<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Drops &amp;quot;TCP Out of Sequence&amp;quot; even after creating excepcions in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123344#M17692</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;We are troubleshooting a random issue with a connection between 2 internal hosts and some external servers on a cloud provider. We don't know if it is related to the issue or not, but we observe in the firewalls logs some "TCP out of state" packet drop.&lt;/P&gt;&lt;P&gt;Most of the drops have "ACK" as TCP flag, and some "PUSH-ACK", as shown on the screenshots attached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we went to Inspection Settings and for our gateway we added the source IPs (only the source, Any destination) and the destination port (443) as exception for the protection "TCP out of Sequence". However nothing has changed, and the gateways keep dropping the packets for time to time.&lt;/P&gt;&lt;P&gt;The gateway cluster is a 4000 series running R80.10&lt;/P&gt;&lt;P&gt;Any help on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ACK.png" style="width: 802px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12502iDBC6F48269F9BFEA/image-size/large?v=v2&amp;amp;px=999" role="button" title="ACK.png" alt="ACK.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PUSH ACK.png" style="width: 801px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12503i5813AE860D3E8362/image-size/large?v=v2&amp;amp;px=999" role="button" title="PUSH ACK.png" alt="PUSH ACK.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jul 2021 14:52:31 GMT</pubDate>
    <dc:creator>arcotangente</dc:creator>
    <dc:date>2021-07-08T14:52:31Z</dc:date>
    <item>
      <title>Drops "TCP Out of Sequence" even after creating excepcions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123344#M17692</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;We are troubleshooting a random issue with a connection between 2 internal hosts and some external servers on a cloud provider. We don't know if it is related to the issue or not, but we observe in the firewalls logs some "TCP out of state" packet drop.&lt;/P&gt;&lt;P&gt;Most of the drops have "ACK" as TCP flag, and some "PUSH-ACK", as shown on the screenshots attached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we went to Inspection Settings and for our gateway we added the source IPs (only the source, Any destination) and the destination port (443) as exception for the protection "TCP out of Sequence". However nothing has changed, and the gateways keep dropping the packets for time to time.&lt;/P&gt;&lt;P&gt;The gateway cluster is a 4000 series running R80.10&lt;/P&gt;&lt;P&gt;Any help on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ACK.png" style="width: 802px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12502iDBC6F48269F9BFEA/image-size/large?v=v2&amp;amp;px=999" role="button" title="ACK.png" alt="ACK.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PUSH ACK.png" style="width: 801px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12503i5813AE860D3E8362/image-size/large?v=v2&amp;amp;px=999" role="button" title="PUSH ACK.png" alt="PUSH ACK.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 14:52:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123344#M17692</guid>
      <dc:creator>arcotangente</dc:creator>
      <dc:date>2021-07-08T14:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Drops "TCP Out of Sequence" even after creating excepcions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123351#M17693</link>
      <description>&lt;P&gt;Why R80.10 and not a later release?&lt;BR /&gt;Regardless a TAC case may be necessary to get to the bottom of this.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 15:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123351#M17693</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-08T15:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Drops "TCP Out of Sequence" even after creating excepcions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123411#M17705</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We haven't had any issues with R80.10 so haven't considered upgrading to a later release.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, why after we put the IP's under exceptions in the Inspection Settings these drops are still happening? is not that the right place to do it? which could be the cause of seeing many ACKs drops and some PUSH-ACKs drops?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 10:33:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123411#M17705</guid>
      <dc:creator>arcotangente</dc:creator>
      <dc:date>2021-07-09T10:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Drops "TCP Out of Sequence" even after creating excepcions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123457#M17735</link>
      <description>&lt;P&gt;Per our original schedule, R80.10 should be End of Support by now, but we extended it to January 2022.&lt;BR /&gt;There are numerous improvements in more recent releases.&lt;/P&gt;
&lt;P&gt;In any case, you're modifying a protection related to TCP sequence numbers, which has nothing to do with this.&lt;BR /&gt;What you probably want to do is:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk11088" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk11088&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jul 2021 00:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Drops-quot-TCP-Out-of-Sequence-quot-even-after-creating/m-p/123457#M17735</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-10T00:02:14Z</dc:date>
    </item>
  </channel>
</rss>

