<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: First packet isn't syn in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153448#M25751</link>
    <description>&lt;P&gt;hello, did you fix it?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2022 08:30:24 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2022-07-20T08:30:24Z</dc:date>
    <item>
      <title>First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/133153#M19790</link>
      <description>&lt;P&gt;Hey everyone.&amp;nbsp; I have a new CPGW R81.10 and I have one workstation that's dropping traffic 3 to 4 times a second with the following issue:&lt;/P&gt;
&lt;P&gt;TCP packet out of state: First packet isn't SYN&lt;/P&gt;
&lt;P&gt;TCP Flags: RST-ACK and FIN-PUSH-ACK&lt;/P&gt;
&lt;P&gt;Can this be ignored?&amp;nbsp; I can't say I'm seeing a perf problem.&amp;nbsp; Or, should/how can it be fixed?&amp;nbsp; Thanks all!&lt;/P&gt;
&lt;DIV id="tinyMceEditortlloyd22_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 15:39:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/133153#M19790</guid>
      <dc:creator>tlloyd22</dc:creator>
      <dc:date>2021-11-03T15:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/133325#M19825</link>
      <description>&lt;P&gt;Generally you can ignore FIN and RST packets that are dropped out of state unless they are conclusively linked to a specific problem.&amp;nbsp; This is typically caused by the connection not being closed gracefully by one side or the other, see my post here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7027/highlight/true#M798" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7027/highlight/true#M798&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 17:13:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/133325#M19825</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-11-05T17:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142645#M22084</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you find anyting related to this issue? I have also seen those packets dropped after upgrading to R81.10 TAKE30.&lt;BR /&gt;I haven´t seen any drops related to&amp;nbsp;&lt;SPAN&gt;TCP Flags: RST-ACK and FIN-PUSH-ACK before upgrade R80.40.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My problem is that I have performance issues related to flows where I see errors in logs.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have disabled HTTPS Inspection which seems to solve the issue.&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 20:18:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142645#M22084</guid>
      <dc:creator>maad-pul</dc:creator>
      <dc:date>2022-02-28T20:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142646#M22085</link>
      <description>&lt;P&gt;After seeing Tim Hall's post and reading through, I chose to ignore the errors since I didn't see a performance issue.&amp;nbsp; Sorry I'm not more helpful...good luck!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 21:24:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142646#M22085</guid>
      <dc:creator>tlloyd22</dc:creator>
      <dc:date>2022-02-28T21:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142647#M22086</link>
      <description>&lt;P&gt;Are you seeing any performance impact, dropped traffic? If so, then I would be concerned...if not, then I would not worry much.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 21:27:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142647#M22086</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-28T21:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142648#M22087</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes! This weekend we upgraded to lastest R81.10 GA,&amp;nbsp; I´m having users reported "slow web browsning" today, I found in logs a lot of dropped packet related to tcp/443, which haven¨t been there before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;TCP packet out of state: First packet isn't SYN&lt;BR /&gt;TCP Flags: RST-ACK and FIN-PUSH-ACK&lt;/P&gt;&lt;P&gt;I quick fix, just to now whats goding on was to disable HTTPS Inspection for that VS. Logs dissapeard and users reported good web browsing performance after that. The Logs are from the FW-blade and not HTTPS Inspection.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 21:51:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142648#M22087</guid>
      <dc:creator>maad-pul</dc:creator>
      <dc:date>2022-02-28T21:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142649#M22088</link>
      <description>&lt;P&gt;You may need to debug wstlsd process for https inspection, when its enabled.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 21:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142649#M22088</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-28T21:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142650#M22089</link>
      <description>&lt;P&gt;I am seeing a LOT of those too in my ubiquiti unifi controller where connection status/heartbeats then gets time out and throwing me an Alert of a device disconnecting even though it’s working fine. It’s so annoying.. never had that issue before checkpoint unfortunately &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 22:47:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142650#M22089</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2022-02-28T22:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142655#M22090</link>
      <description>&lt;P&gt;I would open TAC case for it to have them verify, specially given the fact it causes traffic issues.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 06:11:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142655#M22090</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-01T06:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142664#M22093</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I will do that, I just need to verify &lt;SPAN&gt;Hyperthreading&amp;nbsp;&lt;/SPAN&gt;(SMT/HT) enabling i BIOS for the HPE-server.&amp;nbsp; I don´t know if thats setting was enabled in last update to R80.40, but support seems to be removed.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;See&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Attention-HyperThreading-SMT-support-for-Open-Servers-got/td-p/104962" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Attention-HyperThreading-SMT-support-for-Open-Servers-got/td-p/104962&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 08:57:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/142664#M22093</guid>
      <dc:creator>maad-pul</dc:creator>
      <dc:date>2022-03-01T08:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153448#M25751</link>
      <description>&lt;P&gt;hello, did you fix it?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 08:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153448#M25751</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-07-20T08:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153889#M25914</link>
      <description>&lt;P&gt;&lt;SPAN&gt;hello, I'm having the same problem as you and I'm losing a lot of packages that are destroying the performance. Could you let me know if there was a solution to your problem?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 18:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153889#M25914</guid>
      <dc:creator>Pedro_Sentinela</dc:creator>
      <dc:date>2022-07-26T18:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153891#M25916</link>
      <description>&lt;P&gt;mine isnt fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my experience it doesnt look like Check point have a FIX for it actually &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 19:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153891#M25916</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2022-07-26T19:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153892#M25917</link>
      <description>&lt;P&gt;Well, first packet isnt syn error is not something CP would have a fix for, per se, its usually routing issue, from my experience.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 20:05:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/153892#M25917</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-26T20:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/154225#M26094</link>
      <description>&lt;P&gt;Routing issue in what sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 20:35:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/154225#M26094</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2022-07-30T20:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/154232#M26097</link>
      <description>&lt;P&gt;Indeed, need to ensure the symptoms are identical i.e. i&lt;SPAN&gt;n no particular order:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- Asymmetric routing (both direction/sides of the flow need to traverse the firewall)&lt;/P&gt;
&lt;P&gt;- Aggressive aging (due to resource issue or other transient event)&lt;/P&gt;
&lt;P&gt;- App issue / TCP half-closed (&lt;SPAN&gt;sk11088 / sk137672)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- HTTPS inspection (sk118415)&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 06:26:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/154232#M26097</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-01T06:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/154982#M26353</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, patched an the problem was solved. According to TAC&amp;nbsp;PRJ-30820 was the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 05:57:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/154982#M26353</guid>
      <dc:creator>maad-pul</dc:creator>
      <dc:date>2022-08-15T05:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/155001#M26361</link>
      <description>&lt;P&gt;&lt;SPAN&gt;PRJ-30820 was my issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 14:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/155001#M26361</guid>
      <dc:creator>maad-pul</dc:creator>
      <dc:date>2022-08-15T14:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/155904#M26615</link>
      <description>&lt;P&gt;i'm happy for you.&lt;/P&gt;&lt;P&gt;I don't think that's my case,&amp;nbsp;&lt;SPAN&gt;PRJ-30820 is on T38 and i faced the problem on T55&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 13:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/155904#M26615</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-08-29T13:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't syn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/156428#M26801</link>
      <description>&lt;P&gt;I'm facing similar kind of issue after upgrade and pushing policy on standby gateway .we are not able to access the web UI/ssh of gateway.&lt;/P&gt;&lt;P&gt;While further checking in log&amp;nbsp; found lot of&amp;nbsp; TCP out of order packet drop for reverse traffic,&amp;nbsp; for testing purpose added gateway in expectation, than it starting working .&amp;nbsp; Observers gateway for 2 min and found gateway hang and not responding , so again started new session of ssh but response is too slow again checked resource and found utilisation is fair enough .&lt;/P&gt;&lt;P&gt;So I drop the plan of upgrade and rollback the change .&lt;/P&gt;&lt;P&gt;Upgrade from R80.30 to R81 latest jumbo hotfix.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 02:57:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-packet-isn-t-syn/m-p/156428#M26801</guid>
      <dc:creator>Ravi_cp</dc:creator>
      <dc:date>2022-09-05T02:57:06Z</dc:date>
    </item>
  </channel>
</rss>

