<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP not leaving the firewall in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155260#M26404</link>
    <description>&lt;P&gt;It might be routing problem, but for what Logesh8 wrote, the devices are directly connected to the interfaces. Should not have routing issue there.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/76116"&gt;@Logesh8&lt;/a&gt;&amp;nbsp;Can you elaborate on the topology? If there is routing involved, and the device is not directly connected, then Bob is probably right and you are missing the return route for that traffic.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Aug 2022 08:02:54 GMT</pubDate>
    <dc:creator>AndréTinoco</dc:creator>
    <dc:date>2022-08-19T08:02:54Z</dc:date>
    <item>
      <title>ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155081#M26381</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;When I did a troubleshooting, I saw the weird response.&amp;nbsp; Assume,&amp;nbsp; Network device D1 is connected to CP firewall Interface eth1 and Network device D2 is connected to eth2 Interface.&amp;nbsp; When Ping initiated from D1 to D2, I see packet entering eth1 and leaving eth2 and&amp;nbsp; when got the response back, I see the response on eth2 but its not reached eth1. It observed via both FW monitor and TCPDUMP.&amp;nbsp; Unfortunately, I am not seeing any drop by issuing command debug drop command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest if you came across any.&lt;/P&gt;&lt;P&gt;Thank you in advance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 16:18:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155081#M26381</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-16T16:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155087#M26383</link>
      <description>&lt;P&gt;What does the fw monitor show? i with no I? i-I with no o? i-I-o with no O? Something else?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 18:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155087#M26383</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-08-16T18:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155113#M26387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I see the ICMP reply back on eth2 with "i" and "I" but I did not see "o" and "O".&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:35:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155113#M26387</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-17T07:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155147#M26392</link>
      <description>&lt;P&gt;Hey!&lt;/P&gt;&lt;P&gt;There can be an issue with IP Forwarding on the interface. Can you paste the output of this command:&lt;/P&gt;&lt;P&gt;sysctl -a | grep forward | grep -v "mc_forwarding" | grep "= 0"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;André Tinoco&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:02:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155147#M26392</guid>
      <dc:creator>AndréTinoco</dc:creator>
      <dc:date>2022-08-17T15:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155149#M26393</link>
      <description>&lt;P&gt;HI Andre,&lt;/P&gt;&lt;P&gt;Thank you and sure.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:08:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155149#M26393</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-17T15:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155236#M26399</link>
      <description>&lt;P&gt;That means a routing problem. On the firewall, run 'ip route get &amp;lt;address&amp;gt;' for the destination of the reply (the client which sent the initial packet). Does it tell you traffic would go out the interface you expect?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 17:48:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155236#M26399</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-08-18T17:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155238#M26400</link>
      <description>&lt;P&gt;Agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 18:04:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155238#M26400</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-18T18:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155260#M26404</link>
      <description>&lt;P&gt;It might be routing problem, but for what Logesh8 wrote, the devices are directly connected to the interfaces. Should not have routing issue there.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/76116"&gt;@Logesh8&lt;/a&gt;&amp;nbsp;Can you elaborate on the topology? If there is routing involved, and the device is not directly connected, then Bob is probably right and you are missing the return route for that traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 08:02:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155260#M26404</guid>
      <dc:creator>AndréTinoco</dc:creator>
      <dc:date>2022-08-19T08:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155269#M26405</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;, I have scheduled&amp;nbsp; a troubleshooting call on Monday. I will give you more information.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 08:57:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155269#M26405</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-19T08:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155270#M26406</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25664"&gt;@AndréTinoco&lt;/a&gt;&amp;nbsp;, Sure I will provide you more information about topology soon.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 08:58:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155270#M26406</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-19T08:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155274#M26407</link>
      <description>&lt;P&gt;Hey just my two cents as you say both devices are directly connected and I assume firewall policy and anti-spoofing have been checked, did you check the subnet masks on both ports?&lt;/P&gt;&lt;P&gt;Not that the firewall isn't forwarding the traffic as it's assuming the subnet range belongs to eth2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 09:47:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155274#M26407</guid>
      <dc:creator>Markus_Genser</dc:creator>
      <dc:date>2022-08-19T09:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155450#M26489</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes checked.. When we run tcpdump for physical interface of the switch and router. Output is perfect but not the same when we run tcpdump for loopback IPs of switch and router.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:04:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155450#M26489</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-22T17:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155451#M26490</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, PFO,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;net.bridge.lacp_forwarding = 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;net.ipv4.ip_forward_use_pmtu = 0&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:05:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155451#M26490</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-22T17:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP not leaving the firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155452#M26491</link>
      <description>&lt;P&gt;Hi, IP route get shows the correct Interface details.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICMP-not-leaving-the-firewall/m-p/155452#M26491</guid>
      <dc:creator>Logesh8</dc:creator>
      <dc:date>2022-08-22T17:06:18Z</dc:date>
    </item>
  </channel>
</rss>

