<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No TLS Server Hello Response issue - Networking Troubleshoot in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150523#M24465</link>
    <description>&lt;P&gt;Hello, this description is from pcaps that I took from traffic that does work and other that does not work.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jun 2022 23:24:04 GMT</pubDate>
    <dc:creator>CharlesLZ</dc:creator>
    <dc:date>2022-06-09T23:24:04Z</dc:date>
    <item>
      <title>No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150519#M24463</link>
      <description>&lt;P class=""&gt;Hello, I am currently with a Tshoot on two scenarios from LAN.&lt;/P&gt;&lt;P class=""&gt;IP A:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Original IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;IP B:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;NAT IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;IP C:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WebServer&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Scenario A that works:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Flow:&lt;/P&gt;&lt;P class=""&gt;IP A -&amp;gt; IP C leng 517 (Client Hello TCP with TLS packet)&lt;/P&gt;&lt;P class=""&gt;IP B -&amp;gt; IP C leng 517 (Client Hello TCP with TLS packet)&lt;/P&gt;&lt;P class=""&gt;IP C -&amp;gt; IP A ackno 518 (Server Hello TCP with TLS packet)&lt;/P&gt;&lt;P class=""&gt;IP C-&amp;gt; IP B ackno 518 (Server Hello TCP with TLS packet)&lt;/P&gt;&lt;P class=""&gt;At this point this is expected, and the user can open the browser and connect to the webserver from LAN over HTTPS 443.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Scenario B does Not Work:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Flow:&lt;/P&gt;&lt;P class=""&gt;IP A -&amp;gt; IP C leng 517 (Client Hello TCP with TLS packet)&lt;/P&gt;&lt;P class=""&gt;IP B -&amp;gt; IP C leng 517 (Client Hello TCP with TLS packet)&lt;/P&gt;&lt;P class=""&gt;IP C -&amp;gt; IP A ackno 518 (ONLY TCP ack packet ) no Server Hello response&lt;/P&gt;&lt;P class=""&gt;IP C-&amp;gt; IP B ackno 518 (ONLY TCP ack packet ) no Server Hello response&lt;/P&gt;&lt;P class=""&gt;The user&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;can't&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;connect to this webserver from LAN, browser and over HTTPS 443.&lt;/P&gt;&lt;P class=""&gt;On scenario B: I receive the acknowledge 518 without TLS Server Hello Payload.&lt;/P&gt;&lt;P class=""&gt;Based on your experience could you infer this packet could be lost somewhere on the LAN network? or if Check Point Firewall at some point could block the Server Hello payload response?.&lt;/P&gt;&lt;P class=""&gt;Could be something about Threat Prevention suite ? SecureXL?&lt;/P&gt;&lt;P class=""&gt;I also created TCP State Exceptions but did not work.&lt;/P&gt;&lt;P class=""&gt;I appreciate you response&lt;/P&gt;&lt;P class=""&gt;Have a gr8 day!!!!!!!!!!!!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 19:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150519#M24463</guid>
      <dc:creator>CharlesLZ</dc:creator>
      <dc:date>2022-06-09T19:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150522#M24464</link>
      <description>&lt;P&gt;You would need to do packet captures when it works and when it does not work, so comparing those would probably show you the difference.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 23:19:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150522#M24464</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-09T23:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150523#M24465</link>
      <description>&lt;P&gt;Hello, this description is from pcaps that I took from traffic that does work and other that does not work.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 23:24:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150523#M24465</guid>
      <dc:creator>CharlesLZ</dc:creator>
      <dc:date>2022-06-09T23:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150524#M24466</link>
      <description>&lt;P&gt;Say if you took fw monitor, what do you see? Is it taking the same path?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 23:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150524#M24466</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-09T23:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150948#M24564</link>
      <description>&lt;P&gt;To understand this better, it is important to know, where you did the traffic capture. On the client, on the server, at the firewall itself, at the client side of the firewall, at the server side of the firewall?&lt;/P&gt;
&lt;P&gt;And, as the_rock already said: A fw monitor would be interesting. Please take care of SecureXL or use multiple -F arguments.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 14:06:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/150948#M24564</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-06-15T14:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/216727#M41286</link>
      <description>&lt;P&gt;I also have the same issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both boxes have the same config for httpd, and httpd_ssl. Even when I use the same browser, one gets a Server key and Server Hello back, the other one doesn't.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see a notification that the responses cannot be displayed. If anyone has figured out a fix, can you share? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 13:34:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/216727#M41286</guid>
      <dc:creator>LThomas</dc:creator>
      <dc:date>2024-06-06T13:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221454#M42414</link>
      <description>&lt;P&gt;Facing similar issue. Website is working fine on ASA firewall. When ASA is replaced with Checkpoint it is not working. It has been observed that server hello is not received when Checkpoint is in place. We are using only firewall blade and no HTTPS inspection. Also tried disabling stateful inspection in global properties but no luck. Unable to find the cause of the issue as server team is not ready to troubleshoot the issue from their end as all other locations are able to connect to the same server. Also raised TAC but they are asking to get server team on call.&lt;/P&gt;&lt;P&gt;Any clue why server hello is not received when Checkpoint is in place.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 09:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221454#M42414</guid>
      <dc:creator>Rohit_Raut</dc:creator>
      <dc:date>2024-07-20T09:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221455#M42415</link>
      <description>&lt;P&gt;I can see why TAC is asking you that, I would be doing exactly the same thing. It would be useful to see working and non-working captures for comparison. Btw, when this fails, do you have any logs/debug you can share?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 11:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221455#M42415</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-20T11:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221978#M42548</link>
      <description>&lt;P&gt;Kindly find attached pcap file. src: 192.168.226.55 dst:10.45.74.18.&amp;nbsp; &amp;nbsp;&amp;nbsp;tcp.stream eq 9.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 06:13:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221978#M42548</guid>
      <dc:creator>Rohit_Raut</dc:creator>
      <dc:date>2024-07-26T06:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: No TLS Server Hello Response issue - Networking Troubleshoot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221990#M42550</link>
      <description>&lt;P&gt;Dont see any files...&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 11:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-TLS-Server-Hello-Response-issue-Networking-Troubleshoot/m-p/221990#M42550</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-26T11:30:04Z</dc:date>
    </item>
  </channel>
</rss>

