<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CCP drop packets in R81 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132323#M19587</link>
    <description>&lt;P&gt;You mean to Disable the implied rule?&lt;/P&gt;&lt;P&gt;We kept it to log the traffic getting denied on the firewall, and it's really important for troubleshooting&lt;/P&gt;</description>
    <pubDate>Thu, 21 Oct 2021 07:52:44 GMT</pubDate>
    <dc:creator>Ramasubramaniya</dc:creator>
    <dc:date>2021-10-21T07:52:44Z</dc:date>
    <item>
      <title>CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132282#M19576</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We are in a progress of migrating the Checkpoint hardware from 4400 to 6600.&lt;/P&gt;&lt;P&gt;Old hardware is running on R77.30 and new hardware is already upgraded to R81.&lt;/P&gt;&lt;P&gt;Old hardware running with VRRP Cluster&lt;/P&gt;&lt;P&gt;New hardware running with ClusterXL&lt;/P&gt;&lt;P&gt;Both hardware are connecting on same switch&lt;/P&gt;&lt;P&gt;But the new Firewall cluster is experiencing the below error message.&lt;/P&gt;&lt;P&gt;@;162960;[vs_0];[tid_3];[fw4_3];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;BR /&gt;@;162960;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;BR /&gt;@;162960;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;BR /&gt;@;162960;[vs_0];[tid_2];[fw4_2];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;BR /&gt;@;162961;[vs_0];[tid_3];[fw4_3];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;BR /&gt;@;162961;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;BR /&gt;@;162961;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;BR /&gt;@;162961;[vs_0];[tid_2];[fw4_2];fw_log_drop_ex: Packet proto=17 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 781;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 17:22:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132282#M19576</guid>
      <dc:creator>Ramasubramaniya</dc:creator>
      <dc:date>2021-10-20T17:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132289#M19578</link>
      <description>&lt;P&gt;Is that implicit clean up rule number 781?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 18:26:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132289#M19578</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-20T18:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132313#M19585</link>
      <description>&lt;P&gt;Yes it is a implicit deny rule&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 05:14:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132313#M19585</guid>
      <dc:creator>Ramasubramaniya</dc:creator>
      <dc:date>2021-10-21T05:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132314#M19586</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/20849"&gt;@Ramasubramaniya&lt;/a&gt;&amp;nbsp;You don't happen to have implied rules disabled ?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 05:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132314#M19586</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2021-10-21T05:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132323#M19587</link>
      <description>&lt;P&gt;You mean to Disable the implied rule?&lt;/P&gt;&lt;P&gt;We kept it to log the traffic getting denied on the firewall, and it's really important for troubleshooting&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 07:52:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132323#M19587</guid>
      <dc:creator>Ramasubramaniya</dc:creator>
      <dc:date>2021-10-21T07:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132325#M19589</link>
      <description>&lt;P&gt;No, I was asking if Implied Rules are already disabled. If they are enabled leave them like that; problem is somewhere else.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 07:55:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132325#M19589</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2021-10-21T07:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132350#M19594</link>
      <description>&lt;P&gt;You may wish to engage TAC, because to me, if you think about it logically, since I am pretty sure your rule base had not changed, there is no reason why this would be happening. I get its clusterXL instead of VRRP, but still. So based on the drop, it shows its UDP protocol and port 8116, which is clustering, so one thing I would try to do it maybe quickly just run zdebug only for port 8116 and also fw monitor for that specific port and see what you get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 12:00:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132350#M19594</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-21T12:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132384#M19606</link>
      <description>&lt;P&gt;Anyone please help on this topic&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 15:28:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132384#M19606</guid>
      <dc:creator>Ramasubramaniya</dc:creator>
      <dc:date>2021-10-21T15:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132385#M19607</link>
      <description>&lt;P&gt;You may want to open support case, because this would need some more in depth troubleshooting, for sure.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 15:30:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132385#M19607</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-21T15:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132433#M19617</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are matching&amp;nbsp;sk132672&lt;/P&gt;&lt;P&gt;BR,&lt;BR /&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 13:43:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132433#M19617</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-10-22T13:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132434#M19618</link>
      <description>&lt;P&gt;Very good point Kostas!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 13:50:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132434#M19618</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-10-22T13:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132924#M19746</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did&amp;nbsp;&lt;SPAN&gt;sk132672 help you to resolve this issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Yair&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Oct 2021 09:46:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132924#M19746</guid>
      <dc:creator>Yair_Shahar</dc:creator>
      <dc:date>2021-10-31T09:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: CCP drop packets in R81</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132970#M19754</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for the kind replies. I tried sk132672 but does not help in my case.&lt;/P&gt;&lt;P&gt;As i already said the switch is connected with Current R81 Cluster and the R77.30 VRRP Cluster.&lt;/P&gt;&lt;P&gt;I lately realized this packets are coming from VRRP cluster since the Cluster mode is Mutlicast in the R77.30 Cluster.&lt;/P&gt;&lt;P&gt;I confirmed this by capturing packet on the R77.30 cluster and found same 0.0.0.0:8116 -&amp;gt; 10.0.0.0:8116 packets are exchanging over there.&lt;/P&gt;&lt;P&gt;So it's good say it's our design issue. Once again thanks all for the recommendations, much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ram T S&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 00:48:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CCP-drop-packets-in-R81/m-p/132970#M19754</guid>
      <dc:creator>Ramasubramaniya</dc:creator>
      <dc:date>2021-11-01T00:48:13Z</dc:date>
    </item>
  </channel>
</rss>

