<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Invalid checksum TCP drops between HA MGMT Servers + members? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159508#M27927</link>
    <description>&lt;P&gt;Have you reviewed&amp;nbsp;&lt;SPAN&gt;sk172266, perhaps suggests some underlying network issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The "window" for this can be increased in consultation with TAC to negate if the underlying cause cannot be eliminated.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 06:28:58 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-10-14T06:28:58Z</dc:date>
    <item>
      <title>Invalid checksum TCP drops between HA MGMT Servers + members?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159504#M27924</link>
      <description>&lt;P data-unlink="true"&gt;I have a cluster with 2 MGMT servers (Active and Standby). I'm getting a ton of these:&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;CP_redundant on the way from Active to Standby&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://i.imgur.com/EBbErOQ.png" border="0" width="698" height="741" /&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;CPD_Amon: From Standby to a managed node:&lt;BR /&gt;&lt;IMG src="https://i.imgur.com/g5nyrTT.png" border="0" width="706" height="857" /&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Otherwise, the cluster is green. I can push policy fine. HA MGMT is sync'ing, etc. I do see some flows allowed in the midst of all the drops for the same port, so perhaps that explain the green cluster.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;I'd still like to know what these drops are for?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Network is:&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;{10.10.171.0/24} --&amp;gt; 10.10.171.1 eth2-[CPSite1]-eth4 172.30.0.1/28 &amp;lt;----&amp;gt; 172.30.0.4/28 eth4-[CPSite2]- --&amp;gt; {10.20.171.0/24}&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;There is a route on Checkpoint 1: 10.20.171.0/24 via 172.30.0.4&lt;/P&gt;&lt;P data-unlink="true"&gt;There is a route on Checkpoint 2: 10.10.171.0/24 via 172.30.0.1&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 05:28:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159504#M27924</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-10-14T05:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid checksum TCP drops between HA MGMT Servers + members?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159508#M27927</link>
      <description>&lt;P&gt;Have you reviewed&amp;nbsp;&lt;SPAN&gt;sk172266, perhaps suggests some underlying network issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The "window" for this can be increased in consultation with TAC to negate if the underlying cause cannot be eliminated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 06:28:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159508#M27927</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-14T06:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid checksum TCP drops between HA MGMT Servers + members?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159545#M27949</link>
      <description>&lt;P&gt;I'll give a capture a go. I just noticed some of the same coming in from RemoteAccess VPN Clients, from WAN to LANs directly behind the checkpoint. Nothing crazy. And same thing, there is an allow right beforehand and the traffic works!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 12:50:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159545#M27949</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-10-14T12:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid checksum TCP drops between HA MGMT Servers + members?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159558#M27960</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Here's a cap of the problem:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://i.imgur.com/e3jzjAD.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;10.10.171.12 (LAN) hitting &lt;A href="https://10.20.171.4" target="_blank" rel="noopener"&gt;https://10.20.171.4&lt;/A&gt;&amp;nbsp;(LAN on other side of S2S tunnel)&lt;BR /&gt;&lt;BR /&gt;I wonder if this could be a VMWare/ESX TCP Offload gotcha.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 14:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159558#M27960</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-10-14T14:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid checksum TCP drops between HA MGMT Servers + members?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159576#M27965</link>
      <description>&lt;P&gt;Bingo!&lt;BR /&gt;&lt;BR /&gt;I changed the adapter for ONLY my WAN interface on the CP to E1000 from VMXNET3 and these stopped.&lt;/P&gt;&lt;P&gt;I'm on an old many gens ago Dell server. Running broadcom (bnx3) drivers and ESXi 6.5 with latest approved VIB. (No support for 6.7 or 7) if any one is in the same situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 15:46:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Invalid-checksum-TCP-drops-between-HA-MGMT-Servers-members/m-p/159576#M27965</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-10-14T15:46:21Z</dc:date>
    </item>
  </channel>
</rss>

