<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161086#M28483</link>
    <description>&lt;P&gt;Do you see accept logs for forward traffic on both gateways, and which gateway is logging the drop?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Nov 2022 06:55:38 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2022-11-03T06:55:38Z</dc:date>
    <item>
      <title>Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161032#M28465</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We are facing issue where reverse https traffic from destination to source is being dropped.&lt;/P&gt;&lt;P&gt;Below example FYI&lt;/P&gt;&lt;P&gt;*****Forward Traffic******&lt;/P&gt;&lt;P&gt;Source:10.10.10.10 (source is behind gateway 1)&lt;/P&gt;&lt;P&gt;Source port: Random (52437)&lt;/P&gt;&lt;P&gt;Destination: 20.20.20.20&amp;nbsp;(Destination is behind gateway 2)&lt;/P&gt;&lt;P&gt;Destination port: 443&lt;/P&gt;&lt;P&gt;Traffic is getting allowed on both Gateway&lt;/P&gt;&lt;P&gt;*****Reverse Traffic******&lt;/P&gt;&lt;P&gt;Source: 20.20.20.20&amp;nbsp;(Destination is behind gateway 2)&lt;/P&gt;&lt;P&gt;Source port: 443&lt;/P&gt;&lt;P&gt;Destination: 10.10.10.10 (source is behind gateway 1)&lt;/P&gt;&lt;P&gt;Destination port: Random (52437) ---&amp;gt;Same Random Port which observed in forward traffic&lt;/P&gt;&lt;P&gt;Traffic is getting dropped on gateway 2&lt;/P&gt;&lt;P&gt;**********************&lt;/P&gt;&lt;P&gt;This is unexpected behavior in stateful firewall,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any thoughts on why this is happening , and what could be solution?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 07:07:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161032#M28465</guid>
      <dc:creator>SurajGaikwad</dc:creator>
      <dc:date>2022-11-03T07:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161037#M28466</link>
      <description>&lt;P&gt;What does the drop log say?&lt;BR /&gt;&lt;BR /&gt;For TCP 443 you do not need two rules, one should be enough. Also, what about NAT?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:15:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161037#M28466</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-02T15:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161085#M28482</link>
      <description>&lt;P&gt;Hello _Val_&lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;Zdebug Drop logs says "&lt;SPAN&gt;dropped by fw_send_log_drop Reason: Rulebase drop"&lt;/SPAN&gt;. Same observed in smartconsole logs, traffic is getting dropped by default cleanup rule.&lt;/P&gt;&lt;P&gt;Nating is not enabled for both source and destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 06:44:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161085#M28482</guid>
      <dc:creator>SurajGaikwad</dc:creator>
      <dc:date>2022-11-03T06:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161086#M28483</link>
      <description>&lt;P&gt;Do you see accept logs for forward traffic on both gateways, and which gateway is logging the drop?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 06:55:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161086#M28483</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2022-11-03T06:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161090#M28485</link>
      <description>&lt;P&gt;Hello emmap,&lt;/P&gt;&lt;P&gt;Yes can&amp;nbsp;&lt;SPAN&gt;see accept logs for forward traffic on both gateways.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Drop log is observed on first gateway of return traffic (gateway 2 as explain in question)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 07:11:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161090#M28485</guid>
      <dc:creator>SurajGaikwad</dc:creator>
      <dc:date>2022-11-03T07:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161095#M28487</link>
      <description>&lt;P&gt;This does not make much sense. Check for asymmetric routing.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 07:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161095#M28487</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-03T07:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161148#M28495</link>
      <description>&lt;P&gt;Please provide screenshots of both the accept and drop logs (masking sensitive data).&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 13:32:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161148#M28495</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-03T13:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161238#M28530</link>
      <description>&lt;P&gt;Hello PhoneBoy,&lt;/P&gt;&lt;P&gt;Attached accept and drop logs where forward traffic is accepted and reverse traffic is dropped&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 13:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161238#M28530</guid>
      <dc:creator>SurajGaikwad</dc:creator>
      <dc:date>2022-11-04T13:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161249#M28531</link>
      <description>&lt;P&gt;Please provide the full log card for each log entry.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 15:13:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161249#M28531</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-04T15:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161538#M28600</link>
      <description>&lt;P&gt;attached full log card.&lt;/P&gt;&lt;P&gt;Also let me know is return traffic visible in smartconsole logs.. if forward traffic is accepted.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 11:37:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161538#M28600</guid>
      <dc:creator>SurajGaikwad</dc:creator>
      <dc:date>2022-11-08T11:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse HTTPS traffic is getting dropped on Checkpoint Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161563#M28607</link>
      <description>&lt;P&gt;I’m not seeing the “origin” field on these log entries (I.e. the gateway that is actually logging these packets).&lt;BR /&gt;Have you confirmed the same gateway that is allowing the traffic is actually blocking it?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 13:31:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-HTTPS-traffic-is-getting-dropped-on-Checkpoint-Gateway/m-p/161563#M28607</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-08T13:31:19Z</dc:date>
    </item>
  </channel>
</rss>

