<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIP Traffic droped in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163947#M29293</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read that SK several times...&lt;/P&gt;&lt;P&gt;in the attachement you may find port description. with protocl SIP or without protocl SIP the message is the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2022 11:47:04 GMT</pubDate>
    <dc:creator>SilviuBiden</dc:creator>
    <dc:date>2022-12-02T11:47:04Z</dc:date>
    <item>
      <title>SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163935#M29287</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;From the begining, I'm networking guy not "VoIP telephony" guy.&lt;/P&gt;&lt;P&gt;One VPN is fully functional, except SIP Traffic. My host sends SIP Invite. Packet arrive to destination. The other host Answer to SIP invite, but the pachet is dropped on checkpoint site. I ran fw ctl zdebug drop | grep d.d.d.2&amp;nbsp;&lt;BR /&gt;Packet proto=17 a.a.a.2:5060 -&amp;gt; d.d.d.123:5066 dropped by fw_one_way_enforcement Reason: conn oneway violated&lt;/P&gt;&lt;P&gt;What I did: I defined a rulebase traffic between hosts to be accepted on custom defined services on UDP port 5060 and 5066. I unchecked "MatchAny" on custom service definition and also I checked "Accept Replies".&lt;/P&gt;&lt;P&gt;I put in exception for traffic inspection... nothing is working.&lt;/P&gt;&lt;P&gt;What shall I do more?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 08:39:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163935#M29287</guid>
      <dc:creator>SilviuBiden</dc:creator>
      <dc:date>2022-12-02T08:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163945#M29291</link>
      <description>&lt;P&gt;I know, I feel the same, haha. VOIP has to be my least favorite "subject" when it comes to any vendor, honestly. I hate to tell you this, but if you have TAC case going on, I am 100% positive they will ask you to review below and see what applies to you:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95369" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95369&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Now, let me take a "stab at this". So, logically, based on your drop message, we can see its dropping traffic on port 5066, since all we really care is destination port. Can you send a screenshot how you defined it?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 11:40:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163945#M29291</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T11:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163947#M29293</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read that SK several times...&lt;/P&gt;&lt;P&gt;in the attachement you may find port description. with protocl SIP or without protocl SIP the message is the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 11:47:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163947#M29293</guid>
      <dc:creator>SilviuBiden</dc:creator>
      <dc:date>2022-12-02T11:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163948#M29294</link>
      <description>&lt;P&gt;Ok, so let me ask you this...which scenario from the sk applies to you?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 11:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163948#M29294</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T11:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163949#M29295</link>
      <description>&lt;P&gt;&lt;SPAN&gt;SIP Proxy to SIP Proxy but there is no NAT involoved and communication between SIP proxies is thru a VPN.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 12:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163949#M29295</guid>
      <dc:creator>SilviuBiden</dc:creator>
      <dc:date>2022-12-02T12:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163954#M29298</link>
      <description>&lt;P&gt;so 7-1-C section?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 12:30:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163954#M29298</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T12:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163957#M29299</link>
      <description>&lt;P&gt;Yes. This is the section&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 13:18:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163957#M29299</guid>
      <dc:creator>SilviuBiden</dc:creator>
      <dc:date>2022-12-02T13:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163958#M29300</link>
      <description>&lt;P&gt;Are you able to send rule screenshot please?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 13:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163958#M29300</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T13:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163960#M29301</link>
      <description />
      <pubDate>Fri, 02 Dec 2022 13:42:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163960#M29301</guid>
      <dc:creator>SilviuBiden</dc:creator>
      <dc:date>2022-12-02T13:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163963#M29302</link>
      <description>&lt;P&gt;Services look different than whats defined in the sk.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18621iA2B9C2AD516C1B39/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In 2nd example, it only shows you would have single service as it defines word or, not and.&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 13:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163963#M29302</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T13:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163969#M29303</link>
      <description>&lt;P&gt;even with a single sip service, the error is the same&lt;/P&gt;&lt;P&gt;dropped by fw_one_way_enforcement Reason: conn oneway violated&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 14:31:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163969#M29303</guid>
      <dc:creator>SilviuBiden</dc:creator>
      <dc:date>2022-12-02T14:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163970#M29304</link>
      <description>&lt;P&gt;Ok, fair enough...in that case, I would reach out to TAC to debug it further. That error, to me anyway, logically would indicate that it does not like something either about the service property settings and connection gets terminated. Please share here once you find the solution.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 14:35:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163970#M29304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T14:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163971#M29305</link>
      <description>&lt;P&gt;Thank you anyhow.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 14:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163971#M29305</guid>
      <dc:creator>SilviuBiden</dc:creator>
      <dc:date>2022-12-02T14:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163974#M29306</link>
      <description>&lt;P&gt;No worries. One other thing I would do is run fw monitor to make sure it takes correct path at least. If it does, then yea, Im pretty sure debugs might be needed.&lt;/P&gt;
&lt;P&gt;Below is all I found on that error on support site, but Im sure you already seen those.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18626i04A6C94CFAC42F3F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 14:39:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/163974#M29306</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T14:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Traffic droped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/164039#M29349</link>
      <description>&lt;P&gt;Have you looked at;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31808&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31808&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 23:49:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Traffic-droped/m-p/164039#M29349</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-02T23:49:08Z</dc:date>
    </item>
  </channel>
</rss>

