<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIP VoIP streams are dropped after policy install in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140530#M21580</link>
    <description>&lt;P&gt;I know this SK, relevant is probably scenario 3, however it is still the same w/a. But changing connection persistence on SIP service only could do the trick. A am just a bit&amp;nbsp; nervous about changing parameters of the default SIP service, from my experience any nonstandard use of SIP service can kill the VoIP traffic. I will double check with TAC, just for sure.&lt;/P&gt;&lt;P&gt;Thanks for your hint.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Feb 2022 15:09:46 GMT</pubDate>
    <dc:creator>Lukas_Sosnovec</dc:creator>
    <dc:date>2022-02-04T15:09:46Z</dc:date>
    <item>
      <title>SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140513#M21573</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After policy install SIP communication is dropped on 'old packer rulebase drop', although the newly installed policy allows it. Deleting the connections manually from the fw table resolves the issue, so does rebooting the VoIP gateways.&lt;/P&gt;&lt;P&gt;zdebug shows dropped by fw_handle_old_conn_recovery Reason: old packet rulebase drop; on port 5060&lt;/P&gt;&lt;P&gt;It seems like the problem described in &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sk140112, but newly installed policy does not change SIP rules in any way and still allows it. If fact it happened even after just installing the same policy without any change.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Changing connection persistence to Keep all connection seems to help.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This happens only sometimes, I didn't figure the conditions yet. Anybody with similar issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R80.40 JHFA125 both gw and management. GW is 3600 appliance. VoIP is configured according to ARTG, only sip services relevant for R80.40 used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 13:51:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140513#M21573</guid>
      <dc:creator>Lukas_Sosnovec</dc:creator>
      <dc:date>2022-02-04T13:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140517#M21574</link>
      <description>&lt;P&gt;Have not seen that issue in a long time, but I recall in the old day, what people would do sometimes is open service properties and change protocol to "none". Give that a go and see if it works permanently...if it does, then it means that inspection is not working right for that service. In that case, you may need to get in touch with TAC to find out why.&lt;/P&gt;
&lt;P&gt;However, if that fails to fix the problem as well, maybe do a quick tcpdump and fw monitor just to verify the flow of traffic. Though, based on everything you wrote so far, sounds like its got mostly to do with rematching of the connection.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 13:56:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140517#M21574</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-04T13:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140518#M21575</link>
      <description>&lt;P&gt;Thanks for your idea, but as this is SIP service, I cannot change the protocol, it would break the VoIP streams&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 14:02:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140518#M21575</guid>
      <dc:creator>Lukas_Sosnovec</dc:creator>
      <dc:date>2022-02-04T14:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140521#M21576</link>
      <description>&lt;P&gt;Ok, I understand 100%. You may want to check below if you havent already.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103598" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103598&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 14:11:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140521#M21576</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-04T14:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140530#M21580</link>
      <description>&lt;P&gt;I know this SK, relevant is probably scenario 3, however it is still the same w/a. But changing connection persistence on SIP service only could do the trick. A am just a bit&amp;nbsp; nervous about changing parameters of the default SIP service, from my experience any nonstandard use of SIP service can kill the VoIP traffic. I will double check with TAC, just for sure.&lt;/P&gt;&lt;P&gt;Thanks for your hint.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 15:09:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140530#M21580</guid>
      <dc:creator>Lukas_Sosnovec</dc:creator>
      <dc:date>2022-02-04T15:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140532#M21582</link>
      <description>&lt;P&gt;I would do the same...better to have official vendor support answer, 100%.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 15:16:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140532#M21582</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-04T15:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140552#M21592</link>
      <description>&lt;P&gt;&lt;BR /&gt;This can also have a simple cause. The following parameter is not set for the default SIP service:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Keep_con1.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15249i356C7725F3C146AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Keep_con1.jpg" alt="Keep_con1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would activate this setting and try again afterwards.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 18:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140552#M21592</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-04T18:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140574#M21597</link>
      <description>&lt;P&gt;Yes, that is exactly what sk103598 suggests. But as I said I am really not happy editing default SIP service, it usually does not lead to anything good.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will update after I receive TAC opinion.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 22:10:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140574#M21597</guid>
      <dc:creator>Lukas_Sosnovec</dc:creator>
      <dc:date>2022-02-04T22:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140575#M21598</link>
      <description>&lt;P&gt;Yes, definitely let us know, it would be interesting to see what they suggest in this case.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 22:12:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/140575#M21598</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-04T22:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: SIP VoIP streams are dropped after policy install</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/142468#M22040</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;FYI, TAC engineer agreed that changing anything on default SIP service object is a bad idea and suggested the w/a I already have (keeping all connections open after policy install) as permanent solution. I don't like this because of security point of view but for now it seems there is no other option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 08:23:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-VoIP-streams-are-dropped-after-policy-install/m-p/142468#M22040</guid>
      <dc:creator>Lukas_Sosnovec</dc:creator>
      <dc:date>2022-02-25T08:23:09Z</dc:date>
    </item>
  </channel>
</rss>

