<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Asymmetric Routing causing network slow and MTA issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-Routing-causing-network-slow-and-MTA-issue/m-p/64783#M13315</link>
    <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;Condition-based on topology (Single TE1000X, with 4-Port Bypass Interface &amp;amp; 1 LACP MTA port), please refer to below images :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topology.jpeg" style="width: 256px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2735iA530465C29D0504C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Topology.jpeg" alt="Topology.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;1. All 3 switches are in L3 mode with OSPF equal cost, meaning traffic will be asymmetric. Cannot using link bonding.&lt;BR /&gt;2. Position of Anti Spam in DMZ, and mail server in DC.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have 2 problems:&lt;BR /&gt;1. Regarding condition 1 above, when we put TE as bridging we found 3 (Three) log that we suspect causing network slow.&lt;BR /&gt;- TCP packet out of state First packet isn't Sync&lt;BR /&gt;- TCP segment out of maximum allowed sequenced. Packet dropped.&lt;BR /&gt;- ICMP reply does not match a previous request&lt;/P&gt;&lt;P&gt;2. Traffic from anti-spam to mail server already inspected by bridged interfaces instead of MTA.&lt;/P&gt;&lt;P&gt;Action :&lt;BR /&gt;1. I already disabled TCP packet out of state First packet isn't Sync on Global Properties and expert mode. Log already not show anymore after that.&lt;/P&gt;&lt;P&gt;2. I already allow TCP segment out of maximum allowed sequenced on inspection setting. But log still shows these messages.&lt;/P&gt;&lt;P&gt;3. We also already disabled ICMP reply does not match a previous request on Global Setting and expert mode but log still shows these messages too.&lt;/P&gt;&lt;P&gt;Could anybody please give me suggestion for :&lt;/P&gt;&lt;P&gt;1. How to deploy this TE with bridge mode with this condition?&lt;BR /&gt;2. How to bypass SMTP traffic from anti-spam to mail server on bridged mode because when there is double-checking Threat Emulation traffic will be drop. Or any best practice for this condition?&lt;/P&gt;&lt;P&gt;Thank you CheckMates.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Oct 2019 06:41:59 GMT</pubDate>
    <dc:creator>yudha_spt</dc:creator>
    <dc:date>2019-10-11T06:41:59Z</dc:date>
    <item>
      <title>Asymmetric Routing causing network slow and MTA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-Routing-causing-network-slow-and-MTA-issue/m-p/64783#M13315</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;Condition-based on topology (Single TE1000X, with 4-Port Bypass Interface &amp;amp; 1 LACP MTA port), please refer to below images :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topology.jpeg" style="width: 256px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2735iA530465C29D0504C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Topology.jpeg" alt="Topology.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;1. All 3 switches are in L3 mode with OSPF equal cost, meaning traffic will be asymmetric. Cannot using link bonding.&lt;BR /&gt;2. Position of Anti Spam in DMZ, and mail server in DC.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have 2 problems:&lt;BR /&gt;1. Regarding condition 1 above, when we put TE as bridging we found 3 (Three) log that we suspect causing network slow.&lt;BR /&gt;- TCP packet out of state First packet isn't Sync&lt;BR /&gt;- TCP segment out of maximum allowed sequenced. Packet dropped.&lt;BR /&gt;- ICMP reply does not match a previous request&lt;/P&gt;&lt;P&gt;2. Traffic from anti-spam to mail server already inspected by bridged interfaces instead of MTA.&lt;/P&gt;&lt;P&gt;Action :&lt;BR /&gt;1. I already disabled TCP packet out of state First packet isn't Sync on Global Properties and expert mode. Log already not show anymore after that.&lt;/P&gt;&lt;P&gt;2. I already allow TCP segment out of maximum allowed sequenced on inspection setting. But log still shows these messages.&lt;/P&gt;&lt;P&gt;3. We also already disabled ICMP reply does not match a previous request on Global Setting and expert mode but log still shows these messages too.&lt;/P&gt;&lt;P&gt;Could anybody please give me suggestion for :&lt;/P&gt;&lt;P&gt;1. How to deploy this TE with bridge mode with this condition?&lt;BR /&gt;2. How to bypass SMTP traffic from anti-spam to mail server on bridged mode because when there is double-checking Threat Emulation traffic will be drop. Or any best practice for this condition?&lt;/P&gt;&lt;P&gt;Thank you CheckMates.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 06:41:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-Routing-causing-network-slow-and-MTA-issue/m-p/64783#M13315</guid>
      <dc:creator>yudha_spt</dc:creator>
      <dc:date>2019-10-11T06:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric Routing causing network slow and MTA issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-Routing-causing-network-slow-and-MTA-issue/m-p/64861#M13316</link>
      <description>The fact you are seeing TCP Packet Out of State and the other errors suggest you have asymmetric traffic flows.&lt;BR /&gt;That is going to cause these and other kinds of issues.&lt;BR /&gt;&lt;BR /&gt;To prevent double inspection, you should be able to add a bypass rule in your Threat Prevention policy to not inspect traffic originating from your DMZ mail server to your internal mail servers.</description>
      <pubDate>Fri, 11 Oct 2019 23:21:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-Routing-causing-network-slow-and-MTA-issue/m-p/64861#M13316</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-11T23:21:50Z</dc:date>
    </item>
  </channel>
</rss>

