<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The packets from a source to a destination in one path and takes a different path when it returns in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169400#M30658</link>
    <description>&lt;P&gt;When i initiate a trafic is drop or match another rule, so i need to create another rule for the return trafic.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="explain.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19335iAD3CF1C9F3546CB8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="explain.png" alt="explain.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; See the screenshot&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2023 11:56:29 GMT</pubDate>
    <dc:creator>A_KOUADIO</dc:creator>
    <dc:date>2023-01-27T11:56:29Z</dc:date>
    <item>
      <title>The packets from a source to a destination in one path and takes a different path when it returns</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169400#M30658</link>
      <description>&lt;P&gt;When i initiate a trafic is drop or match another rule, so i need to create another rule for the return trafic.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="explain.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19335iAD3CF1C9F3546CB8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="explain.png" alt="explain.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; See the screenshot&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 11:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169400#M30658</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-27T11:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169484#M30684</link>
      <description>&lt;P&gt;Have you confirmed the routing is correct end-to-end and that anti-spoofing is set correctly?&lt;/P&gt;
&lt;P&gt;Is there any NAT involved and could you please share a better/clearer screenshot?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 04:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169484#M30684</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-28T04:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169491#M30687</link>
      <description>&lt;P&gt;I would agree totally with what Chris said. 99% of the time, its either NAT, routing or anti-spoofing (or combination of all of them).&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 17:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169491#M30687</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-28T17:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169498#M30689</link>
      <description>&lt;P&gt;Routing is correct.&lt;/P&gt;&lt;P&gt;antispoofing is set correctly.&lt;/P&gt;&lt;P&gt;I will check the NAT.&lt;/P&gt;&lt;P&gt;Do you think that it is normal (correct) to have return trafic as new entry in log without nat the trafic ?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 23:42:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169498#M30689</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-28T23:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169499#M30690</link>
      <description>&lt;P&gt;This screenshot appears different to the original, can you provide the more detailed log cards for both flows?&lt;/P&gt;
&lt;P&gt;There is some suggestion here that's proxy is involved, are only some ports/redirected to the proxy and others NAT different?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 00:10:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169499#M30690</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-29T00:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169503#M30693</link>
      <description>&lt;P&gt;Dropped by Access Rule Number 1225 ???&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 08:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169503#M30693</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-29T08:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169506#M30694</link>
      <description>&lt;P&gt;Because the source port match another rule.&lt;/P&gt;&lt;P&gt;As I said previously, the return traffic is dissociated from the going trafic so it match another rule or drop by the cleanup rule.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 08:49:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169506#M30694</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-29T08:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169508#M30696</link>
      <description>&lt;P&gt;Ok I will check the cpinfo file today to verify?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 08:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169508#M30696</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-29T08:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169514#M30698</link>
      <description>&lt;P&gt;I would not use 1225 rules - but that should not cause asymmetrical routing afaik...&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 10:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169514#M30698</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-29T10:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169515#M30699</link>
      <description>&lt;P&gt;What will you check how in cpinfo ?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 10:18:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169515#M30699</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-29T10:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169564#M30724</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;As i said, I am currently looking for the cause of the asymmetric routing&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 09:32:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169564#M30724</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-30T09:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169566#M30726</link>
      <description>&lt;P&gt;But how to accomplish this in cpinfo ? Never heard of routing issues resolved by cpinfo analysis...&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 09:01:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169566#M30726</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-30T09:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169567#M30727</link>
      <description>&lt;P&gt;I don't have access to the appliance, so i will analyze on my side the cpinfo file and after that i will contact the customer to have clear understanding of the issues.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 09:11:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169567#M30727</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-30T09:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169573#M30730</link>
      <description>&lt;P&gt;I do not think you will find all answers in the CPInfo. In most cases, asymmetric routing is caused by external factors.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 09:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169573#M30730</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-30T09:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169583#M30732</link>
      <description>&lt;P&gt;Great - which tool are you using ? Or do you search in the cpinfo text ?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 11:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169583#M30732</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-30T11:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169595#M30738</link>
      <description>&lt;P&gt;CheckPoint Diagnostics View&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 12:21:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169595#M30738</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-30T12:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169596#M30739</link>
      <description>&lt;P&gt;I didn't understand your message but the client has a proxy in his intranet.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 12:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169596#M30739</guid>
      <dc:creator>A_KOUADIO</dc:creator>
      <dc:date>2023-01-30T12:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: The packets from a source to a destination in one path and takes a different path when it return</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169603#M30742</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87269"&gt;@A_KOUADIO&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I think what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;are saying is that its very unlikely you would find an answer as to why assymetric routing happens from cpinfo file review, as thats simply the config file from the firewall. Here is what I would run and examine carefully the output. So, just as an example, say the source is 10.10.10.10 and dst is 20.20.20.20, try commands like below:&lt;/P&gt;
&lt;P&gt;fw monitor -e "accept host(10.10.10.10) and dst(20.20.20.20);"&lt;/P&gt;
&lt;P&gt;fw monitor -e "accept host(20.20.20.20) and dst(10.10.10.10);"&lt;/P&gt;
&lt;P&gt;fw minitor -e "accept host(10.10.10.10) or dst(20.20.20.20);"&lt;/P&gt;
&lt;P&gt;Alternatively, you can also use below command. Idea is to filter for src IP, src port, dst IP, dst IP, protocol&lt;/P&gt;
&lt;P&gt;fw monitor -F "10.10.10.10,0,20.20.20.20,0,0" -F "20.20.20.20,0,10.10.10.10,0,0"&lt;/P&gt;
&lt;P&gt;I can also suggest a website my colleague made ages ago to help people with captures on different platforms (its very useful)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tcpdump101.com/#" target="_blank" rel="noopener"&gt;https://tcpdump101.com/#&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope all this helps you.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 13:05:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-packets-from-a-source-to-a-destination-in-one-path-and-takes/m-p/169603#M30742</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-01T13:05:08Z</dc:date>
    </item>
  </channel>
</rss>

