp;&lt;SPAN&gt;DC-Internet-Fw-&lt;/SPAN&gt;&lt;STRONG&gt;02 (same as intial direction)&amp;nbsp;&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;or any solutions for this dropping?&lt;/P&gt;&lt;P&gt;(Now I am having to add a explicit rule to allow replying packet (from DST to SRC , service: tcp-high-port))&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks!!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 08:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65634#M12191</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2019-10-23T08:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65638#M12192</link>
      <description>&lt;P&gt;just curious: is the packet droped because of "out of state" or just by the cleanup rule ?&lt;/P&gt;&lt;P&gt;or did you disable to drop out of state packets:&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="out-of-state.png" style="width: 290px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2826iA6455C5931FEB06B/image-dimensions/290x270?v=v2" width="290" height="270" role="button" title="out-of-state.png" alt="out-of-state.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 09:24:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65638#M12192</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2019-10-23T09:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65646#M12193</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It is dropped by cleanup rule (as pic in #1 my post)&lt;/P&gt;&lt;P&gt;Here is my screen (already disable drop out of state)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="global.png" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2828iE93F5B373E647521/image-size/large?v=v2&amp;amp;px=999" role="button" title="global.png" alt="global.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 09:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65646#M12193</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2019-10-23T09:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Packet replying does not match initial connection (R80.10)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65671#M12194</link>
      <description>&lt;P&gt;You can enable the Sticky Decision Function, but be careful, this will disable SecureXL.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 14:02:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-replying-does-not-match-initial-connection-R80-10/m-p/65671#M12194</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2019-10-23T14:02:39Z</dc:date>
    </item>
  </channel>
</rss>

