<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Asymmetric structure network test in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-structure-network-test/m-p/134469#M20152</link>
    <description>&lt;P&gt;It should apply fwkern.conf on reboot.&lt;BR /&gt;If not, I recommend a TAC case.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Nov 2021 07:30:41 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-11-19T07:30:41Z</dc:date>
    <item>
      <title>Asymmetric structure network test</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-structure-network-test/m-p/134207#M20083</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I conducted a network test of asymmetric structure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Check packet drop&amp;nbsp; icmp&amp;nbsp; in asymmetric structure network test.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------&lt;/P&gt;&lt;P&gt;[Expert@test2:0]# fw ctl zdebug + drop&lt;/P&gt;&lt;P&gt;@;103266;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=1 200.0.0.100:0 -&amp;gt; 100.0.0.100:17460 dropped by fw_first_packet_state_checks Reason: ICMP reply does not match a previous request;&lt;BR /&gt;@;103467;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=1 200.0.0.100:0 -&amp;gt; 100.0.0.100:17459 dropped by fw_first_packet_state_checks Reason: ICMP reply does not match a previous request;&lt;BR /&gt;@;103601;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=1 200.0.0.100:0 -&amp;gt; 100.0.0.100:17458 dropped by fw_first_packet_state_checks Reason: ICMP reply does not match a previous request;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. fw ctl get int fw_allow_out_of_state_icmp is checked, value 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[Expert@test2:0]# fw ctl get int fw_allow_out_of_state_icmp&lt;BR /&gt;fw_allow_out_of_state_icmp = 0&lt;BR /&gt;[Expert@test2:0]# fw ctl get int fw_allow_out_of_state_tcp&lt;BR /&gt;fw_allow_out_of_state_tcp = 0&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------&lt;/P&gt;&lt;P&gt;3. fw ctl set -f int fw_allow_out_of_state_icmp 1 / cat&amp;nbsp;$FWDIR/boot/modules/fwkern.conf file&lt;/P&gt;&lt;P&gt;[Expert@test2:0]# cat $FWDIR/boot/modules/fwkern.conf&lt;/P&gt;&lt;P&gt;fw_allow_out_of_state_icmp=1&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After setting it up, the ping test was successful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;when rebooting, the value of the fwkern.conf file remains the same.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but when fw ctl get int fw_allow_out_state_icmp is entered, fw_allow_out_of_state_icmp = 0.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ping test failed when rebooting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateway OS version R81..&lt;/P&gt;&lt;P&gt;I know the setting value of $FWDIR/boot/modules/fwkern.conf should be applied first booted when booting the equipment.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But wouldn't it be applied if I reboot it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please help me..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 05:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-structure-network-test/m-p/134207#M20083</guid>
      <dc:creator>csh</dc:creator>
      <dc:date>2021-11-17T05:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric structure network test</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-structure-network-test/m-p/134469#M20152</link>
      <description>&lt;P&gt;It should apply fwkern.conf on reboot.&lt;BR /&gt;If not, I recommend a TAC case.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 07:30:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Asymmetric-structure-network-test/m-p/134469#M20152</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-19T07:30:41Z</dc:date>
    </item>
  </channel>
</rss>

