<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: millions of dropped packets in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157517#M27344</link>
    <description>&lt;P&gt;It is not clear if the drops being reported there are policy drops, or interface buffering drops (RX-DRP).&amp;nbsp; Please post the output of:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ifconfig gre1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ethtool -S gre1&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;(this may not work)&lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2022 12:24:04 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2022-09-19T12:24:04Z</dc:date>
    <item>
      <title>millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157505#M27343</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;we have several GW R81.10 with a GRE interface configured. The GRE together with Policy Based Routing is used for Zscaler. On one Firewall at the headquarters&amp;nbsp;we see only 50k dropped&amp;nbsp;packets, but on another branch, we see over 2M&amp;nbsp;dropped&amp;nbsp;packets. How can I find out, &lt;STRONG&gt;what is dropped&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gedroppte_pakete.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17809iD107F94108D58269/image-size/large?v=v2&amp;amp;px=999" role="button" title="gedroppte_pakete.png" alt="gedroppte_pakete.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 10:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157505#M27343</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-19T10:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157517#M27344</link>
      <description>&lt;P&gt;It is not clear if the drops being reported there are policy drops, or interface buffering drops (RX-DRP).&amp;nbsp; Please post the output of:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ifconfig gre1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ethtool -S gre1&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;(this may not work)&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 12:24:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157517#M27344</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-09-19T12:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157518#M27345</link>
      <description>&lt;P&gt;Drop ratio is four times higher.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 12:26:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157518#M27345</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-19T12:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157546#M27355</link>
      <description>&lt;P&gt;[Expert@vrafws01:0]# &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;eth0 1500 0 1737832834 0 0 0 1600292921 0 0 0 BMRU&lt;BR /&gt;eth1 1500 0 1758186694 0 0 0 1695221461 0 0 0 BMRU&lt;BR /&gt;eth2 1500 0 520731 0 0 0 81 0 0 0 BMRU&lt;BR /&gt;eth2.716 1500 0 520729 0 0 0 81 0 0 0 BMRU&lt;BR /&gt;eth2.802 1500 0 0 0 0 0 0 0 0 0 BMRU&lt;BR /&gt;eth2.816 1500 0 0 0 0 0 0 0 0 0 BMRU&lt;BR /&gt;eth2.817 1500 0 0 0 0 0 0 0 0 0 BMRU&lt;BR /&gt;eth2.819 1500 0 0 0 0 0 0 0 0 0 BMRU&lt;BR /&gt;gre1 1476 0 576331143 0 0 0 673523116 0 0 0 MOPRU&lt;BR /&gt;gre2 1476 0 420183 0 0 0 500820 0 0 0 MOPRU&lt;BR /&gt;lo 65536 0 4625268 0 0 0 4625268 0 0 0 LMPRU&lt;/P&gt;&lt;P&gt;[Expert@vrafws01:0]# &lt;STRONG&gt;ifconfig gre1&lt;/STRONG&gt;&lt;BR /&gt;gre1 Link encap:UNSPEC HWaddr DF-1F-02-F2-16-09-AC-8B-00-00-00-00-00-00-00-00&lt;BR /&gt;inet addr:172.21.241.129 P-t-P:172.21.241.130 Mask:255.255.255.252&lt;BR /&gt;UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1476 Metric:1&lt;BR /&gt;RX packets:576348007 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:673539505 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:351032158812 (326.9 GiB) TX bytes:622558876610 (579.8 GiB)&lt;/P&gt;&lt;P&gt;[Expert@vrafws01:0]# &lt;STRONG&gt;ethtool -S gre1&lt;/STRONG&gt;&lt;BR /&gt;no stats available&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 15:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157546#M27355</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-19T15:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157551#M27359</link>
      <description>&lt;P&gt;Must be policy drops then, try applying this filter to the traffic logs in the SmartConsole:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;interface:gre1 and not action:accept&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Otherwise you'll need to run &lt;STRONG&gt;fw ctl zdebug + drop | grep gre1&lt;/STRONG&gt; and wait for some traffic to get dropped to see the reason.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 16:24:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157551#M27359</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-09-19T16:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157560#M27362</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/65443"&gt;@Exonix&lt;/a&gt;&amp;nbsp;use the filter mentioned by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;in the log view of SmartConsole. On the right you can open and see a statistics tab with details to top source, destination, service etc. With this information you &amp;nbsp;get more details for the dropped traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 19:38:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157560#M27362</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-09-19T19:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157590#M27376</link>
      <description>&lt;P&gt;I found a lot of dropped traffic from and to Zscaler Servers.&amp;nbsp;&lt;STRONG&gt;fw ctl zdebug &lt;/STRONG&gt;didn't schow anyting.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gre47.png" style="width: 681px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17816i7D1911AD826EF449/image-size/large?v=v2&amp;amp;px=999" role="button" title="gre47.png" alt="gre47.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The top-sources are Zscaler Servers:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="top1.png" style="width: 242px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17817iE94ACBA36BE4D564/image-size/large?v=v2&amp;amp;px=999" role="button" title="top1.png" alt="top1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 08:10:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157590#M27376</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-20T08:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157591#M27377</link>
      <description>&lt;P&gt;Click on one of the logs, what does it say?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 08:22:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157591#M27377</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-20T08:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157595#M27378</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17818i9DFCC494BDA0DC37/image-size/large?v=v2&amp;amp;px=999" role="button" title="log2.png" alt="log2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;can this setting be a reson for the drop?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="qos1.png" style="width: 827px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17819iACA542DD58DF0054/image-size/large?v=v2&amp;amp;px=999" role="button" title="qos1.png" alt="qos1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 08:29:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157595#M27378</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-20T08:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157602#M27380</link>
      <description>&lt;P&gt;Yes, it could be it. Why did you set this in the first place?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 09:07:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157602#M27380</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-20T09:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157651#M27386</link>
      <description>&lt;P&gt;I didn't set it, it was configured long time ago, before I joined the company.&lt;/P&gt;&lt;P&gt;As soon as we removed this restriction, the number of dropped packets decreased three times. I was told the customer has upgraded its Internet connection to 50 Mbit and the restriction is no longer necessary.&amp;nbsp;I keep watching.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 15:08:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157651#M27386</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-20T15:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157687#M27392</link>
      <description>&lt;P&gt;Good we figured this out&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 06:51:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157687#M27392</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-21T06:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: millions of dropped packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157715#M27415</link>
      <description>&lt;P&gt;thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 11:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/millions-of-dropped-packets/m-p/157715#M27415</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-09-21T11:12:38Z</dc:date>
    </item>
  </channel>
</rss>

