<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNMP being secretly dropped by &amp;quot;fwpslglue_chain Reason: PSL Drop: ASPII_MT&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62178#M12411</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2128"&gt;@Darren_Fine&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; was right.&lt;/P&gt;
&lt;P&gt;I had the same problem with customers and the following &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97876&amp;amp;partition=Advanced&amp;amp;product=Security" target="_self"&gt;sk97876&lt;/A&gt; helped.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when everything's solved, that's great. &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 08 Sep 2019 09:29:49 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2019-09-08T09:29:49Z</dc:date>
    <item>
      <title>SNMP being secretly dropped by "fwpslglue_chain Reason: PSL Drop: ASPII_MT"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/61516#M12406</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Had an interesting problem today - snmp was &lt;U&gt;not&lt;/U&gt; working through an R80.10 firewall with JHF 112.&lt;/P&gt;&lt;P&gt;All the logs showed it was being allowed through on &lt;U&gt;both&lt;/U&gt; the security policy and the application control layer.(which led most of the firewall admins to tell the network monitoring guys that its their issue...hahaha)&lt;/P&gt;&lt;P&gt;However when this was escalated I ran a fw ctl zdeug drop and low and behold..... found the infamous "dropped by fwpslglue_chain Reason: PSL Drop: ASPII_MT" for this traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since I have encountered this error before and it seems it can be for numerous blades I logged a call to see if TAC could give me a good idea on how to track this down .(thought maybe they would have some great way to isolate what can cause this by now..)&lt;/P&gt;&lt;P&gt;The only idea they had was to install latest JHF &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anyhow - after doing that in a change window (the new JHF did not help ) - I tried switching off IPS which made no difference. I then switched off application control and what do you know - snmp started working. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the end the solution was to make a rule higher up in the Application control layer rulebase allowing this ,&lt;/P&gt;&lt;P&gt;(even though there was a rule further down allowing this and the firewall logged as being allowed on that rule.... very misleading....)&lt;/P&gt;&lt;P&gt;So I just thought I would share this in case this assists anyone else out there ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 22:04:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/61516#M12406</guid>
      <dc:creator>Darren_Fine</dc:creator>
      <dc:date>2019-08-29T22:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP being secretly dropped by "fwpslglue_chain Reason: PSL Drop: ASPII_MT"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/61551#M12407</link>
      <description>&lt;P&gt;Hello, looking for any domain object without FQDN flag marked.... this situation in r80.10 bring a lot of problems...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 13:58:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/61551#M12407</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-08-30T13:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP being secretly dropped by "fwpslglue_chain Reason: PSL Drop: ASPII_MT"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62160#M12408</link>
      <description>SNMP is one of those services that's handled in the firewall (meaning it doesn't require App Control).&lt;BR /&gt;Did the drop message provide a clue about what rule might be the culprit?</description>
      <pubDate>Sat, 07 Sep 2019 23:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62160#M12408</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-07T23:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP being secretly dropped by "fwpslglue_chain Reason: PSL Drop: ASPII_MT"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62173#M12409</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2128"&gt;@Darren_Fine&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In firewall rulebase, the service may be evaluated before evaluating the source or the destination.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Workaround:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) Create a new customer service for SNMP and set the &lt;STRONG&gt;protocol type&lt;/STRONG&gt; to "&lt;STRONG&gt;none&lt;/STRONG&gt;". &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Now&amp;nbsp;&lt;STRONG&gt;unchecking&lt;/STRONG&gt; the box '&lt;STRONG&gt;Match for 'Any&lt;/STRONG&gt;'' in the new customer service.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) Use the new customer service in the rule.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) Install policy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;More to PSL/PXL can you read here:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Security-Gateway-Architecture-Logical-Packet-Flow/td-p/41747" target="_self"&gt;R80.x Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2019 08:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62173#M12409</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-09-08T08:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP being secretly dropped by "fwpslglue_chain Reason: PSL Drop: ASPII_MT"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62176#M12410</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reading my post and for the reply&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;there was only allows in the normal firewall logs for both firewall rules and application rules (its a legacy rulebase so they in different layers). I only saw the drop when doing the debug ..with the error mentioned in the subject.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Creating the allow snmp rule in the application control layer solved the problem so not sure how it would not require application control ?&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;it did look like the rule was evaluated and found to be allowed (at least this is what the logs said). I did see a knowledge base that mentioned the steps you listed but some snmp traffic was working fine so I did not go that way .. As mentioned the addition of an application control rule for snmp seems to have fixed the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So its definitely working from the application control rule addition but I am now confused since you guys seem to think this should &lt;U&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/U&gt; have been the solution &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2019 09:05:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62176#M12410</guid>
      <dc:creator>Darren_Fine</dc:creator>
      <dc:date>2019-09-08T09:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP being secretly dropped by "fwpslglue_chain Reason: PSL Drop: ASPII_MT"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62178#M12411</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2128"&gt;@Darren_Fine&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; was right.&lt;/P&gt;
&lt;P&gt;I had the same problem with customers and the following &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97876&amp;amp;partition=Advanced&amp;amp;product=Security" target="_self"&gt;sk97876&lt;/A&gt; helped.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when everything's solved, that's great. &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2019 09:29:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62178#M12411</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-09-08T09:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP being secretly dropped by "fwpslglue_chain Reason: PSL Drop: ASPII_MT"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62334#M12412</link>
      <description>App Control will be involved if there were other rules before the SNMP rule that require App Control.&lt;BR /&gt;This applies even if the final matching rule doesn't require it. &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;BR /&gt;By putting a specific SNMP rule at/near the top, you avoid this.</description>
      <pubDate>Mon, 09 Sep 2019 22:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-being-secretly-dropped-by-quot-fwpslglue-chain-Reason-PSL/m-p/62334#M12412</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-09T22:23:39Z</dc:date>
    </item>
  </channel>
</rss>

