<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Gateway dropped some packets in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169887#M30799</link>
    <description>&lt;P&gt;So, some answers:&lt;BR /&gt;&lt;BR /&gt;1. UDP 8116 is CCP traffic. CCP is used to monitor cluster functionality. It is not okay that CCP from NW network is leaking to i1/2/3 network. Check your router does not forward broadcast between network. If it does, see how to remove that. The issue 1 is only cosmetic, not a matter of concern though.&lt;/P&gt;
&lt;P&gt;2. Not clear if this is indeed a multicast, and where it comes from. Not related to setup, I believe.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Those are high ports, some reply to TCP traffic. Show more details, especially the source ports for each, to determine the application sending this traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 11:15:38 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-02-01T11:15:38Z</dc:date>
    <item>
      <title>Security Gateway dropped some packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169883#M30796</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dear Team,&lt;BR /&gt;&lt;BR /&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are implementing ClusterXL and Management High Availability.&lt;BR /&gt;We have also activated Anti-Spoofing.&lt;BR /&gt;A diagram of the network infrastructure is displayed below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-02-01_19h21_20.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19378i3C4570F370C9BFB4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-02-01_19h21_20.png" alt="2023-02-01_19h21_20.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Under these conditions, the Security Gateway is dropping the following packets:&lt;/P&gt;&lt;P&gt;i1&amp;amp;i2 -&amp;gt; Management NW network address (4th octet 0), UDP/8116&lt;BR /&gt;i1&amp;amp;i2 -&amp;gt; 239.255.255.250, UDP/1900&lt;BR /&gt;m3&amp;amp;m4 -&amp;gt; m1&amp;amp;m2, TCP/45112 TCP/53393&lt;/P&gt;&lt;P&gt;The cluster configuration appears to be functioning correctly, as indicated by SmartConsole or the output of the "show cluster state" command.&lt;BR /&gt;It is effectively executing failover procedures even after simulating failures, such as shutting down the active SG.&lt;/P&gt;&lt;P&gt;(Question 1) Is there an issue with this current setup?&lt;BR /&gt;(Question 2) If there is an issue, what steps should be taken to resolve it (e.g. implementing additional firewall policies)?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 10:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169883#M30796</guid>
      <dc:creator>tepeeeeei</dc:creator>
      <dc:date>2023-02-01T10:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway dropped some packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169885#M30797</link>
      <description>&lt;P&gt;What do the drop log entries say?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 10:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169885#M30797</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-01T10:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway dropped some packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169886#M30798</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you for reply, he said&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- i1&amp;amp;i2 -&amp;gt; Management NW network address (4th octet 0), UDP/8116&lt;BR /&gt;&amp;nbsp; -&amp;nbsp; by rule (All DENY)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- i1&amp;amp;i2 -&amp;gt; 239.255.255.250, UDP/1900&lt;BR /&gt;&lt;/SPAN&gt;&amp;nbsp; -&amp;nbsp;IP multicast routing failed (missing OS route)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- m3&amp;amp;m4 -&amp;gt; m1&amp;amp;m2, TCP/45112 TCP/53393&lt;BR /&gt;&amp;nbsp; -&amp;nbsp;TCP packet out of state:&amp;nbsp;TCP packet out of state&lt;BR /&gt;&amp;nbsp; -&amp;nbsp;TCP Flags: PUSH-ACK&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 11:00:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169886#M30798</guid>
      <dc:creator>tepeeeeei</dc:creator>
      <dc:date>2023-02-01T11:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway dropped some packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169887#M30799</link>
      <description>&lt;P&gt;So, some answers:&lt;BR /&gt;&lt;BR /&gt;1. UDP 8116 is CCP traffic. CCP is used to monitor cluster functionality. It is not okay that CCP from NW network is leaking to i1/2/3 network. Check your router does not forward broadcast between network. If it does, see how to remove that. The issue 1 is only cosmetic, not a matter of concern though.&lt;/P&gt;
&lt;P&gt;2. Not clear if this is indeed a multicast, and where it comes from. Not related to setup, I believe.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Those are high ports, some reply to TCP traffic. Show more details, especially the source ports for each, to determine the application sending this traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 11:15:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169887#M30799</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-01T11:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway dropped some packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169895#M30803</link>
      <description>&lt;P&gt;1. understood that it is a network problem, not Quantum.&lt;BR /&gt;2. I don't particularly care about it.&lt;BR /&gt;3．The source port was 257.&lt;BR /&gt;&amp;nbsp; It seems to be a return communication of log transmission.&lt;BR /&gt;&amp;nbsp; Since I am receiving logs correctly under normal circumstances, this did not seem to be a problem either.&lt;/P&gt;&lt;P&gt;Thank you very much for your answer!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 11:51:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-dropped-some-packets/m-p/169895#M30803</guid>
      <dc:creator>tepeeeeei</dc:creator>
      <dc:date>2023-02-01T11:51:20Z</dc:date>
    </item>
  </channel>
</rss>

