<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Troubleshooting outbound traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-outbound-traffic/m-p/170760#M30928</link>
    <description>&lt;P&gt;So troubleshooting outbound traffic to a single IP...&lt;/P&gt;&lt;P&gt;I can ping from the gateway just fine.&lt;/P&gt;&lt;P&gt;when doing a fw mon i get the following..&lt;/P&gt;&lt;P&gt;[Expert@IndyFWb:0]# &lt;STRONG&gt;fw monitor -e "accept host(192.147.37.210) and host(10.1.9.29) and ip_p=1;"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44783&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=608&lt;BR /&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44784&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=609&lt;BR /&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44785&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=610&lt;BR /&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44786&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=611&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a rule that allows it as you can see below...&lt;/P&gt;&lt;P&gt;[Expert@IndyFWb:0]# &lt;STRONG&gt;fw up_execute src=10.1.9.29 dst=192.147.37.210 ipp=1&lt;/STRONG&gt;&lt;BR /&gt;Rulebase execution ended successfully.&lt;BR /&gt;Overall status:&lt;BR /&gt;----------------&lt;BR /&gt;Active clob mask: 0&lt;BR /&gt;Required clob mask: 0&lt;BR /&gt;Match status: MATCH&lt;BR /&gt;Match action: Accept&lt;/P&gt;&lt;P&gt;Per Layer:&lt;BR /&gt;------------&lt;BR /&gt;Layer name: MainFWPol Network&lt;BR /&gt;Layer id: 0&lt;BR /&gt;Match status: MATCH&lt;BR /&gt;Match action: Accept&lt;BR /&gt;Matched rule: 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw ctl zdebug drops do not report any drops...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are some next steps to try and determine why the traffic isn't leaving the gateway?&lt;/P&gt;&lt;P&gt;Trying to do some more troubleshooting before opening a case with Checkpoint support. Also want to be sure it isn't something simple.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2023 16:43:55 GMT</pubDate>
    <dc:creator>Sam_Ponder</dc:creator>
    <dc:date>2023-02-08T16:43:55Z</dc:date>
    <item>
      <title>Troubleshooting outbound traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-outbound-traffic/m-p/170760#M30928</link>
      <description>&lt;P&gt;So troubleshooting outbound traffic to a single IP...&lt;/P&gt;&lt;P&gt;I can ping from the gateway just fine.&lt;/P&gt;&lt;P&gt;when doing a fw mon i get the following..&lt;/P&gt;&lt;P&gt;[Expert@IndyFWb:0]# &lt;STRONG&gt;fw monitor -e "accept host(192.147.37.210) and host(10.1.9.29) and ip_p=1;"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44783&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=608&lt;BR /&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44784&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=609&lt;BR /&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44785&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=610&lt;BR /&gt;[vs_0][fw_0] bond3:i[44]: 10.1.9.29 -&amp;gt; 192.147.37.210 (ICMP) len=60 id=44786&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=611&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a rule that allows it as you can see below...&lt;/P&gt;&lt;P&gt;[Expert@IndyFWb:0]# &lt;STRONG&gt;fw up_execute src=10.1.9.29 dst=192.147.37.210 ipp=1&lt;/STRONG&gt;&lt;BR /&gt;Rulebase execution ended successfully.&lt;BR /&gt;Overall status:&lt;BR /&gt;----------------&lt;BR /&gt;Active clob mask: 0&lt;BR /&gt;Required clob mask: 0&lt;BR /&gt;Match status: MATCH&lt;BR /&gt;Match action: Accept&lt;/P&gt;&lt;P&gt;Per Layer:&lt;BR /&gt;------------&lt;BR /&gt;Layer name: MainFWPol Network&lt;BR /&gt;Layer id: 0&lt;BR /&gt;Match status: MATCH&lt;BR /&gt;Match action: Accept&lt;BR /&gt;Matched rule: 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw ctl zdebug drops do not report any drops...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are some next steps to try and determine why the traffic isn't leaving the gateway?&lt;/P&gt;&lt;P&gt;Trying to do some more troubleshooting before opening a case with Checkpoint support. Also want to be sure it isn't something simple.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 16:43:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-outbound-traffic/m-p/170760#M30928</guid>
      <dc:creator>Sam_Ponder</dc:creator>
      <dc:date>2023-02-08T16:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting outbound traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-outbound-traffic/m-p/170770#M30929</link>
      <description>&lt;P&gt;well... more digging into it and got it figured out. It was a NAT issue and a fault on my config.&amp;nbsp;&lt;/P&gt;&lt;P&gt;and if anyone else comes across this... I looked at the log entry in the smart app. and noticed it was trying to NAT to the incorrect network. Which got me to look at that nat rule and discovered my error in config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 17:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-outbound-traffic/m-p/170770#M30929</guid>
      <dc:creator>Sam_Ponder</dc:creator>
      <dc:date>2023-02-08T17:20:24Z</dc:date>
    </item>
  </channel>
</rss>

