<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155107#M26386</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After upgrading from R80.20 to R81.10 we see many many TCP drops in the logs from many servers.&lt;/P&gt;&lt;P&gt;Drops are First Packet Isn't SYN with TCP flags are mostly FIN-ACK, ACK.&lt;/P&gt;&lt;P&gt;No performance or other issue with these servers.&lt;/P&gt;&lt;P&gt;We've never had these drops on R80.20 from these servers, and we haven't changed any topology when upgraded.&lt;/P&gt;&lt;P&gt;I suspect it's just cosmetic or a new logging feature issue, but not sure...&lt;/P&gt;&lt;P&gt;I've noticed a checkbox under Global Properties -&amp;gt; Stateful Inspection -&amp;gt; "Log on drop". I don't know if it was checked before the upgrade, maybe it explains the issue?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TCPDrops.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17442i4C483110C9709240/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TCPDrops.JPG" alt="TCPDrops.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;One thing to mention, not sure it's related - upgrade is not finished yet, we have one member upgraded and the other one is still running R80.20 but is not functioning (cpstop), so the cluster is actually broken at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2022 06:13:48 GMT</pubDate>
    <dc:creator>Jonathan</dc:creator>
    <dc:date>2022-08-17T06:13:48Z</dc:date>
    <item>
      <title>Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155107#M26386</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After upgrading from R80.20 to R81.10 we see many many TCP drops in the logs from many servers.&lt;/P&gt;&lt;P&gt;Drops are First Packet Isn't SYN with TCP flags are mostly FIN-ACK, ACK.&lt;/P&gt;&lt;P&gt;No performance or other issue with these servers.&lt;/P&gt;&lt;P&gt;We've never had these drops on R80.20 from these servers, and we haven't changed any topology when upgraded.&lt;/P&gt;&lt;P&gt;I suspect it's just cosmetic or a new logging feature issue, but not sure...&lt;/P&gt;&lt;P&gt;I've noticed a checkbox under Global Properties -&amp;gt; Stateful Inspection -&amp;gt; "Log on drop". I don't know if it was checked before the upgrade, maybe it explains the issue?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TCPDrops.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17442i4C483110C9709240/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TCPDrops.JPG" alt="TCPDrops.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;One thing to mention, not sure it's related - upgrade is not finished yet, we have one member upgraded and the other one is still running R80.20 but is not functioning (cpstop), so the cluster is actually broken at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 06:13:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155107#M26386</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-08-17T06:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155114#M26388</link>
      <description>&lt;P&gt;I would advise completing the upgrade and seeing if the issue persists with Jumbo T45 or later applied.&lt;/P&gt;
&lt;P&gt;There have been &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/First-packet-isn-t-syn/m-p/133153" target="_self"&gt;situations&lt;/A&gt; where similar symptoms were reported and linked to:&lt;/P&gt;
&lt;TABLE id="filter1Table" class="TableStyle-TP_Table_Jumbo_Fixes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-Grey_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_ID-Grey_Background"&gt;
&lt;P&gt;PRJ-30820,&lt;BR /&gt;PRHF-19417&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_Product-Grey_Background"&gt;
&lt;P&gt;SecureXL&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_Description-Grey_Background"&gt;
&lt;P&gt;In a rare scenario, after an upgrade, HTTPS traffic may be dropped.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155114#M26388</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-17T07:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155121#M26389</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;I'm on the latest JHF (take 66). We don't have HTTPS inspection of this traffic, and also it happens on other services and ports other than 443.&lt;/P&gt;&lt;P&gt;I will wait however until we finish with the upgrade, probably next Sunday, and will update if it's resolved.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 11:48:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155121#M26389</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-08-17T11:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155123#M26390</link>
      <description>&lt;P&gt;Noted. There are other possible causes for these messages as the other discussion suggests. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 11:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155123#M26390</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-17T11:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155339#M26412</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;So upgrade is all finished, but issue is the same.&lt;/P&gt;&lt;P&gt;Only noticable change is that 99% of the logs now have TCP Flag: RST-ACK, which I know is generally normal to see. I just don't understand how come we never saw it prior to the upgrade and how to stop seeing it in logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 09:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155339#M26412</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-08-21T09:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155349#M26417</link>
      <description>&lt;P&gt;seeing the same thing "all of the sudden" No solution so far.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 19:56:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155349#M26417</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2022-08-21T19:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155393#M26476</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check this sk:&amp;nbsp;&lt;SPAN&gt;sk137672 -&amp;nbsp;How to change the 'TCP Half Closed timer' value.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;with this solution we can improve the TCP close session processus.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 09:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/155393#M26476</guid>
      <dc:creator>laurent_ragon</dc:creator>
      <dc:date>2022-08-22T09:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/163891#M29263</link>
      <description>&lt;P&gt;We have upgraded R80.40 ot R81.10 10 days ago, and we are monitoring large number of&lt;SPAN&gt;&amp;nbsp;First Packet Isn't SYN drops, mainly with packets with tcp flag RST-ACK.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For a monitored connections between selected hosts, the increase of dropped packets is with 15% compared with the day before upgrade. Also some application issues are reported after upgrade and seems related to the drops.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am not sure how solution in&amp;nbsp;sk137672 is supposed to control.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 15:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/163891#M29263</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2022-12-01T15:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/164399#M29416</link>
      <description>&lt;P&gt;It appears that in my case, the connection is being expired after 15 seconds when the firewall sees the DEST-FIN.&amp;nbsp; The client (Chrome/Edge)&amp;nbsp; continues to send Keep-Alive packets for about 5 minutes, which are all dropped out of state.&amp;nbsp; The client then sends several FIN-ACK packets, which are also dropped out of state.&amp;nbsp; This is what the connection looks like before DST-FIN:&lt;/P&gt;&lt;P&gt;&amp;lt;00000000, 0a7a1550, 0000d333, ac1c2015, 00000050, 00000006;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;0001c001&lt;/STRONG&gt;, 40044080, 00000038, 000001cf, 00000000, 6387085d, 00000008, 13e3b1d3, d7e5c551, 00000003, ffffffff, ffffffff, ffffffff, 0000e800, 00000000, 80000000, 00000000, 00000000, ac442808, 00007f8e, 00000000, 02101801, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;3603/3615&lt;/STRONG&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;and after the DEST-FIN&lt;BR /&gt;&lt;BR /&gt;&amp;lt;00000000, 0a7a1550, 0000d330, ac1c2015, 00000050, 00000006;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;0001e001&lt;/STRONG&gt;, 40044080, 00000038, 000001cf, 00000000, 6387085d, 00000000, 13e3b1d3, d7e5c551, 00000003, ffffffff, ffffffff, ffffffff, 0000e800, 00000000, 80000000, 00000000, 00000000, b8fd9088, 00007f8e, 00000000, 06ce0001, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000, 00000000;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;14/15&lt;/STRONG&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;After the server sends the FIN-ACK to the client, the connection is updated with this 15 second timeout.&amp;nbsp; The client (Chrome/Edge) sends the first Keep-Alive packets after 45 seconds and several more Keep-Alive packets at 45 second intervals, These Keep-Alive packets are all dropped out of state, as well as subsequent FIN-ACK packets.&amp;nbsp; I'm not sure where the 15 second timeout is coming from; the TCP end session timeout is 5 seconds.&amp;nbsp; Disabling SecureXL resolves the issue.&amp;nbsp; I have a case open, but not getting anywhere quickly unfortunately.&amp;nbsp; I'm not sure if this is impacting user experience, other than causing Chrome and Edge to use more sockets than necessary and generating lots of unnecessary logs.&amp;nbsp; It seems to be that there is an issue with SecureXL expiring half-closed connections too early and would like to get to the bottom of it&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 04:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/164399#M29416</guid>
      <dc:creator>Jonne_Hannon</dc:creator>
      <dc:date>2022-12-07T04:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167581#M30293</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25651"&gt;@Jonne_Hannon&lt;/a&gt;&amp;nbsp;, do you have any solution about the problem ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 12:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167581#M30293</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2023-01-12T12:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167641#M30294</link>
      <description>&lt;P&gt;Please review&amp;nbsp;&lt;SPAN&gt;sk180364 and see if it helps&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 15:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167641#M30294</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-12T15:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167657#M30297</link>
      <description>&lt;P&gt;Might also be this from R81.10 Take 82.&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;PRJ-42445,&lt;BR /&gt;PRHF-26215&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;SecureXL&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;The Security Gateway may prematurely expire half-closed TCP connections and drop VoIP and HTTPS packets with "&lt;EM&gt;First packet isn't SYN&lt;/EM&gt;".&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 12 Jan 2023 16:17:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167657#M30297</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-01-12T16:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Many TCP  First-Packet-isn't-SYN drops after upgrade to R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167701#M30301</link>
      <description>&lt;P&gt;Hi Dilian,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sk137672 -&amp;nbsp;How to change the 'TCP Half Closed timer' value is most helpful for me.&amp;nbsp; I am still investigating the hotfix from sk180364, because that hotfix seems to remove the half-closed DST-FIN connection from the SecureXL connections table, but the firewall half-closed DST-FIN connection still has the 15 second timeout resulting is many "First packet isn't SYN" drops.&amp;nbsp; I also note that sk137672 was recently updated with the following added information:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Some of the Half closed connections ( DST-FIN ) by default will have 15 seconds timeout starting from the versions mentioned above.&lt;BR /&gt;To increase the default timeout to 3600 seconds for all Half closed connections please proceed with the procedure described above."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This seems to imply that the 15 second timeout is a change in behaviour.&amp;nbsp; I'm not sure what the rationale is behind expiring the half-closed DST-FIN connections so quickly.&amp;nbsp; Other than generating lots of "First packet isn't SYN" logs, I'm not sure if the user experience is impacted by expiring half-closed DST-FIN connections after 15 seconds.&amp;nbsp; Maybe a Check Point employee can explain the rationale behind this change?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jonne.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 00:29:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Many-TCP-First-Packet-isn-t-SYN-drops-after-upgrade-to-R81-10/m-p/167701#M30301</guid>
      <dc:creator>Jonne_Hannon</dc:creator>
      <dc:date>2023-01-13T00:29:36Z</dc:date>
    </item>
  </channel>
</rss>

