<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Telnet connection to cisco via Check Point in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152758#M25485</link>
    <description>&lt;P&gt;Thanks for the clarification.&lt;BR /&gt;Network experts say the route is symmetrical.&lt;/P&gt;&lt;P&gt;Unfortunately, I haven't been able to apply the solution from the sk for R81 with an error:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Get operation failed: failed to get parameter fw_trust_suspicious_establishment_conn&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2022 05:14:56 GMT</pubDate>
    <dc:creator>Miktator</dc:creator>
    <dc:date>2022-07-12T05:14:56Z</dc:date>
    <item>
      <title>Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152121#M25333</link>
      <description>&lt;P&gt;When connecting to cisco via telnet protocol over fw r81.10 we are experiencing connection problems. namely, the connection does not happen at the first attempt within one connection, but from 3 or more, sometimes even from 10 times.&lt;BR /&gt;When connecting directly, everything happens from the first time&lt;/P&gt;&lt;P&gt;When connecting pyton script comes out an error "[WinError 10060] A connection attempt failed because the connected party did not properly respond after a period of time, or established connection"&lt;BR /&gt;When connecting via cmd ".Could not open connection to the host, on port 23: Connect Failed." From 2 to 10 times and then it connects.&lt;/P&gt;&lt;P&gt;I added the host to the IPS exclusion but it did not help.&lt;BR /&gt;Please tell me where to look, maybe someone has already done this?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 11:42:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152121#M25333</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-06-30T11:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152154#M25334</link>
      <description>&lt;P&gt;Sorry I have to ask why Telnet versus SSH and wh&lt;SPAN&gt;at do you see in logs / packet capture?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 05:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152154#M25334</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-01T05:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152161#M25335</link>
      <description>&lt;P&gt;Thank you for your attention to my problem.&lt;BR /&gt;I understand your concern about using telnet, but it is the customer's choice.&lt;BR /&gt;I only see accepts in the logs, so I didn't find any clues in my investigation.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 06:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152161#M25335</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-07-01T06:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152192#M25336</link>
      <description>&lt;P&gt;What precise device is the telnet coming from?&lt;BR /&gt;What does fw ctl zdebug drop say?&lt;BR /&gt;What does a tcpdump show?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 15:06:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152192#M25336</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-01T15:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152356#M25394</link>
      <description>&lt;P&gt;&lt;EM&gt;What precise device is the telnet coming from?&lt;/EM&gt;&lt;BR /&gt;WindowsPC&lt;BR /&gt;&lt;SPAN&gt;&lt;EM&gt;What does fw ctl zdebug drop say?&lt;/EM&gt;&lt;BR /&gt;@;1317998394;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 DST_IP:23 -&amp;gt; SRC_IP:50684 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;&lt;BR /&gt;&lt;EM&gt;fw ctl zdebug+ drop&lt;/EM&gt;&lt;BR /&gt;@;1317506904;[cpu_0];[SIM-209695455];do_inbound: Possible TCP state violation for &amp;lt;DST_IP,23,SRC_IP,50665,6&amp;gt; -&amp;gt; dropping packet ;&lt;BR /&gt;@;1317506904;[cpu_0];[SIM-209695455];sim_pkt_send_drop_notification: (0,0) received drop, reason: Invalid TCP option, conn: &amp;lt;DST_IP,23,SRC_IP,50665,6&amp;gt;;&lt;BR /&gt;@;1317506904;[cpu_0];[SIM-209695455];sim_pkt_send_drop_notification: no track is needed for this drop - not sending a notificaion, conn: &amp;lt;DST_IP,23,SRC_IP,50665,6&amp;gt;;&lt;BR /&gt;@;1317506904;[cpu_0];[SIM-209695455];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:&amp;lt;DST_IP,23,SRC_IP,50665,6&amp;gt;;&lt;BR /&gt;@;1317509016;[cpu_0];[SIM-209695455];update_tcp_state: invalid state detected (current state: 0x10000, th_flags=0x12, cdir=1) -&amp;gt; dropping packet, conn: [&amp;lt;SRC_IP,50665,DST_IP,23,6&amp;gt;][PPK0];&lt;BR /&gt;&lt;BR /&gt;Where src_ip - windows PC and dst_ip - cisco2950.&lt;BR /&gt;&lt;BR /&gt;What is noteworthy is that if the WinPC is connected through the router, without going through the Checkpoint, then the connection goes first time.&lt;BR /&gt;And if our WinPC connects to a cisco2960, which is located in the same network segment as the 2950, it also connects from the first time.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 15:30:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152356#M25394</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-07-05T15:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152474#M25415</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Reason: First packet isn't SYN;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You could possibly have an asymmetric routing issue. What does your topology look like?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 03:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152474#M25415</guid>
      <dc:creator>Paul_Kazzi</dc:creator>
      <dc:date>2022-07-07T03:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152701#M25469</link>
      <description>&lt;P&gt;ARM-&amp;gt;some router with ospf-&amp;gt;eth1.100checkpoint-&amp;gt;eth2.200checkpoint-&amp;gt;some router with ospf-&amp;gt;cisco2950&lt;BR /&gt;&lt;SPAN&gt;Reason: First packet isn't SYN i see on eth2.200 interface in logs from cisco to ARM.&lt;BR /&gt;&lt;/SPAN&gt;From Arm To cisco i see only accept logs.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The problem would be easier to solve if the connection does not work at all, but the connection works, but not the first time. I have to make from 3 to 10 connections.&lt;BR /&gt;We use telnet because this cisco2950 has no other protocol.&lt;/P&gt;&lt;P&gt;I am curious why the 2960 works in the same network segment with no problems and connects the first time.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 14:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152701#M25469</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-07-11T14:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152702#M25470</link>
      <description>&lt;P&gt;Do both the 2950 and 2960 have the same default gateway set?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 14:36:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152702#M25470</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-11T14:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152703#M25471</link>
      <description>&lt;P&gt;Yes I looked at the output of the trace command from both cisco to ARM.And from the gateway to both cisco.And all the hops match.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 14:38:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152703#M25471</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-07-11T14:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152734#M25478</link>
      <description>&lt;P&gt;First Packet isn't SYN generally means it saw a packet for the connection AFTER the initial SYN packet.&lt;BR /&gt;That points to an asymmetric routing issue, as pointed out by others.&lt;BR /&gt;It could also be something funny with sequence numbers, as this SK suggests:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119302&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119302&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 20:10:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152734#M25478</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-11T20:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152758#M25485</link>
      <description>&lt;P&gt;Thanks for the clarification.&lt;BR /&gt;Network experts say the route is symmetrical.&lt;/P&gt;&lt;P&gt;Unfortunately, I haven't been able to apply the solution from the sk for R81 with an error:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Get operation failed: failed to get parameter fw_trust_suspicious_establishment_conn&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 05:14:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152758#M25485</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-07-12T05:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152778#M25499</link>
      <description>&lt;P&gt;I would suggest to contact TAC to get this resolved!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 11:11:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152778#M25499</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-12T11:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152806#M25514</link>
      <description>&lt;P&gt;To get to the bottom of this, you're probably going to need a TAC case.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 14:05:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/152806#M25514</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-12T14:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153266#M25707</link>
      <description>&lt;P&gt;I found the solution in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468" target="_blank"&gt;How to disable SecureXL for specific IP addresses (checkpoint.com)&lt;/A&gt;.I added src and dst telnet connections to the exception.&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 15:02:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153266#M25707</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-07-18T15:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153267#M25708</link>
      <description>&lt;P&gt;This is a workaround, you should contact TAC to understand why it changes the outcome and implement a proper fix.&lt;/P&gt;
&lt;P&gt;Perhaps test again after applying the latest GA Jumbo hotfix if not already used.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 15:07:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153267#M25708</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-18T15:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153273#M25709</link>
      <description>&lt;P&gt;Yes we have the last JHF and I shared my workaround with TAC,if there is a direct solution I will be sure to add it.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 15:50:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153273#M25709</guid>
      <dc:creator>Miktator</dc:creator>
      <dc:date>2022-07-18T15:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet connection to cisco via Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153282#M25711</link>
      <description>&lt;P&gt;The fact this "solves" the issue suggests what we stated earlier: asymmetric routing is likely to blame for this.&lt;BR /&gt;One thing SecureXL does is cache the ingress/egress interface to be used.&lt;BR /&gt;Disabling SecureXL for that specific connection would prevent any related issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 16:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Telnet-connection-to-cisco-via-Check-Point/m-p/153282#M25711</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-18T16:19:06Z</dc:date>
    </item>
  </channel>
</rss>

