<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What could be the reason behind this drop? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128268#M18675</link>
    <description>&lt;P&gt;ICMP is never accelerated by SecureXL and always goes F2F, so disabling SecureXL shouldn't have any effect on this issue.&amp;nbsp; I'm assuming this has something to do with Smart Connection Reuse, although it isn't employed for non-TCP connections/sessions, at least to my knowledge:&amp;nbsp;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk24960: "Smart Connection Reuse" feature modifies some SYN packets&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Aug 2021 23:14:13 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-08-27T23:14:13Z</dc:date>
    <item>
      <title>What could be the reason behind this drop?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128231#M18665</link>
      <description>&lt;P&gt;Hi Team, This is R80.20 and my packets are getting dropped with below error which I captured using fw ctl zdebug. There is a PBR configured on firewall for source IP x.x.x.x for Internet as destination.&lt;/P&gt;&lt;P&gt;Surprisingly web traffic works fine however only ICMP is getting dropped. Any reason&amp;nbsp; why? I tried searching through lot of SKs however none of them was pinpoint to the below error neither any one has worked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;@;3779257712;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -&amp;gt; 8.8.8.8:63298 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;&lt;BR /&gt;@;3779396743;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -&amp;gt; 8.8.8.8:63297 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;&lt;BR /&gt;@;3779497504;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -&amp;gt; 8.8.8.8:63296 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;&lt;BR /&gt;@;3779590799;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -&amp;gt; 8.8.8.8:63295 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 12:07:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128231#M18665</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-27T12:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: What could be the reason behind this drop?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128232#M18666</link>
      <description>&lt;P&gt;I had seen this before be caused by securexl. If you disable it and it works, then below would apply.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Permanently set the value of kernel parameter&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;CODE&gt;fwconn_set_esp_after_nat_links&lt;/CODE&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;(one) - follow&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk26202" target="_blank" rel="noopener"&gt;sk26202 (Changing the kernel global parameters for Check Point Security Gateway)&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 12:11:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128232#M18666</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-27T12:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: What could be the reason behind this drop?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128233#M18667</link>
      <description>&lt;P&gt;Yeah initially I thought so hence I had disabled securexl as well however it did not work. fwaccel off is the only thing that I need to do?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 12:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128233#M18667</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-27T12:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: What could be the reason behind this drop?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128234#M18668</link>
      <description>&lt;P&gt;Thats all I found, sorry brother.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 12:40:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128234#M18668</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-27T12:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: What could be the reason behind this drop?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128268#M18675</link>
      <description>&lt;P&gt;ICMP is never accelerated by SecureXL and always goes F2F, so disabling SecureXL shouldn't have any effect on this issue.&amp;nbsp; I'm assuming this has something to do with Smart Connection Reuse, although it isn't employed for non-TCP connections/sessions, at least to my knowledge:&amp;nbsp;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk24960: "Smart Connection Reuse" feature modifies some SYN packets&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 23:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128268#M18675</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-27T23:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: What could be the reason behind this drop?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128269#M18676</link>
      <description>&lt;P&gt;True true...I remember having to do that sk once before when customer upgraded from R80.20 to R80.30, but never related to errors in the post.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 23:07:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128269#M18676</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-27T23:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: What could be the reason behind this drop?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128405#M18702</link>
      <description>&lt;P&gt;Any way I now removed the PBR and it started working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 05:07:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-could-be-the-reason-behind-this-drop/m-p/128405#M18702</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-31T05:07:27Z</dc:date>
    </item>
  </channel>
</rss>

