<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lost Zabbix packets in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170972#M30980</link>
    <description>&lt;P&gt;Assuming there is no NAT involved, a reason to see only SYN could be that the packets are accelerated. Use -F flag instead of -e to look for the accelerated packets as well. Mind the filtering with "-F", see&amp;nbsp;&lt;SPAN&gt;sk30583 for more details.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2023 12:00:54 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-02-10T12:00:54Z</dc:date>
    <item>
      <title>Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/169417#M30667</link>
      <description>&lt;P&gt;Hey,&lt;BR /&gt;I have a problem with a CP 7000 cluster, Gaia R80.40.&lt;BR /&gt;The problem manifests itself in the loss of some packages from Zabbix. There are no rejected packets in the CP.. Most of the packets reach their destination, but some of them get lost along the way and cannot be seen on the destination servers. Between Zabbix and the servers there is only a CP cluster and switches. The traffic is on tcp 10050. When we change the port for the selected servers to a different one, the communication starts to work properly It looks like some queue is clogged or something like that when there are too many requests on tco 10050.&lt;/P&gt;&lt;P&gt;Please help diagnose the problem&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:29:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/169417#M30667</guid>
      <dc:creator>Mateusz_89</dc:creator>
      <dc:date>2023-01-27T13:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/169438#M30671</link>
      <description>&lt;P&gt;The first step is to make sure those packets are "lost" because of the firewall. Logs, traces, drop debugging, did you look into any of those?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 17:09:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/169438#M30671</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-27T17:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170236#M30851</link>
      <description>&lt;P&gt;Yes, I'm looking but the logs don't show dropped packets, fw ctl debug drop doesn't show anything either.&lt;BR /&gt;I thought it might be something related to:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960&lt;/A&gt;&lt;BR /&gt;but the proposed changes had no effect.&lt;BR /&gt;Behind the CP there are only switches and a server to which some packets do not reach, routing is ok because most sessions work properly so I assume that the problem is on the CP&lt;BR /&gt;Can you suggest what to check next?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 11:02:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170236#M30851</guid>
      <dc:creator>Mateusz_89</dc:creator>
      <dc:date>2023-02-03T11:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170241#M30852</link>
      <description>&lt;P&gt;Have you looked at the interface level counters using the likes of cpview or netstat -i / ifconfig / ethtool -S&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 13:53:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170241#M30852</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-03T13:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170270#M30862</link>
      <description>&lt;P&gt;If you do not see dropped packets, it is likely they just do not reach the FW. Try snooping outside of FW to prove that.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 13:24:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170270#M30862</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-03T13:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170958#M30978</link>
      <description>&lt;P&gt;I can't catch packets before CP. The topology looks like this:&lt;BR /&gt;Zabbix - Cisco Nexus - CheckPoint Cluter (active-passive)-another Cisco Nexus - destination servers.&lt;BR /&gt;I do not have physical access to the infrastructure.&lt;BR /&gt;I catch packets on CP:&lt;BR /&gt;fw monitor -T -w -e "accept (src=10.120.58.98 and dst=10.120.61.148) or (src=10.120.61.148 and dst=10.120.58.98);" -o /var/log/test.cap&lt;BR /&gt;10.120.58.98 - zabbix&lt;BR /&gt;I&amp;nbsp; see only SYN&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pcap.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19531i27B16B20D71B4CC3/image-size/large?v=v2&amp;amp;px=999" role="button" title="pcap.png" alt="pcap.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 09:39:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170958#M30978</guid>
      <dc:creator>Mateusz_89</dc:creator>
      <dc:date>2023-02-10T09:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170972#M30980</link>
      <description>&lt;P&gt;Assuming there is no NAT involved, a reason to see only SYN could be that the packets are accelerated. Use -F flag instead of -e to look for the accelerated packets as well. Mind the filtering with "-F", see&amp;nbsp;&lt;SPAN&gt;sk30583 for more details.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 12:00:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/170972#M30980</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-10T12:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/171841#M31201</link>
      <description>&lt;P&gt;fw monitor -F "10.120.58.98,0,10.120.61.148,0,0" -o /var/log/test.cap&lt;BR /&gt;Pcap screenshots in the attachments.&lt;/P&gt;&lt;P&gt;There is another DC in the infrastructure with the same devices. The pcap in the second DC looks very similar, there is also a lot of malformed packet and nothing else is visible in pcap. Traffic from zabbix to the servers in the other DC is working fine. There are the same models of CP and switches with the same firmware.&lt;BR /&gt;Any suggestions what else I can check?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 08:32:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/171841#M31201</guid>
      <dc:creator>Mateusz_89</dc:creator>
      <dc:date>2023-02-17T08:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/171852#M31203</link>
      <description>&lt;P&gt;Open a SR# with CP TAC! But i fear that only being able to sniffer on CP GW&amp;nbsp; will not help here...&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 09:45:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/171852#M31203</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T09:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: Lost Zabbix packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/171886#M31216</link>
      <description>&lt;P&gt;Wireshark is reporting the packets are malformed because &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; only captures the first 40 bytes of a packet (the snaplen) and not the whole thing, pass the &lt;STRONG&gt;-w&lt;/STRONG&gt; flag to capture the entire packet and that warning will go away.&amp;nbsp; So that is a red herring.&lt;/P&gt;
&lt;P&gt;All packets in your firewall capture are appearing 4 times at all 4 capture points so they are passing through the firewall just fine.&amp;nbsp; Please post the output of &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;&amp;nbsp;on the firewall to this thread; assuming packets are not being lost at the NIC level there it appears they are getting across the firewall just fine, and your problem lies elsewhere with an improperly defined bond or errors racking up on some interface somewhere.&amp;nbsp; You need to check the network error counters on all firewall/Nexus/Zabbix/Servers in the path, I guarantee you are taking interface errors somewhere which is why packets are randomly not making it.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 14:33:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lost-Zabbix-packets/m-p/171886#M31216</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-02-17T14:33:28Z</dc:date>
    </item>
  </channel>
</rss>

